This policy explains what information CloudGuard ("we", "us") collects when you use cloudguard.solutions and the CloudGuard platform, how we use it, and the choices you have.
Account information. When you create an account we collect your name, email address, organization name, and a password (stored only as a bcrypt hash).
Scan data. To provide the service, CloudGuard connects to the cloud accounts, VMware vCenter environments, and servers you choose to connect, using read-only access. We collect configuration metadata needed to run security checks: for example resource names and identifiers, configuration settings, and service states. We do not collect the contents of your workloads, databases, or files.
Connection credentials. Credentials you provide for scanning (such as cloud role identifiers or vCenter credentials) are encrypted at rest using Fernet symmetric encryption and used only to perform the scans you configure.
Support data. When you open a support ticket we collect the information you submit (subject, description, attachments) together with context such as your plan, the page you were on, and your browser, so we can help faster.
Usage and technical data. Standard server logs (IP address, browser type, timestamps) used for security and operations.
We do not sell your personal information, and we do not use your scan data for advertising.
We rely on a small number of providers to operate CloudGuard:
All data in CloudGuard is scoped to your organization. Tenant isolation is enforced in every query and verified through cross-organization access testing. Access to your environments is read-only by design. Passwords are hashed with bcrypt, stored credentials are encrypted at rest, and access to the platform is protected by short-lived tokens.
We retain your data while your account is active. If you close your account or ask us to, we will delete your organization's data, including stored credentials, findings, and support history, within 30 days, except where we are legally required to retain records (for example billing records).
Depending on your location, you may have rights to access, correct, export, or delete your personal information. To exercise any of these rights, email support@cloudguard.solutions and we will respond within 30 days.
CloudGuard uses browser local storage to keep you signed in. We do not use advertising or third-party tracking cookies.
If we make material changes to this policy, we will update the date above and, for significant changes, notify account owners by email.
Questions about this policy: support@cloudguard.solutions