This page describes the infrastructure, controls, and practices behind CloudGuard Solutions, so you can evaluate connecting it to your environment with confidence. It complements our Privacy Policy and Terms of Use.
CloudGuard is hosted on Amazon Web Services in the US East region. We rely on AWS's physical, environmental, and infrastructure-level security controls and certifications rather than running our own data centers.
| Cloud provider | Amazon Web Services (AWS) |
| Primary region | US East |
| Payment processing | Stripe |
| Email delivery | Resend |
| Compliance frameworks covered | SOC 2, ISO 27001, CIS Benchmarks v8, HIPAA, GDPR, PCI DSS v4.0, NIST CSF |
Production systems sit behind managed network controls that restrict inbound access to only what the service actually needs. Administrative access to infrastructure is restricted and never exposed to the public internet.
If you're evaluating CloudGuard as part of a vendor security review and need more detail, such as a completed security questionnaire or a named sub-processor list, contact security@cloudguard.solutions.
CloudGuard connects to your cloud accounts, virtualization environment, and servers using read-only credentials or a locally installed agent. Every setup guide only ever asks for the minimum access needed: read-only IAM roles for AWS, Reader-level roles for Azure, Viewer-level roles for GCP, and a Read-only role for vCenter. There's no code path in the platform that creates, modifies, or deletes anything in an environment you connect.
CloudGuard is a multi-tenant platform, so every API request is checked against the requesting user's organization before any data is read or written. We don't just rely on code review for this. Isolation boundaries are verified through direct adversarial testing against every by-ID endpoint.
Login and registration are protected by CAPTCHA (Cloudflare Turnstile) to keep out automated abuse. Sessions use short-lived tokens rather than long-lived credentials, and API access is rate limited to guard against brute-force attempts and scraping.
All data in transit is encrypted using TLS.
Any connection credentials you provide for scanning, such as cloud role identifiers, service account keys, or vCenter credentials, are encrypted at rest and never transmitted or stored in plaintext. Passwords are never stored in readable form either. They're hashed using a strong, industry-standard algorithm built to resist brute-force attacks.
Billing for paid plans runs through Stripe. CloudGuard never receives or stores your full card details. That data is handled directly by Stripe's own PCI-compliant infrastructure.
Code changes go through a documented review and testing process before anything reaches production.
We monitor dependencies and infrastructure components for known vulnerabilities and apply security patches on a regular basis.
Security-relevant activity, including access to compliance controls and evidence, is recorded in an append-only audit trail so we can investigate incidents and track changes with full accountability.
Customer data is backed up on a regular schedule, with backups stored separately from production systems.
Our hosting infrastructure provides redundancy at the underlying cloud provider level.
If a security incident affects your data, we'll notify you without undue delay, and within whatever timeframe the law requires where a formal notification obligation applies.
CloudGuard maps its own controls, and the evidence you upload, across seven frameworks: SOC 2, ISO 27001, CIS Benchmarks v8, HIPAA, GDPR, PCI DSS v4.0, and NIST CSF. Evidence that satisfies one framework's requirement is reused automatically wherever it overlaps with another.
Every control attestation keeps its full history. Changes, retractions, and re-attestations are all logged, not just whatever the current state happens to be.
We maintain a vendor and sub-processor register tracking each vendor's role, data access, and current DPA or BAA status. Contact security@cloudguard.solutions for the current named list.
| Amazon Web Services | Cloud infrastructure hosting |
| Stripe | Payment processing |
| Resend | Transactional email delivery |