Last updated: January 1, 2025
CloudSteer is committed to protecting the security, confidentiality, and integrity of information belonging to our customers, partners, and users. Security is a foundational principle of how we build, operate, and deliver our platform. We continuously work to improve our protections and stay ahead of emerging threats.
Our practices are aligned with SOC 2 security and privacy principles and industry best practices, including:
Security and privacy are not afterthoughts - they are core business responsibilities.
Security at CloudSteer is managed by designated leadership and is integrated into our engineering, infrastructure, and operational processes. Controls, risks, and procedures are reviewed periodically to ensure they remain effective and aligned with business objectives and regulatory expectations.
CloudSteer develops and operates AI-enabled cloud cost optimization platforms. Security controls are integrated into the design, development, and operation of these systems to protect customer data and ensure responsible system operation.
We welcome responsible disclosure of security vulnerabilities from the security research community. If you believe you have found a security issue in any CloudSteer service, we encourage you to notify us.
Report vulnerabilities to: security@cloudsteer.io
We will acknowledge receipt and work with you to investigate and remediate the issue in a timely manner.
When reporting a vulnerability, please include:
We ask that security researchers follow these guidelines:
We support responsible security research conducted in good faith. We will not pursue legal action against individuals who report vulnerabilities responsibly and in accordance with these guidelines.
CloudSteer does not currently operate a public bug bounty program. Vulnerability reports are not eligible for monetary rewards or compensation. We appreciate the efforts of the security community and acknowledge responsible reporters where appropriate.
This policy applies to:
Third-party services used by CloudSteer (e.g., payment processors, authentication providers) are out of scope. Issues with third-party services should be reported directly to the respective vendor.
For questions about this policy or CloudSteer's security practices, please contact security@cloudsteer.io.