CloudSteer LogoCloudSteer

Security

Last updated: January 1, 2025

Our Security Commitment

CloudSteer is committed to protecting the security, confidentiality, and integrity of information belonging to our customers, partners, and users. Security is a foundational principle of how we build, operate, and deliver our platform. We continuously work to improve our protections and stay ahead of emerging threats.

Our practices are aligned with SOC 2 security and privacy principles and industry best practices, including:

  • Access control and least privilege
  • Secure system architecture and development practices
  • Encryption of data in transit and at rest where appropriate
  • Continuous monitoring and logging
  • Incident response and recovery procedures
  • Protection of personal and sensitive data
  • Vendor and infrastructure security management

Security and privacy are not afterthoughts - they are core business responsibilities.

Security Governance

Security at CloudSteer is managed by designated leadership and is integrated into our engineering, infrastructure, and operational processes. Controls, risks, and procedures are reviewed periodically to ensure they remain effective and aligned with business objectives and regulatory expectations.

AI and Platform Security

CloudSteer develops and operates AI-enabled cloud cost optimization platforms. Security controls are integrated into the design, development, and operation of these systems to protect customer data and ensure responsible system operation.

Vulnerability Disclosure Program

We welcome responsible disclosure of security vulnerabilities from the security research community. If you believe you have found a security issue in any CloudSteer service, we encourage you to notify us.

Report vulnerabilities to: security@cloudsteer.io

We will acknowledge receipt and work with you to investigate and remediate the issue in a timely manner.

When reporting a vulnerability, please include:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Any relevant screenshots or logs
  • The affected domain, system, or feature

Responsible Disclosure Guidelines

We ask that security researchers follow these guidelines:

  • Act in good faith to avoid privacy violations, data destruction, or service disruption
  • Avoid accessing or modifying user data beyond what is necessary to demonstrate the vulnerability
  • Avoid disrupting CloudSteer services or infrastructure
  • Allow reasonable time for us to address the issue before any public disclosure
  • Do not publicly disclose vulnerability details before a resolution has been confirmed

We support responsible security research conducted in good faith. We will not pursue legal action against individuals who report vulnerabilities responsibly and in accordance with these guidelines.

No Bug Bounty or Compensation

CloudSteer does not currently operate a public bug bounty program. Vulnerability reports are not eligible for monetary rewards or compensation. We appreciate the efforts of the security community and acknowledge responsible reporters where appropriate.

Scope

This policy applies to:

  • cloudsteer.io and its subdomains and infrastructure
  • Applications, APIs, and services operated by CloudSteer

Third-party services used by CloudSteer (e.g., payment processors, authentication providers) are out of scope. Issues with third-party services should be reported directly to the respective vendor.

Questions

For questions about this policy or CloudSteer's security practices, please contact security@cloudsteer.io.