Security

How Cloud-Vex is built, and how to reach us if you find something.

The architecture is the security model

Cloud-Vex deploys into your cloud account. Scans run there, results are stored there, and nothing about your environment is transmitted to us. There is no central store of customer cloud data to breach, because none exists.

The collectors are read-only: they inventory and analyse, and hold no permissions to modify, create, or delete resources in your environment. What Cloud-Vex recommends, you apply — or don't — through your own change process.

What we operate, and how

The only Cloud-Vex-operated services your deployment talks to are licence validation and, at signup, purchase verification. On our side:

  • All traffic is TLS, end to end.
  • The subscription records we do hold — customer contacts and licence keys — are stored encrypted at rest.
  • Licence keys are high-entropy random credentials; in our logs they appear only as one-way hashes, never in full.
  • Purchases are verified server-side with the marketplace — a signup can't be forged by replaying or guessing identifiers.
  • Secrets live in AWS Secrets Manager, not in code or configuration files.
  • Our infrastructure is defined as code and deployed from version control.
  • Payment details never touch our systems; billing runs entirely through your cloud marketplace.

Reporting a vulnerability

If you believe you've found a security issue in Cloud-Vex — the product, this site, or our services — we want to hear about it: support@cloud-vex.com. We acknowledge reports within one business day.

We support good-faith research: give us reasonable time to fix an issue before disclosing it publicly, don't access data that isn't yours, and don't degrade the service for others. We will not pursue legal action against research conducted in that spirit.

We don't run a paid bug bounty today. We do credit reporters who want it, once a fix ships.

Machine-readable contact details: /.well-known/security.txt