How Cloud-Vex is built, and how to reach us if you find something.
Cloud-Vex deploys into your cloud account. Scans run there, results are stored there, and nothing about your environment is transmitted to us. There is no central store of customer cloud data to breach, because none exists.
The collectors are read-only: they inventory and analyse, and hold no permissions to modify, create, or delete resources in your environment. What Cloud-Vex recommends, you apply — or don't — through your own change process.
The only Cloud-Vex-operated services your deployment talks to are licence validation and, at signup, purchase verification. On our side:
If you believe you've found a security issue in Cloud-Vex — the product, this site, or our services — we want to hear about it: support@cloud-vex.com. We acknowledge reports within one business day.
We support good-faith research: give us reasonable time to fix an issue before disclosing it publicly, don't access data that isn't yours, and don't degrade the service for others. We will not pursue legal action against research conducted in that spirit.
We don't run a paid bug bounty today. We do credit reporters who want it, once a fix ships.
Machine-readable contact details: /.well-known/security.txt