Skip to main content

Legal

Security

How this website protects what it handles, what we do not hold, and how to report a vulnerability.

Draft under legal review — not yet in effect.This page describes what the site does today. Counsel is reviewing it, and it takes effect only when this notice is replaced by the date it takes effect.

Controls in place today

  • Every page is served over HTTPS.
  • A strict content security policy, with a fresh value for each request, limits what can run on a page.
  • Forms, sign-in and the price calculator are rate limited, and the forms turn away automated submissions.
  • Passwords are stored only as argon2id hashes.
  • Session cookies cannot be read by scripts and can be set only by this website.
  • Staff sign in with a second factor.
  • Security events are recorded in an append-only log: the application can add to it, never change it.
  • Automated checks run on every proposed change, including a dependency audit and a scan for secrets in the code.

What we do not hold

We hold no security certification, such as ISO 27001 or a SOC 2 report. We have published no independent audit of power efficiency or carbon.

The infrastructure

Phase 1 capacity is planned for a third-party data centre in Nepal, under NDA. We do not publish its details, and no platform capacity is in operation yet.

Reporting a vulnerability

Email tech@cloudfrm.ai with what you found and how to reproduce it. Please do not access other people’s data, disrupt the service, or make the issue public before it is fixed. We read every report and reply from that address.

Changes to this page

This page is a draft under legal review and is not yet in effect. When it takes effect, its date appears at the top of this page, and each later change shows a new date.