Controls in place today
- Every page is served over HTTPS.
- A strict content security policy, with a fresh value for each request, limits what can run on a page.
- Forms, sign-in and the price calculator are rate limited, and the forms turn away automated submissions.
- Passwords are stored only as argon2id hashes.
- Session cookies cannot be read by scripts and can be set only by this website.
- Staff sign in with a second factor.
- Security events are recorded in an append-only log: the application can add to it, never change it.
- Automated checks run on every proposed change, including a dependency audit and a scan for secrets in the code.
What we do not hold
We hold no security certification, such as ISO 27001 or a SOC 2 report. We have published no independent audit of power efficiency or carbon.
The infrastructure
Phase 1 capacity is planned for a third-party data centre in Nepal, under NDA. We do not publish its details, and no platform capacity is in operation yet.
Reporting a vulnerability
Email tech@cloudfrm.ai with what you found and how to reproduce it. Please do not access other people’s data, disrupt the service, or make the issue public before it is fixed. We read every report and reply from that address.
Changes to this page
This page is a draft under legal review and is not yet in effect. When it takes effect, its date appears at the top of this page, and each later change shows a new date.