Cloudsphere

Trust Center

Building Trust Through Security, Privacy, and Compliance

Last updated: 25 July 2026

Cloudsphere is committed to protecting customer information through secure engineering practices, privacy-by-design principles, regulatory compliance, and continuous improvement.

Registered PSEUU PDPISO/IEC 27001 AlignedISO/IEC 27701 ReferencedPrivacy by DesignSecurity by Design
Registered Private Electronic System Provider (PSE)
Privacy by Design
Security by Design
Responsible Disclosure
Transparent Security Practices

Regulatory & Compliance

Compliance with Indonesian regulation and international data-protection principles is foundational to our services.

Private Electronic System Provider (PSE)

Status

Registered

Registration (PB UMKU)

130726010770200020001

Authority

Ministry of Communication and Digital (Komdigi)

Issued

17 July 2026

Personal Data Protection Law

Cloudsphere processes personal data in accordance with Law No. 27 of 2022 concerning Personal Data Protection (UU PDP). We implement technical and organizational safeguards to protect personal information and respect the rights of data subjects.

GDPR

Although Cloudsphere is established in Indonesia, our privacy practices are designed with reference to the General Data Protection Regulation (GDPR) principles, including lawfulness, transparency, data minimization, purpose limitation, and accountability.

Information Security

ISO/IEC 27001:2022

Cloudsphere develops its services in alignment with ISO/IEC 27001:2022 Information Security Management System (ISMS) principles.

Status

Aligned with ISO/IEC 27001:2022

Certification

Not Certified

ISO/IEC 27701 — Privacy Information Management

Cloudsphere references ISO/IEC 27701 when designing privacy governance and personal data protection controls.

Status

Aligned

Certification

Not Certified

Security Practices

The security controls we apply across infrastructure, access, and operational data.

Infrastructure

Certified data-center hosting, firewall/WAF, and layered network protection.

Access Control

Least-privilege access with production and development environments separated.

Encryption

TLS 1.3 in transit and AES-256 at rest.

Backup

Routine backups with adequate retention and periodic recovery testing.

Logging

Append-only audit trail for accountability and investigation.

Monitoring

Periodic system monitoring and security log review.

RBAC

Role-Based Access Control — access granted to fit each role.

MFA

Multi-Factor Authentication required for admin accounts and production access.

Sub-Processors

We rely on the following trusted infrastructure providers (sub-processors) to operate our products and services. Each sub-processor is bound by a data processing agreement (DPA) and security and confidentiality obligations equivalent to our standards.

Amazon Web Services (AWS) logo

Amazon Web Services (AWS)

Role: Cloud infrastructure, compute, and data storage

Scope: SaaS products

Vercel logo

Vercel

Role: Web application hosting and deployment

Scope: Website & web applications

Cloudflare logo

Cloudflare

Role: CDN, DNS, and network security protection (WAF)

Scope: All services

Material changes to this sub-processor list will be communicated through updates to this page. Details on personal data processing are available in our Privacy Policy.

Service Commitments (SLA)

A summary of availability and recovery commitments for our SaaS products. For consulting and VAPT services, delivery schedules and standards follow each engagement's Statement of Work.

VendorSphere · RiskSphere · AssetSphere · PeopleSphere · ComplianceSphere · AuditSphere · PrivacySphere

Uptime: 99.5% per monthCritical Response: 4 business hoursRTO: 8 hrsRPO: 24 hrs

GuardSphere

Uptime: 99.9% per monthCritical Response: 2 business hoursRTO: 4 hrsRPO: 8 hrs

Full SLA details — including compensation and exclusions — are set out in our Terms of Service (Section 6).

Privacy

Privacy Principles

  • Privacy by Design
  • Privacy by Default
  • Purpose Limitation
  • Data Minimization
  • Lawfulness
  • Transparency
  • Data Subject Rights

Customer Data Protection

  • Encrypted in transit
  • Encrypted at rest
  • Least Privilege Access
  • Need-to-Know Principle
  • Periodic Access Review

Responsible Disclosure

We believe collaboration with the security community makes everyone safer. If you discover a vulnerability in Cloudsphere's systems or services, please report it responsibly.

Submit your report by email to [email protected] with subject [SECURITY REPORT].

  • Vulnerability description, category (e.g. XSS, SQLi, IDOR), and potential impact.
  • Clear, reproducible steps to reproduce.
  • Proof of Concept without destroying or exfiltrating real data.
  • Your contact information for follow-up.

2 business days

Acknowledgment of your report

7 business days

Investigation status update

Safe harbor

No legal action for good-faith reports

Optional

Public credit if you wish

Incident Response

Cloudsphere maintains a documented incident response procedure following the NIST SP 800-61 incident-handling phases.

1Detection
2Containment
3Eradication
4Recovery
5Notification
6Lessons Learned

For incidents affecting personal data, notification follows UU PDP No. 27/2022 obligations (72-hour window).

Framework Alignment

A summary of the frameworks and regulations our security and privacy practices reference.

FrameworkStatus
PSE Komdigi Registered
UU PDP No. 27/2022 Implemented
ISO/IEC 27001:2022 Aligned
ISO/IEC 27701 Referenced
ISO 31000 Applied
NIST CSF 2.0 Referenced
OWASP ASVS Referenced
OWASP Top 10 Referenced

Cloudsphere continuously aligns its security and privacy practices with internationally recognized standards. Unless explicitly stated, references to standards or frameworks do not imply third-party certification.

Security Contact

For general security questions not related to vulnerability reporting:

Cloudsphere Security Team

Security Email: [email protected]

General Email: [email protected]

For non-security questions, use our Contact Us.