Regulatory & Compliance
Compliance with Indonesian regulation and international data-protection principles is foundational to our services.
Private Electronic System Provider (PSE)
Status
Registered
Registration (PB UMKU)
130726010770200020001
Authority
Ministry of Communication and Digital (Komdigi)
Issued
17 July 2026
Personal Data Protection Law
Cloudsphere processes personal data in accordance with Law No. 27 of 2022 concerning Personal Data Protection (UU PDP). We implement technical and organizational safeguards to protect personal information and respect the rights of data subjects.
GDPR
Although Cloudsphere is established in Indonesia, our privacy practices are designed with reference to the General Data Protection Regulation (GDPR) principles, including lawfulness, transparency, data minimization, purpose limitation, and accountability.
Information Security
ISO/IEC 27001:2022
Cloudsphere develops its services in alignment with ISO/IEC 27001:2022 Information Security Management System (ISMS) principles.
Status
Aligned with ISO/IEC 27001:2022
Certification
Not Certified
ISO/IEC 27701 — Privacy Information Management
Cloudsphere references ISO/IEC 27701 when designing privacy governance and personal data protection controls.
Status
Aligned
Certification
Not Certified
Security Practices
The security controls we apply across infrastructure, access, and operational data.
Infrastructure
Certified data-center hosting, firewall/WAF, and layered network protection.
Access Control
Least-privilege access with production and development environments separated.
Encryption
TLS 1.3 in transit and AES-256 at rest.
Backup
Routine backups with adequate retention and periodic recovery testing.
Logging
Append-only audit trail for accountability and investigation.
Monitoring
Periodic system monitoring and security log review.
RBAC
Role-Based Access Control — access granted to fit each role.
MFA
Multi-Factor Authentication required for admin accounts and production access.
Sub-Processors
We rely on the following trusted infrastructure providers (sub-processors) to operate our products and services. Each sub-processor is bound by a data processing agreement (DPA) and security and confidentiality obligations equivalent to our standards.
Amazon Web Services (AWS)
Role: Cloud infrastructure, compute, and data storage
Scope: SaaS products
Vercel
Role: Web application hosting and deployment
Scope: Website & web applications
Cloudflare
Role: CDN, DNS, and network security protection (WAF)
Scope: All services
Material changes to this sub-processor list will be communicated through updates to this page. Details on personal data processing are available in our Privacy Policy.
Service Commitments (SLA)
A summary of availability and recovery commitments for our SaaS products. For consulting and VAPT services, delivery schedules and standards follow each engagement's Statement of Work.
VendorSphere · RiskSphere · AssetSphere · PeopleSphere · ComplianceSphere · AuditSphere · PrivacySphere
GuardSphere
Full SLA details — including compensation and exclusions — are set out in our Terms of Service (Section 6).
Privacy
Privacy Principles
- Privacy by Design
- Privacy by Default
- Purpose Limitation
- Data Minimization
- Lawfulness
- Transparency
- Data Subject Rights
Customer Data Protection
- Encrypted in transit
- Encrypted at rest
- Least Privilege Access
- Need-to-Know Principle
- Periodic Access Review
Responsible Disclosure
We believe collaboration with the security community makes everyone safer. If you discover a vulnerability in Cloudsphere's systems or services, please report it responsibly.
Submit your report by email to [email protected] with subject [SECURITY REPORT].
- Vulnerability description, category (e.g. XSS, SQLi, IDOR), and potential impact.
- Clear, reproducible steps to reproduce.
- Proof of Concept without destroying or exfiltrating real data.
- Your contact information for follow-up.
2 business days
Acknowledgment of your report
7 business days
Investigation status update
Safe harbor
No legal action for good-faith reports
Optional
Public credit if you wish
Incident Response
Cloudsphere maintains a documented incident response procedure following the NIST SP 800-61 incident-handling phases.
For incidents affecting personal data, notification follows UU PDP No. 27/2022 obligations (72-hour window).
Framework Alignment
A summary of the frameworks and regulations our security and privacy practices reference.
| Framework | Status |
|---|---|
| PSE Komdigi | Registered |
| UU PDP No. 27/2022 | Implemented |
| ISO/IEC 27001:2022 | Aligned |
| ISO/IEC 27701 | Referenced |
| ISO 31000 | Applied |
| NIST CSF 2.0 | Referenced |
| OWASP ASVS | Referenced |
| OWASP Top 10 | Referenced |
Cloudsphere continuously aligns its security and privacy practices with internationally recognized standards. Unless explicitly stated, references to standards or frameworks do not imply third-party certification.
Security Contact
For general security questions not related to vulnerability reporting:
Cloudsphere Security Team
Security Email: [email protected]
General Email: [email protected]
For non-security questions, use our Contact Us.