Third-Party Sources & Dependencies
CloudNexus maintains a transparent, audited registry of all external services, libraries, and infrastructure dependencies integrated into our platform. Each source is evaluated for security, compliance, and reliability standards.
| Provider / Source | Category | Purpose & Scope | Compliance | |
|---|---|---|---|---|
|
Amazon Web Services
Compute & Core Infrastructure
|
Infrastructure | Primary compute nodes, bare-metal provisioning, and regional fault isolation. | SOC 2 Type II ISO 27001 | View → |
|
Cloudflare
Edge Network & WAF
|
Networking | Global content delivery, DDoS mitigation, and Web Application Firewall rules. | GDPR CCPA | View → |
|
PostgreSQL Foundation
Database Engine
|
Data & Storage | Managed relational database clusters with automated failover and replication. | Open Source (BSD) | View → |
|
Prometheus & Grafana Labs
Metrics & Visualization
|
Monitoring | Real-time infrastructure telemetry, alerting pipelines, and dashboard rendering. | APACHE 2.0 | View → |
|
Let's Encrypt
Certificate Authority
|
Security | Automated TLS/SSL certificate provisioning and renewal for customer endpoints. | EAB Ready WebTrust | View → |
|
Snyk
Dependency Scanning
|
Security | Continuous vulnerability assessment for container images, IaC, and open-source packages. | SOC 2 Type II | View → |
|
HashiCorp (Terraform)
Infrastructure as Code
|
Infrastructure | Provisioning orchestration, state management, and drift detection across regions. | BSL 1.1 | View → |
|
PagerDuty
Incident Response
|
Monitoring | On-call routing, escalation policies, and real-time incident coordination for SRE teams. | HIPAA ISO 27001 | View → |
Vendor Management & Data Handling Policy
CloudNexus employs a strict third-party risk management framework aligned with ISO 27001 and SOC 2 Type II standards. All integrated services undergo quarterly security reviews, penetration testing validation, and data residency verification.
Customer data is never shared with third-party sources unless explicitly required for service delivery (e.g., SSL issuance, edge caching). All data in transit is encrypted via TLS 1.3+, and data at rest utilizes AES-256 encryption managed under customer-supplied keys (BYOK) where applicable.