Compliance & Security

CloudNexus is built to meet the strictest regulatory and security requirements. Our infrastructure undergoes regular third-party audits, and we maintain full transparency around data handling, encryption, and access controls.

SOC 2 Type II Certified ISO 27001 & 27018 GDPR Compliant HIPAA Ready

Certifications & Audits

Independently verified certifications demonstrating our commitment to security, privacy, and operational excellence.

🛡️
SOC 2 Type II
Active & Current
Annual audit covering security, availability, and confidentiality controls across all data centers and management interfaces.
Valid through: Dec 2026
📜
ISO/IEC 27001
Active & Current
International standard for information security management systems (ISMS) governing risk assessment and treatment.
Valid through: Mar 2027
🔒
ISO/IEC 27018
Active & Current
Code of practice for protection of personally identifiable information (PII) in public cloud environments.
Valid through: Mar 2027
🇪🇺
GDPR Compliance
Fully Compliant
End-to-end data protection alignment with EU regulations, including data minimization, breach notification, and DPA execution.
Continuous Compliance
🏥
HIPAA BAA
Available
Business Associate Agreements available for healthcare workloads. Encrypted at rest and in transit with strict access logging.
Upon Request
💳
PCI DSS
Level 1 Scope
Infrastructure meets PCI DSS requirements for payment data processing. Scope reduction available via network segmentation.
Annual Assessment

Security Framework Mapping

Our platform controls mapped to industry-standard frameworks and regulatory requirements.

Control Category SOC 2 ISO 27001 GDPR HIPAA
Data Encryption (AES-256 / TLS 1.3)✓ Supported✓ Mapped✓ Aligned✓ Compliant
Access Control & RBAC✓ Supported✓ Mapped✓ Aligned✓ Compliant
Audit Logging & Monitoring✓ Supported✓ Mapped✓ Aligned✓ Compliant
Physical Data Center Security✓ Supported✓ Mapped✓ Aligned✓ Compliant
Incident Response & Breach Notification✓ Supported✓ Mapped✓ Aligned✓ Compliant
Data Residency & Sovereignty✓ Supported✓ Mapped✓ Aligned⚠ Region-Dependent
Third-Party Risk Management✓ Supported✓ Mapped✓ Aligned✓ Compliant

Compliance Resources & Downloads

Access legal agreements, security documentation, and audit summaries directly.

📄PDF • 2.4 MB
Data Processing Agreement (DPA)
Standard DPA template aligned with GDPR, CCPA, and international data transfer requirements.
🏥PDF • 1.1 MB
Business Associate Agreement (BAA)
HIPAA-compliant BAA for protected health information (PHI) processing and storage workloads.
📊PDF • 3.8 MB
Security Architecture Whitepaper
Technical overview of network segmentation, encryption standards, identity management, and monitoring.
🔍PDF • 1.5 MB
Redacted Audit Summary
High-level summary of latest third-party security assessments and remediation tracking.

Frequently Asked Questions

Common compliance, security, and audit inquiries from enterprise customers.

Where is my data physically stored?
CloudNexus operates 50+ data centers across 6 continents. You can select specific regions at deployment, and your data remains strictly within your chosen jurisdiction unless explicitly replicated by your configuration. Data residency guarantees are documented in our DPA.
How is data encrypted at rest and in transit?
All data is encrypted in transit using TLS 1.3. At rest, we use AES-256 encryption with keys managed via our FIPS 140-2 Level 2 validated KMS. Customer-managed keys (CMK) are available for Professional and Enterprise tiers.
Can I access full audit logs for compliance reporting?
Yes. CloudNexus provides immutable, tamper-proof audit logs capturing all administrative actions, API calls, and infrastructure changes. Logs can be exported in JSON/CSV or streamed to your SIEM via our Logpush API.
Do you support third-party security questionnaires (SIG, CAIQ)?
Absolutely. We maintain pre-approved responses to SIG Lite, CAIQ v3.0, and standard vendor risk assessment templates. Enterprise customers can request access to our secure compliance portal for instant questionnaire auto-filling.
How are security incidents handled and communicated?
Our incident response team follows a documented playbook aligned with NIST SP 800-61. Affected customers receive notification within 24 hours of confirmed impact, followed by regular status updates until resolution and post-mortem publication.

Need Custom Compliance Documentation?

Our dedicated Trust & Compliance team handles enterprise security reviews, vendor risk assessments, and custom DPA/BAA execution.