Security at Cloudrms

How we protect your RMS Cloud API credentials, your account data and your module configuration from unauthorised access.

API credential encryption

Your RMS Cloud API key is stored at rest with symmetric AES-256 encryption. The encryption key is kept separate from the data in a dedicated key management system. API keys are never logged in clear text.

TLS 1.3 in transit

Every communication between your browser, the Cloudrms platform and the RMS Cloud API uses TLS 1.3. Earlier TLS versions are not accepted. HSTS is enabled on the cloudrms.org domain.

Access controls

Staff access to production systems follows the principle of least privilege. Support can view account metadata and billing data but cannot see API keys in clear text. Access to production data requires two-factor authentication.

Security testing

Cloudrms undergoes an annual penetration test by an independent security firm. Critical vulnerabilities are fixed within 72 hours. High-severity findings within 14 days.

Incident response

In the event of an eligible data breach within the meaning of Part IIIC of the Privacy Act 1988 (Cth), affected customers and the Office of the Australian Information Commissioner (OAIC) are notified without undue delay under the Notifiable Data Breaches scheme. A public incident report is published within 30 days.

Responsible disclosure

Spotted a vulnerability? Write to security@cloudrms.org with the details. We reply within 24 hours and credit researchers who report valid findings responsibly.