Skip to content

CertifyClouds Privacy Policy

Last Updated: July 2026

This Privacy Policy explains how CertifyClouds ("we", "us", or "our") handles information when you use our software and services.


The Short Version

Your deployment and stored data stay under your control. CertifyClouds runs in your Azure environment. CertifyClouds-operated services do not receive your secret values, credentials, scan results, or audit logs. They receive license validation and, unless disabled, bounded aggregate Fleet Visibility counters. Optional integrations transmit selected data only to destinations your administrator configures.


1. Information We DO NOT Collect

CertifyClouds is designed with privacy in mind. We do NOT collect or have access to:

  • Your Azure Key Vault secret values
  • Your Azure credentials or tokens
  • Your secret names or metadata
  • Your compliance scan results
  • Your audit logs
  • Any data from your Azure environment

CertifyClouds application data is stored in your PostgreSQL database within your environment. Optional customer-configured integrations can transmit selected data directly to the destination chosen by your administrator.


2. Information We DO Collect

License Validation

When CertifyClouds validates your license, we receive:

Data Purpose Retention
License key Verify valid license Permanent
Timestamp Track validation requests 90 days
Aggregate operational counters (optional - see below) Support and improve your deployment 30 days

When fleet visibility is enabled (the default), the licence heartbeat also includes a small set of aggregate, anonymous operational counters, such as how many scans have run and how many items are nearing expiry, used solely to help us support and improve your deployment. It never includes names, resource identifiers, secret values, or scan contents. You can disable this at any time in Settings → Advanced → App Behaviour, and the data is retained for a maximum of 30 days.

Optional: Update Checks

If update checking is enabled, we receive:

Data Purpose Retention
Current version Determine if update available Not stored

Update checks happen automatically and will silently skip if the server is unreachable. No data is stored from update checks.

Optional: Hosted AI clients through MCP

The ENTERPRISE MCP Connector is disabled by default. If your administrator enables it and an authorized user invokes a read-only tool from a hosted AI client, CertifyClouds sends that tool's result over TLS directly to the selected provider. Results can contain asset names and identifiers, expiry metadata, dependency relationships, compliance findings, or scoped audit events.

CertifyClouds-operated services do not receive MCP tool results. The selected provider processes them under your agreement and settings with that provider. MCP Phase 1 does not return bearer tokens, secret values, private keys, certificate material, or value-shaped hints. Your administrator can close this data path by disabling the connector in Settings -> MCP Connector.


3. How We Use Information

We use the limited information we collect to:

  • Validate your license is active and not expired
  • Prevent license key sharing or abuse
  • Provide version update notifications
  • Improve our service (aggregate, anonymized usage)

We do NOT use your information to:

  • Sell to third parties
  • Send marketing communications (unless you opt in)
  • Profile your Azure environment
  • Track your secret management practices

4. Data Storage and Security

License Server

Our license validation server (license.certifyclouds.com) is:

  • Hosted on Cloudflare's global edge network
  • Protected by DDoS mitigation
  • Encrypted in transit (TLS 1.3)
  • Minimal data retention (90 days for logs)

Your Environment

All CertifyClouds application data is stored in your environment:

  • PostgreSQL database (you control)
  • Docker volumes (you control)
  • Log files (you control)

We have no administrative access to your environment or stored application data.


5. Data Sharing

We do not sell or rent your information. CertifyClouds-operated services share the limited information they receive only in these circumstances:

  • Service Providers: Cloudflare (hosting) - see their privacy policy
  • Legal Requirements: If required by law, subpoena, or legal process
  • Business Transfer: In connection with a merger or acquisition (with notice)

6. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access: Know what data we have about you
  • Correction: Fix inaccurate data
  • Deletion: Request deletion of your data
  • Portability: Receive your data in portable format
  • Objection: Object to certain processing

To exercise these rights, contact: privacy@certifyclouds.com


7. Data Retention

Data Type Retention Period
License records Duration of license + 1 year
Validation logs 90 days
Support communications 2 years
Legal/compliance records As required by law

8. International Transfers

Our license server is hosted on Cloudflare's global network. Your license validation request may be processed in various countries. Cloudflare maintains appropriate safeguards for international data transfers.


9. Children's Privacy

CertifyClouds is a business software product. We do not knowingly collect information from children under 16. If you believe a child has provided information to us, contact privacy@certifyclouds.com.


10. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted at:

Continued use after changes constitutes acceptance.


11. Contact Us

For privacy questions or concerns:

  • Email: privacy@certifyclouds.com
  • Website: https://certifyclouds.com

Summary Table

Question Answer
Do you see my secrets? No
Do you store my Azure data? No
What do you collect? License key, validation timestamp, and (unless disabled) aggregate anonymous operational counters
Can I use this offline? Yes, with cached license (7-day grace)
Can an integration send data elsewhere? Only when your administrator configures it; hosted MCP sends selected read-only results to your chosen AI provider
Who controls access to my scans? Your organization

By using CertifyClouds, you acknowledge that you have read and understood this Privacy Policy.