CertifyClouds Privacy Policy¶
Last Updated: July 2026
This Privacy Policy explains how CertifyClouds ("we", "us", or "our") handles information when you use our software and services.
The Short Version¶
Your deployment and stored data stay under your control. CertifyClouds runs in your Azure environment. CertifyClouds-operated services do not receive your secret values, credentials, scan results, or audit logs. They receive license validation and, unless disabled, bounded aggregate Fleet Visibility counters. Optional integrations transmit selected data only to destinations your administrator configures.
1. Information We DO NOT Collect¶
CertifyClouds is designed with privacy in mind. We do NOT collect or have access to:
- Your Azure Key Vault secret values
- Your Azure credentials or tokens
- Your secret names or metadata
- Your compliance scan results
- Your audit logs
- Any data from your Azure environment
CertifyClouds application data is stored in your PostgreSQL database within your environment. Optional customer-configured integrations can transmit selected data directly to the destination chosen by your administrator.
2. Information We DO Collect¶
License Validation¶
When CertifyClouds validates your license, we receive:
| Data | Purpose | Retention |
|---|---|---|
| License key | Verify valid license | Permanent |
| Timestamp | Track validation requests | 90 days |
| Aggregate operational counters (optional - see below) | Support and improve your deployment | 30 days |
When fleet visibility is enabled (the default), the licence heartbeat also includes a small set of aggregate, anonymous operational counters, such as how many scans have run and how many items are nearing expiry, used solely to help us support and improve your deployment. It never includes names, resource identifiers, secret values, or scan contents. You can disable this at any time in Settings → Advanced → App Behaviour, and the data is retained for a maximum of 30 days.
Optional: Update Checks¶
If update checking is enabled, we receive:
| Data | Purpose | Retention |
|---|---|---|
| Current version | Determine if update available | Not stored |
Update checks happen automatically and will silently skip if the server is unreachable. No data is stored from update checks.
Optional: Hosted AI clients through MCP¶
The ENTERPRISE MCP Connector is disabled by default. If your administrator enables it and an authorized user invokes a read-only tool from a hosted AI client, CertifyClouds sends that tool's result over TLS directly to the selected provider. Results can contain asset names and identifiers, expiry metadata, dependency relationships, compliance findings, or scoped audit events.
CertifyClouds-operated services do not receive MCP tool results. The selected provider processes them under your agreement and settings with that provider. MCP Phase 1 does not return bearer tokens, secret values, private keys, certificate material, or value-shaped hints. Your administrator can close this data path by disabling the connector in Settings -> MCP Connector.
3. How We Use Information¶
We use the limited information we collect to:
- Validate your license is active and not expired
- Prevent license key sharing or abuse
- Provide version update notifications
- Improve our service (aggregate, anonymized usage)
We do NOT use your information to:
- Sell to third parties
- Send marketing communications (unless you opt in)
- Profile your Azure environment
- Track your secret management practices
4. Data Storage and Security¶
License Server¶
Our license validation server (license.certifyclouds.com) is:
- Hosted on Cloudflare's global edge network
- Protected by DDoS mitigation
- Encrypted in transit (TLS 1.3)
- Minimal data retention (90 days for logs)
Your Environment¶
All CertifyClouds application data is stored in your environment:
- PostgreSQL database (you control)
- Docker volumes (you control)
- Log files (you control)
We have no administrative access to your environment or stored application data.
5. Data Sharing¶
We do not sell or rent your information. CertifyClouds-operated services share the limited information they receive only in these circumstances:
- Service Providers: Cloudflare (hosting) - see their privacy policy
- Legal Requirements: If required by law, subpoena, or legal process
- Business Transfer: In connection with a merger or acquisition (with notice)
6. Your Rights¶
Depending on your jurisdiction, you may have rights to:
- Access: Know what data we have about you
- Correction: Fix inaccurate data
- Deletion: Request deletion of your data
- Portability: Receive your data in portable format
- Objection: Object to certain processing
To exercise these rights, contact: privacy@certifyclouds.com
7. Data Retention¶
| Data Type | Retention Period |
|---|---|
| License records | Duration of license + 1 year |
| Validation logs | 90 days |
| Support communications | 2 years |
| Legal/compliance records | As required by law |
8. International Transfers¶
Our license server is hosted on Cloudflare's global network. Your license validation request may be processed in various countries. Cloudflare maintains appropriate safeguards for international data transfers.
9. Children's Privacy¶
CertifyClouds is a business software product. We do not knowingly collect information from children under 16. If you believe a child has provided information to us, contact privacy@certifyclouds.com.
10. Changes to This Policy¶
We may update this Privacy Policy periodically. Changes will be posted at:
- https://certifyclouds.com/privacy
- In the product documentation at docs.certifyclouds.com
Continued use after changes constitutes acceptance.
11. Contact Us¶
For privacy questions or concerns:
- Email: privacy@certifyclouds.com
- Website: https://certifyclouds.com
Summary Table¶
| Question | Answer |
|---|---|
| Do you see my secrets? | No |
| Do you store my Azure data? | No |
| What do you collect? | License key, validation timestamp, and (unless disabled) aggregate anonymous operational counters |
| Can I use this offline? | Yes, with cached license (7-day grace) |
| Can an integration send data elsewhere? | Only when your administrator configures it; hosted MCP sends selected read-only results to your chosen AI provider |
| Who controls access to my scans? | Your organization |
By using CertifyClouds, you acknowledge that you have read and understood this Privacy Policy.