TRUST & SECURITY

Security without unsupported claims

CloudForge documents controls that are actually implemented. Framework support is not a certification.

Framework support

NIS2Directive (EU) 2022/2555
Product-ready
Austria NISG 2026BGBl. I Nr. 94/2025
Partial
GDPR / DSGVORegulation (EU) 2016/679
Partial
EU AI ActRegulation (EU) 2024/1689
Product-ready
ISO/IEC 27001:20222022
Reference mapping
ISO/IEC 27001:20132013
Deprecated
NIST Cybersecurity Framework 2.02.0
Partial
DORARegulation (EU) 2022/2554
Partial
Cyber Resilience ActRegulation (EU) 2024/2847
Planned
NIST AI RMF 1.01.0
Partial
ISO/IEC 42001:20232023
Reference mapping
ISO/IEC 27017:20262026
Reference mapping
ISO/IEC 27018:20252025
Reference mapping
CIS Controls 8.18.1
License required
SOC 2TSP Section 100 (2022)
Product-ready
BSI C5C5:2026 v1.0.1
Product-ready
BSI C5:2020C5:2020 v1.0
Deprecated
TISAX / VDA ISAVDA ISA 6.0.3
Product-ready
TISAX / VDA ISA 2027VDA ISA 2027
Planned

Technical safeguards

EU data residency

Production and customer data for the current service are operated in the EU; customer-specific contractual commitments are documented separately.

Transport encryption

Public endpoints use HTTPS. Internal transport and certificate configuration are monitored operationally.

Tenant isolation

API access is constrained through organization context, roles and server-side tenant checks.

MFA for privileged roles

Platform and privileged organization roles require MFA and a verified session.

Auditable administration

Critical user, MFA, membership and organization changes are stored as audit events.

Secure delivery

Release contracts, type checks, tests, isolated preflights, health checks and controlled rollback are part of deployment.

Vulnerability disclosure

Found a security issue? Report it directly. We will acknowledge receipt as quickly as possible.

security@cloudforge.team

Responsible disclosure. Do not publish exploit details before a coordinated fix.

CloudForge Team — Cloud, Container and AI under control