Security Policy

Effective Date: July 31, 2026

Valorem Cloud is committed to protecting the security and confidentiality of your information. This Security Policy outlines the measures we take to safeguard your data.

Data Protection

We implement industry-standard security measures to protect your information from unauthorized access, alteration, disclosure, or destruction.

Encryption

  • All data transmission is encrypted using TLS 1.2 or higher
  • Sensitive data at rest is encrypted using AES-256 encryption
  • Passwords are hashed using bcrypt with salt

Access Controls

  • Role-based access controls limit data access to authorized personnel only
  • Multi-factor authentication is required for all administrative access
  • Regular access reviews ensure appropriate permissions

AWS Assessment Security

Read-Only Access

Our AWS cost optimization assessments use read-only access with minimal required permissions:

  • Temporary IAM roles with time-limited access
  • Least-privilege permissions based on specific assessment needs
  • No root account access required
  • Full audit trail through AWS CloudTrail

Data Handling

  • Billing data is securely downloaded and encrypted during transfer
  • All data is deleted from our systems within 30 days of assessment completion
  • Confidential information is handled under strict non-disclosure agreements
  • Physical and digital security measures protect data during analysis

Incident Response

We maintain an incident response plan to quickly address any security events:

  • 24/7 monitoring of security systems
  • Immediate notification of security incidents
  • Regular security assessments and penetration testing
  • Continuous improvement of security measures

Compliance

While we are not currently certified under specific compliance frameworks, we follow industry best practices for data protection and security.

Contact Us

If you have any questions about our security practices, please contact us at: security@valoremcloud.com

Disclaimer: This is a general template and should be reviewed by a qualified security professional to ensure compliance with applicable standards and regulations.