Cloud Armor IT Consultancy logo

Legal

Privacy Policy

We are a security company, so we hold ourselves to the standard we sell. This page sets out plainly what we collect, who touches it, how long we keep it — and how your data stays separated from every other customer's.

Last updated 11 August 2026

1. Who we are

Cloud Armor is an enterprise cybersecurity consultancy and managed security service provider (MSSP). We deliver security engineering and advisory services, and we operate two platforms: Ayati One, our managed security operations platform, and AyatiOne Code, our Opengrep-based code quality and security analysis tool.

Services are contracted through the Cloud Armor entity appropriate to your region. Each entity is the data controller for its own customer and marketing records, and acts as a data processor when handling data on your behalf through our platforms:

  • India

    Cloud Armor IT Consultancy Pvt. Ltd., 2nd Floor, 79, Kavuri Hills Rd, opposite Kapston Services, Kavuri Hills, Madhapur, Hyderabad, Telangana 500081.

  • United Arab Emirates

    Cloud Armor IT Consultancy FZCO, Building A1, IFZA Business Park, DDP, Premises No: 78829-001, Dubai.

  • United States

    MeghArmor IT Solutions LLC, Suite 447, 2nd Floor, Broadway, New York, NY 10013.

2. What this policy covers

This policy explains how we collect, use, share, protect and retain information across three distinct contexts, which are governed by different rules and should not be confused with one another:

  • This website

    Information you give us directly through our contact and pricing forms, and limited analytics about how the site is used. Here we act as a data controller.

  • Ayati One

    Security telemetry, logs, alerts and incident records processed on your behalf under your service agreement. Here we act as a data processor, and you remain the controller of your own data.

  • AyatiOne Code

    Source code analysis and the findings it produces, delivered either as a hosted service on your own subdomain or installed inside your infrastructure. Here we also act as a data processor, and the data flows differ materially between those two models — see section 6.

3. Information collected through this website

We deliberately keep this minimal. We do not sell personal information, we do not operate advertising trackers, and we do not build marketing profiles of site visitors.

  • Contact and pricing enquiries

    When you submit an enquiry we collect your name, company, email address, any phone number you provide and the content of your message. It is stored in our enquiry inbox and emailed to our team so we can respond. We use it to reply to you and to maintain a record of the enquiry — nothing else.

  • Analytics

    We use Google Analytics 4 to understand aggregate site usage — pages viewed, approximate location and device type. This relies on cookies set by Google. You can block it with any standard cookie or script blocker, or with browser Do Not Track settings, without losing access to any part of this site.

  • Server logs

    Our web server records standard request logs, including IP address and user agent, for security monitoring and troubleshooting. These are operational security records, not a marketing dataset.

4. Information processed through Ayati One

Ayati One exists to detect and respond to threats in your environment, which means it necessarily processes data about your systems and the people using them. We process this strictly on your documented instructions, for the purpose of delivering the security service you have contracted, and for no independent purpose of our own. We do not use your security telemetry to train models, and we do not sell or share it for commercial purposes.

Depending on which modules you enable, this can include:

  • Endpoint and server telemetry

    Hostnames, operating system and hardware details, installed software and versions, patch state, running processes, and the local or domain user account associated with an event.

  • Security event and log data

    Operating system event logs, network metadata such as source and destination IP addresses, DNS and TLS records, firewall and network device logs collected by our agents or log collectors.

  • Identity and cloud activity

    Sign-in and audit events pulled from your own identity provider or cloud tenancy — for example Microsoft Entra sign-in logs — where you have connected those sources. These commonly contain usernames, email addresses and IP addresses.

  • Alerts, incidents and case records

    Detections, correlated incidents, analyst notes, tasks, comments and attachments, together with the identity of the analyst or user who took each action.

  • Platform user accounts

    The names, usernames and email addresses of your staff who hold Ayati One logins, and an audit record of their actions in the console.

5. How we keep your data separate from other customers

This is the question every prospective customer of a multi-tenant security platform should ask, so we answer it concretely rather than in general assurances.

Ayati One is not a shared database with a customer identifier column. Each tenant is provisioned with its own separate physical database, created at onboarding and named for that tenant alone. There is no shared table in which one customer's events sit alongside another's, which means a query cannot accidentally return another tenant's records — the data is not there to return.

  • Separate databases per tenant

    Every customer's telemetry, alerts, incidents and user accounts live in a database dedicated to that customer. Provisioning a new tenant creates an empty database and applies the baseline schema; no data is ever copied from an existing tenant.

  • Request-scoped tenant routing

    Every authenticated request is resolved to exactly one tenant and served from that tenant's connection. A session issued for one tenant cannot be used to read another.

  • Isolated credentials and secrets

    Connector credentials, scan credentials and integration secrets are stored encrypted with AES-256-GCM inside the owning tenant's database. They are never shared across tenants and are never written to logs.

  • Separated administrative planes

    The control plane used to create and manage tenants is a distinct application from the tenant consoles your team uses, with its own authentication. Access to it is restricted to authorised Cloud Armor administrators.

  • Staff access on a need-to-know basis

    Our SOC analysts access customer environments only as required to deliver the contracted service. Access is authenticated, role-based and recorded in an append-only audit log that shows who did what and when.

6. Source code and AyatiOne Code

Source code is among the most sensitive material a customer can entrust to a supplier, so we set out plainly where it goes. AyatiOne Code is offered in two deployment models and the data flows differ materially between them. Which one applies to you is recorded in your engagement documentation.

  • Hosted (SaaS)

    We run AyatiOne Code for you on your own subdomain — your-organisation.code.ayati.one. Repositories you connect, or source archives you upload, are analysed inside that tenant, and the findings are stored there. This is the model to assume applies unless your agreement says otherwise.

  • On-premise

    AyatiOne Code is installed inside your own infrastructure, on a hostname you choose. Your source code, findings and scan history never leave your environment and we hold no copy of them. Our access is limited to whatever support arrangement you have separately agreed.

  • What the analysis processes

    Source files, repository and branch metadata, commit and author identifiers where present in the repository, resolved dependencies and their licences, and the findings produced — rule identifier, severity, CWE and OWASP classification, file path, line number and a short code excerpt as evidence. Where a customer uses the hosted model, uploaded source archives are retained so that a scan can be reproduced and audited; they are deleted when you delete the project or on request.

  • Detected secrets are masked, never stored

    The secret scanner reports that a credential was found and where, but persists only a masked value. The raw secret is never written to our database, our logs or our reports — so a finding cannot itself become the means of a compromise.

  • Analysis runs locally, not through third parties

    The scanning engines — Opengrep for static analysis, osv-scanner for dependencies, gitleaks for secrets, and the OpenAPI and code-quality tooling — all execute inside the deployment that holds your code. Your source is not sent to any external analysis service. Only package identifiers and version numbers are matched against public vulnerability data (the OSV and NIST NVD databases) to establish which components carry known CVEs.

  • What we never do with your code

    We do not use customer source code to train any machine-learning model, we do not share it with other customers, and we do not use it for any purpose beyond delivering the analysis you have contracted.

7. How we protect information

Cloud Armor operates an Information Security Management System certified to ISO/IEC 27001, and holds a SOC 2 Type II attestation for its security controls. Our controls are audited rather than self-asserted.

In practical terms, the measures protecting your data include:

  • Encryption of data in transit using TLS 1.2 or 1.3, enforced by HTTP Strict Transport Security so that a browser will not fall back to an unencrypted connection, and mutual TLS for agent-to-platform communication.

  • Encryption at rest of stored credentials and integration secrets using AES-256-GCM. Account passwords are stored only as bcrypt hashes and are never recoverable, by us or by anyone else.

  • Role-based access control with per-user permissions limiting which modules and data a user can reach, re-checked against the database on every request rather than trusted from the session.

  • Short-lived access tokens with separately revocable refresh sessions, so that deactivating an account ends its live sessions rather than waiting for them to expire.

  • Audit logging of privileged and analyst actions, retained so that access to your data can be reconstructed after the fact. No interface is exposed for deleting or altering an audit record.

  • Segregation of production from non-production environments, with customer data excluded from testing and development.

  • Continuous automated security testing of our own platforms — static analysis, dependency and secret scanning run against our own code on every change and nightly, with release gates that block a build on new critical findings. We apply to ourselves the practices we sell.

  • Background-checked personnel bound by confidentiality obligations, with security awareness training and access removed promptly when someone leaves or changes role.

8. Third parties who may process data

We keep the number of parties touching customer data deliberately small. Where a third party is involved, it is bound by contract to confidentiality and to processing only on our instructions. The services below may be involved in delivering Ayati One and AyatiOne Code. We do not sell personal data and we do not share it for advertising.

  • Threat intelligence enrichment

    VirusTotal and AbuseIPDB may be queried to establish the reputation of a technical indicator — an IP address, domain or file hash. Only the indicator itself is sent. We do not send message content, log contents or the identity of the customer being investigated.

  • Breach and exposure intelligence

    Where you enable the email and domain monitoring module, DeHashed is queried to check whether your domains or staff email addresses appear in known credential breaches. This means an email address you ask us to monitor is sent to that service for the lookup. The purpose is to warn you that a credential is already exposed; results are returned to your tenant and not used for anything else.

  • Public vulnerability data

    We match the software found in your estate against the NIST National Vulnerability Database and the Open Source Vulnerabilities database to identify known CVEs. This is a one-way lookup of public data into our platform — no information about you, your estate or your code is sent to either source.

  • Your own cloud and identity providers

    Where you connect Microsoft 365, Microsoft Entra or another cloud provider, we read from those systems using credentials you authorise. Data flows from your tenancy to your Ayati One tenant; we do not write your data into any third-party system in the process.

  • AI-assisted triage

    Ayati One can summarise and triage alerts using a locally hosted model running inside our own infrastructure, which is the default — alert data is not sent to an external AI provider in that configuration. If a third-party AI service is enabled for your tenant, that is done only with your agreement and recorded in your service documentation. AI output is advisory only and never executes actions.

  • Infrastructure and communications

    Our platforms are hosted on Microsoft Azure, primarily in the India region, and we use Microsoft 365 for business email and collaboration when corresponding with you. A current list of sub-processors, with the role each plays, is available on request.

9. International transfers

We operate from India, the United Arab Emirates and the United States, and we host customer environments in more than one region. The region in which your data resides is determined by the Cloud Armor entity you contract with and is recorded in your service documentation; where data residency is a regulatory requirement for you, Ayati One can also be deployed into your own cloud tenancy or on-premises so that your data never leaves your infrastructure.

Where personal data does move between countries — for example when a follow-the-sun SOC analyst in another region works your case — the transfer is covered by contractual safeguards between our entities and limited to what delivering the service requires.

10. How long we keep information

Retention is configurable per customer and per module, because the right period depends on your regulatory obligations rather than ours. The periods applying to you are set in your service configuration and agreement.

  • Security event data

    Retained for the period configured for your tenant. Where no period has been set, event data is retained for the duration of the engagement and is not automatically purged — if you require a fixed retention window, tell us and we will configure it.

  • Vulnerability and application scan findings

    Retained for 180 days by default, adjustable to your requirements.

  • Incident and case records

    Retained for the life of the engagement so that investigations remain auditable, then deleted or returned in line with your agreement.

  • Source code and scan history (AyatiOne Code)

    In the hosted model, uploaded source archives and scan results are retained for the life of the project so that a finding can be reproduced and evidenced to an auditor. Deleting a project deletes them, and we will delete them earlier on request. In the on-premise model this is entirely under your control and we hold nothing. If you need a fixed retention window on hosted projects, tell us and we will configure it.

  • Website enquiries

    Retained for as long as needed to respond and to keep a record of our correspondence with you.

  • On termination

    At the end of an engagement we delete or return customer data as instructed in your agreement, subject to any legal obligation requiring us to retain a copy.

11. Your rights

Depending on where you are located, you may have rights to access the personal data we hold about you, to have it corrected or erased, to object to or restrict its processing, to receive a copy in portable form, and to complain to a supervisory authority. In India these rights arise under the Digital Personal Data Protection Act 2023; in the European Economic Area and the United Kingdom under the GDPR; and comparable rights exist in other jurisdictions where we operate.

An important distinction applies to data inside Ayati One or AyatiOne Code. Where we process data on behalf of a customer, that customer is the controller and we are the processor. If you are an employee of one of our customers and wish to exercise rights over data held in their tenant, you should approach your own organisation. If you contact us directly, we will refer your request to them rather than act on it unilaterally, because acting on it ourselves would undermine the very isolation described in section 5.

12. Security incidents affecting personal data

If we become aware of a personal data breach affecting your data, we will notify you without undue delay, with the facts as established, the categories and approximate volume of data involved, the likely consequences and the measures we are taking. We will support you in meeting your own notification obligations to regulators and affected individuals.

Where an incident falls within the reporting directions issued by CERT-In, the Indian national computer emergency response team, reporting is made within the required six-hour window. Ayati One is built to make that deadline achievable, capturing the incident record structurally so that the required detail exists at the moment it is needed rather than being reconstructed under time pressure.

13. Children

Our services are sold to organisations and are not directed at children. We do not knowingly collect personal data from anyone under the age of 18 through this website.

14. Changes to this policy

We review this policy periodically and when our services or obligations change. The date at the top of this page shows when it was last updated. Where a change materially affects how we handle customer data, we will notify affected customers directly rather than relying on this page alone.

15. How to contact us

For any question about this policy, to exercise your rights, or to raise a privacy grievance, contact us and we will respond. Please mark your message for the attention of the privacy team so it reaches the right people quickly.

Data Protection Officer
Venkat Anjan venkat@cloudarmor.in
Grievance Officer (India)
Venkat Anjan venkat@cloudarmor.in. Appointed under the Digital Personal Data Protection Act 2023. If you are not satisfied with our response you may complain to the Data Protection Board of India, or to your own supervisory authority where the GDPR or another regime applies.
info@cloudarmor.in
  • Cloud Armor IT Consultancy Pvt. Ltd.

    2nd Floor, 79, Kavuri Hills Rd, opposite Kapston Services, Kavuri Hills, Madhapur, Hyderabad, Telangana 500081

    +91 888 567 1802

  • Cloud Armor IT Consultancy FZCO

    Building A1, IFZA Business Park, DDP, Premises No: 78829 - 001, Dubai

    +971 58 595 1802

  • MeghArmor IT Solutions LLC

    Suite 447, 2nd Floor, Broadway, New York, NY 10013, USA

If you are an employee of one of our customers and your request concerns data held in their Ayati One or AyatiOne Code tenant, please contact your own organisation first — see section 11 for why. For anything else, our contact page reaches the same team.