Skip to content

Security

CloudRebuild protects backup data with AES-256-GCM encryption at rest and in transit, supports bring-your-own-key via Azure Key Vault, and runs on SOC 2 Type II compliant infrastructure. Recovery points are immutable and integrity-verified on every backup.

Encryption and key management

  • AES-256-GCM encryption for data at rest and in transit.
  • Bring-your-own-key (BYOK) support, so encryption keys remain under your control.
  • Azure Key Vault integration for key storage and rotation.

Access control

  • Zero-trust architecture with least-privilege access throughout.
  • Cloud accounts are connected with read-only discovery permissions.
  • Isolated execution engines: cloud infrastructure backup and SaaS backup run with separate runtimes, queues and database schemas.

Backup integrity

  • Immutable recovery points that cannot be altered after they are written.
  • Automatic integrity verification on every backup.
  • Immutable backup manifests supporting audit and regulatory evidence.
  • Redundant storage across availability zones with multi-region replication.

Compliance

CloudRebuild runs on SOC 2 Type II compliant infrastructure. Automated retention rules and audit trails are built in to support regulatory requirements around data retention and recoverability.

Reliability

  • 99.99% uptime SLA.
  • 24/7 monitoring with automated failover.
  • Recovery time objective of under 15 minutes.

Reporting a vulnerability

If you believe you have found a security issue in CloudRebuild, please contact us at security@cloudrebuild.com. We will acknowledge your report and keep you updated while we investigate.

Security questionnaires

We are happy to complete vendor security questionnaires as part of an evaluation. Request one here and tell us which framework you need it mapped to.