Skip to content
Security

Built so that connecting is never the risk

Read-only access, secrets in Azure Key Vault, no agents, and strict isolation between customers.

Read-only access

KloudRecon needs only the built-in Reader role. Reader cannot create, change or delete resources, and cannot read secrets, keys, app settings or data inside your services. If we detect write permissions on the app you connect, we tell you and explain why you should remove them.

Secrets stay in Key Vault

The client secret you provide is stored only in Azure Key Vault and accessed with a managed identity. Our database keeps the secret name, never the value. After saving, the secret is write-only: it is never shown again and never written to logs.

Metadata, not your data

We collect resource metadata and configuration, metrics, and cost data. We never read data-plane content such as files, blobs, database rows, messages or secrets.

Tenant isolation

Every query is scoped to your organization, and PostgreSQL row-level security enforces the same boundary a second time in the database. Automated tests check isolation on every change.

Encryption and transport

All traffic uses HTTPS with HSTS. Data is stored on encrypted Azure managed disks and in Azure Storage with encryption at rest. The database accepts only local connections from the application host.

Sign-in with Microsoft Entra

Accounts use Microsoft Entra External ID with email verification and multi-factor authentication. Every new organization is reviewed by our team before it can connect Azure.

Audit trail

Sensitive actions — connections, secrets, roles, invitations, approvals and exports — are written to an audit log that your administrators can review.

Deletion on request

Deleting a connection deletes its secret and its data. Deleting your organization purges all of its data within 30 days.

Secure engineering

Dependencies are scanned continuously, code is reviewed and analyzed before release, and every deployment is health-checked with automatic rollback.

Compliance

Compliance mapping

KloudRecon maps its checks to control IDs from frameworks such as CIS Microsoft Azure Foundations, Microsoft Cloud Security Benchmark, ISO/IEC 27001, NIST SP 800-53, PCI DSS, SOC 2 and HIPAA to help you prepare for audits. Mapping is not certification: KloudRecon does not certify your environment.

  • CIS Azure Foundations
  • MCSB
  • ISO/IEC 27001
  • NIST SP 800-53
  • PCI DSS
  • SOC 2
  • HIPAA