Security Overview
CloudSaver is designed around least privilege, customer control and auditability.
Controls
- Microsoft Entra ID authentication and role-based access.
- Read access before write access; explicit approval for destructive actions.
- TLS in transit, Azure platform encryption at rest and managed key protection.
- Tenant isolation, audit trails, request validation and rate limiting.
- Customer-held connector secrets through Azure Key Vault references.
Shared responsibility
Security is shared. Customers control their tenant configuration, identities, permissions, connected sources, backups and approval decisions. No service can guarantee prevention of every security incident; CloudSaver applies controls designed to reduce risk and responds in accordance with its contractual and legal obligations.
Contact
For security questions or responsible disclosure, email security@consumeit.se.