Skip to content

Infrastructure & Operations

Cloud Security

The security controls we require of our cloud providers and the measures we take to use cloud services securely.

Last reviewed: July 2026

Risely relies on trusted third-party cloud service providers to run our platform. This page describes the security controls we require of those providers and the measures we take to use cloud services securely, so we can protect the data our customers entrust to us.

Our commitment

While Risely depends on several third-party cloud service providers to achieve our business objectives, protecting the confidentiality, integrity, and availability of the data our customers have entrusted to us remains our responsibility. We set security requirements for every critical cloud service provider we choose to work with, and we implement our own controls on top of the services they provide.

What we require of our cloud providers

Every critical cloud service provider is required to meet the following:

  • Logical data segregation. The provider must offer logical data segregation in a multi-tenant environment, or similar segregation capabilities that meet our network security requirements.
  • Log collection. The provider must be able to send logs from the cloud environment, covering events such as user activity, modifications, exceptions, security events, and faults within the private network.
  • Operational security. The provider must supply patch management, vulnerability assessments, and remediation methods for the infrastructure.
  • Data encryption. The provider must encrypt data in storage and in transit, in line with our encryption standards.
  • Access control. The provider must allow us to restrict access to its cloud services, its cloud service functions, and customer data, in line with our access control standards.
  • Authentication. The provider must offer capabilities for allocating secret authentication information, such as passwords.
  • Media disposal. The provider must be able to completely remove all Risely data in the event of an exit.
  • Incident management. The provider must have a documented plan and associated procedures for information security incidents.
  • Breach notification. The provider must fully disclose, in a timely manner, security breaches resulting in unauthorized intrusions that may affect Risely or its data.
  • Disaster recovery and business continuity. The provider must offer capabilities that let us meet our disaster recovery and business continuity requirements.
  • Physical and environmental security. The provider must take appropriate measures to meet physical and environmental security standards.

Provider compliance certifications

Each critical cloud service provider must hold one or more of the following attestations or certifications:

  • SOC 2 Type 2 report
  • ISO/IEC 27001 or ISO/IEC 27017
  • Cloud Security Alliance Security, Trust, and Assurance Registry (STAR) Level 2

Depending on the nature of the data or application deployed with a provider, we may additionally require certifications such as PCI-DSS, HIPAA, ISO 27701, and ISO 27018 as applicable.

How we use cloud services securely

As a customer of our cloud providers, we take the following measures to ensure the secure use of cloud services:

  • Use virtual private cloud or similar capabilities whenever a secured private or isolated network is required within the cloud environment.
  • Configure applications to generate audit logs.
  • Periodically review each provider’s information security posture and implement controls under our Vendor Management Policy, so the services we use continue to meet our requirements.
  • Periodically review each provider’s shared responsibility matrix for the relevant cloud services, to determine inherited controls and any additional controls we need to implement in our own environment.

Questions

If you have any questions about this policy, contact us at [email protected].

← Back to Trust Center

Questions about this policy? [email protected]