Data Security and Integrity
On this page
- 1. Security Framework
- 2. Compliance & Certifications
- 3. Deployment Models
- 4. Data Residency & Region Selection
- 5. Data-Lifecycle Controls
- 6. Infrastructure & Access Security
- 7. AI-Assisted Engineering
- 8. Incident Response & Business Continuity
- 9. Continuous Improvement
- 10. Privacy & Data Processing
- 11. Vulnerability Disclosure
- 12. Contact
1. Security Framework
ClonePartner grounds every engagement on the CIA triad—Confidentiality, Integrity, Availability—and runs a formal risk assessment before any migration begins, mapping vulnerabilities, verifying access scopes, and selecting controls that neutralise identified risks.
2. Compliance & Certifications
- Infrastructure and processes are independently audited for SOC 2 Type II and ISO 27001, with controls continuously monitored through our compliance-automation platform.
- We additionally maintain CASA Type II verification, and migrations observe GDPR, CCPA, and HIPAA safeguards for regulated data.
- Current assurance reports, certificates, and our information-security policies are available under NDA via our Trust Center or on request to security@clonepartner.com
- We maintain cyber-liability insurance commensurate with the scale and sensitivity of our engagements.
3. Deployment Models
You choose how a migration is delivered, and the security responsibilities differ accordingly:
- Cloud delivery — we operate the migration end to end on our hardened infrastructure. Data pulled from the source system is held in an encrypted staging database in your selected region (see Section 4) and then pushed to the destination. We are responsible for the security of the staging environment, the migration pipeline, and all access controls around them.
- Self-hosted (on-premises) delivery — our migration stack is deployed inside your own infrastructure and operated by your team. Customer data records never leave your environment: we do not access, receive, or store them, and the software transmits only licensing, usage, and diagnostic telemetry back to us. Under this model you are responsible for securing the host environment (network, access control, backups), while we remain responsible for the security of the software we ship and for supporting you throughout the engagement.
4. Data Residency & Region Selection
For cloud-delivered migrations, you choose the region where the temporary staging database lives. We provision it on our audited infrastructure providers—DigitalOcean and OVHcloud—in your selected region, and your data stays there for the duration of the project: we do not relocate staging data out of the selected region except on your documented instructions or where required by law.
Available staging regions include:
| Provider | Regions |
|---|---|
| DigitalOcean | United States (New York, San Francisco), Canada (Toronto), United Kingdom (London), Netherlands (Amsterdam), Germany (Frankfurt), India (Bangalore), Singapore, Australia (Sydney) |
| OVHcloud | France (Gravelines, Roubaix, Strasbourg), Germany (Frankfurt), United Kingdom (London), Poland (Warsaw), Canada (Beauharnois), United States (Virginia, Oregon), India (Mumbai), Singapore, Australia (Sydney) |
If you do not specify a region, we select one reasonably proximate to your source or destination systems and confirm it with you before the migration begins.
5. Data-Lifecycle Controls
Pre-migration
- Classify data sensitivity and confirm least-privilege API scopes.
- Enforce multi-factor authentication (MFA) and role-based access (RBAC) for the engineer assigned to the project.
In transit
- All data flows through TLS 1.2+ channels; private subnets block unauthorised ingress.
Temporary at-rest storage
- Staging data resides in an isolated MongoDB instance encrypted with AES-256, provisioned in your selected region.
- Only the designated engineer can reach that instance, enforced by RBAC and hardware-token MFA.
Post-migration
- Checksums confirm destination integrity.
- Staging databases auto-purge 30 days after project close—or sooner at your request.
6. Infrastructure & Access Security
- Network defence: layered firewalls, intrusion-detection sensors, and streaming logs to a tamper-proof SIEM.
- Key management: encryption keys are centrally managed and rotated quarterly.
- Vendor security: sub-processors undergo due-diligence and contract review before onboarding and periodically thereafter.
- Zero-trust & Least Privilege: every internal service must re-authenticate; permissions are scoped to the minimum required.
- RBAC + MFA for every console, database, and CI/CD pipeline.
- Continuous monitoring & audits under the SOC 2 and ISO 27001 programmes, complemented by regular third-party penetration tests.
7. AI-Assisted Engineering
Our engineers use AI-assisted development tooling (currently Cursor, by Anysphere) when building and validating migration scripts. These tools run with privacy mode enforced: inputs are never used to train models and are covered by zero- or limited-retention commitments from the providers, which may include foundation-model providers such as OpenAI, Anthropic, and Google. They are disclosed as sub-processors in our Data Processing Agreement and Trust Center, and you can prohibit the use of AI tooling on your engagement entirely by written notice.
8. Incident Response & Business Continuity
- Immediate containment, forensic snapshot, and root-cause analysis upon alert.
- Customer notification without undue delay—and, where feasible, within 48 hours of becoming aware of a breach, consistent with our DPA—followed by a full impact report and remediation timeline.
- Resilience measures: encrypted backups and automated fail-over to redundant infrastructure keep Recovery Point Objective ≤ 4 h and Recovery Time Objective ≤ 1 h.
9. Continuous Improvement
- Annual third-party penetration testing and quarterly security audits validate defences.
- All engineering and support staff complete yearly secure-coding and privacy training aligned with ISO 27001.
- Personnel with access to customer data undergo background screening at hire, where permitted by local law.
- A security risk assessment is rerun for every new integration connector before it reaches production.
10. Privacy & Data Processing
ClonePartner acts as a Data Processor under GDPR for cloud-delivered engagements; for self-hosted deployments, customer data is processed entirely within your environment and never reaches us. Our Data Processing Agreement incorporates the EU and UK Standard Contractual Clauses, and customer data is shared only with the vetted sub-processors listed in our Trust Center.
11. Vulnerability Disclosure
We welcome good-faith security research. If you believe you have found a vulnerability in any ClonePartner service, email security@clonepartner.com with enough detail for us to reproduce the issue. We will acknowledge your report promptly, keep you informed while we investigate, and credit researchers who wish to be named. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us reasonable time to remediate before public disclosure. A machine-readable policy is available at /.well-known/security.txt.
12. Contact
For SOC 2 or ISO 27001 reports, detailed questionnaires, or security disclosures, email security@clonepartner.com