ClonePartner Talk to us
Terms Privacy DPA GDPR CCPA Security Cookies Trust Center

Data Security and Integrity

Last updated: 28 July 2026
View as Markdown ·
On this page
  • 1. Security Framework
  • 2. Compliance & Certifications
  • 3. Deployment Models
  • 4. Data Residency & Region Selection
  • 5. Data-Lifecycle Controls
  • 6. Infrastructure & Access Security
  • 7. AI-Assisted Engineering
  • 8. Incident Response & Business Continuity
  • 9. Continuous Improvement
  • 10. Privacy & Data Processing
  • 11. Vulnerability Disclosure
  • 12. Contact

1. Security Framework

ClonePartner grounds every engagement on the CIA triad—Confidentiality, Integrity, Availability—and runs a formal risk assessment before any migration begins, mapping vulnerabilities, verifying access scopes, and selecting controls that neutralise identified risks.

2. Compliance & Certifications

  • Infrastructure and processes are independently audited for SOC 2 Type II and ISO 27001, with controls continuously monitored through our compliance-automation platform.
  • We additionally maintain CASA Type II verification, and migrations observe GDPR, CCPA, and HIPAA safeguards for regulated data.
  • Current assurance reports, certificates, and our information-security policies are available under NDA via our Trust Center or on request to security@clonepartner.com
  • We maintain cyber-liability insurance commensurate with the scale and sensitivity of our engagements.

3. Deployment Models

You choose how a migration is delivered, and the security responsibilities differ accordingly:

  • Cloud delivery — we operate the migration end to end on our hardened infrastructure. Data pulled from the source system is held in an encrypted staging database in your selected region (see Section 4) and then pushed to the destination. We are responsible for the security of the staging environment, the migration pipeline, and all access controls around them.
  • Self-hosted (on-premises) delivery — our migration stack is deployed inside your own infrastructure and operated by your team. Customer data records never leave your environment: we do not access, receive, or store them, and the software transmits only licensing, usage, and diagnostic telemetry back to us. Under this model you are responsible for securing the host environment (network, access control, backups), while we remain responsible for the security of the software we ship and for supporting you throughout the engagement.

4. Data Residency & Region Selection

For cloud-delivered migrations, you choose the region where the temporary staging database lives. We provision it on our audited infrastructure providers—DigitalOcean and OVHcloud—in your selected region, and your data stays there for the duration of the project: we do not relocate staging data out of the selected region except on your documented instructions or where required by law.

Available staging regions include:

ProviderRegions
DigitalOceanUnited States (New York, San Francisco), Canada (Toronto), United Kingdom (London), Netherlands (Amsterdam), Germany (Frankfurt), India (Bangalore), Singapore, Australia (Sydney)
OVHcloudFrance (Gravelines, Roubaix, Strasbourg), Germany (Frankfurt), United Kingdom (London), Poland (Warsaw), Canada (Beauharnois), United States (Virginia, Oregon), India (Mumbai), Singapore, Australia (Sydney)

If you do not specify a region, we select one reasonably proximate to your source or destination systems and confirm it with you before the migration begins.

5. Data-Lifecycle Controls

Pre-migration

  • Classify data sensitivity and confirm least-privilege API scopes.
  • Enforce multi-factor authentication (MFA) and role-based access (RBAC) for the engineer assigned to the project.

In transit

  • All data flows through TLS 1.2+ channels; private subnets block unauthorised ingress.

Temporary at-rest storage

  • Staging data resides in an isolated MongoDB instance encrypted with AES-256, provisioned in your selected region.
  • Only the designated engineer can reach that instance, enforced by RBAC and hardware-token MFA.

Post-migration

  • Checksums confirm destination integrity.
  • Staging databases auto-purge 30 days after project close—or sooner at your request.

6. Infrastructure & Access Security

  • Network defence: layered firewalls, intrusion-detection sensors, and streaming logs to a tamper-proof SIEM.
  • Key management: encryption keys are centrally managed and rotated quarterly.
  • Vendor security: sub-processors undergo due-diligence and contract review before onboarding and periodically thereafter.
  • Zero-trust & Least Privilege: every internal service must re-authenticate; permissions are scoped to the minimum required.
  • RBAC + MFA for every console, database, and CI/CD pipeline.
  • Continuous monitoring & audits under the SOC 2 and ISO 27001 programmes, complemented by regular third-party penetration tests.

7. AI-Assisted Engineering

Our engineers use AI-assisted development tooling (currently Cursor, by Anysphere) when building and validating migration scripts. These tools run with privacy mode enforced: inputs are never used to train models and are covered by zero- or limited-retention commitments from the providers, which may include foundation-model providers such as OpenAI, Anthropic, and Google. They are disclosed as sub-processors in our Data Processing Agreement and Trust Center, and you can prohibit the use of AI tooling on your engagement entirely by written notice.

8. Incident Response & Business Continuity

  • Immediate containment, forensic snapshot, and root-cause analysis upon alert.
  • Customer notification without undue delay—and, where feasible, within 48 hours of becoming aware of a breach, consistent with our DPA—followed by a full impact report and remediation timeline.
  • Resilience measures: encrypted backups and automated fail-over to redundant infrastructure keep Recovery Point Objective ≤ 4 h and Recovery Time Objective ≤ 1 h.

9. Continuous Improvement

  • Annual third-party penetration testing and quarterly security audits validate defences.
  • All engineering and support staff complete yearly secure-coding and privacy training aligned with ISO 27001.
  • Personnel with access to customer data undergo background screening at hire, where permitted by local law.
  • A security risk assessment is rerun for every new integration connector before it reaches production.

10. Privacy & Data Processing

ClonePartner acts as a Data Processor under GDPR for cloud-delivered engagements; for self-hosted deployments, customer data is processed entirely within your environment and never reaches us. Our Data Processing Agreement incorporates the EU and UK Standard Contractual Clauses, and customer data is shared only with the vetted sub-processors listed in our Trust Center.

11. Vulnerability Disclosure

We welcome good-faith security research. If you believe you have found a vulnerability in any ClonePartner service, email security@clonepartner.com with enough detail for us to reproduce the issue. We will acknowledge your report promptly, keep you informed while we investigate, and credit researchers who wish to be named. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us reasonable time to remediate before public disclosure. A machine-readable policy is available at /.well-known/security.txt.

12. Contact

For SOC 2 or ISO 27001 reports, detailed questionnaires, or security disclosures, email security@clonepartner.com

On this page

  • 1. Security Framework
  • 2. Compliance & Certifications
  • 3. Deployment Models
  • 4. Data Residency & Region Selection
  • 5. Data-Lifecycle Controls
  • 6. Infrastructure & Access Security
  • 7. AI-Assisted Engineering
  • 8. Incident Response & Business Continuity
  • 9. Continuous Improvement
  • 10. Privacy & Data Processing
  • 11. Vulnerability Disclosure
  • 12. Contact
ClonePartner

Best-in-class custom data migration and custom integration services for your best customers.

SOC 2, GDPR, ISO 27001, HIPAA Certified

9450, SW Gemini Drive, Beaverton, Oregon, US - 97008 Contact: support@clonepartner.com | (415)-592-5896

Case Studies

Decantalo Highsnobiety Shade Station Paazl 24 Hour Home Care Emergicon Watts & Co Flowtex Energy Integrative Nutrition RPM Shop Sales ATÖLYE Inuka Takomo Golf Loving Tan Parker Baby

Services

Help Desk Data Migration CRM Migration HRIS Migration Ecommerce Migration ATS Migration Accounting Migration Knowledge Base Migration ITSM Migration ERP Migration Financial Services CRM Migration

Resources

Pricing Customers Partners Refer a Deal Blog Philosophy Contact

Legal

Terms of Service Privacy Policy Data Processing Agreement GDPR CCPA Security Cookie Policy Manage Cookies Trust Center

Listed On

Zendesk Front Missive HubSpot Close Copper tawk.to Drupal Customer.io