Cloventa only needs access to the information required to assess your compliance posture.
Depending on your setup, this may include
configuration data, security settings, access controls, infrastructure metadata, logs, and information from connected development or cloud services.
Cloventa uses this data to:
- assess your environment against applicable compliance requirements;
- identify potential compliance gaps and misconfigurations;
- monitor changes that could affect your compliance status;
- provide evidence and context for compliance controls.
Cloventa does
not need access to your application's business data or customer content simply to assess your infrastructure.
The principle is
least-privilege access: Cloventa should access only the data and permissions necessary to perform compliance checks.
Your data is used to provide and improve the compliance monitoring service and is handled according to Cloventa's security and data protection policies.