Security & compliance

Confidential by design. Compliant by default.

CloudPocket is architected for chip-design data — the most sensitive, most regulated and most valuable IP in the holding.

256-bitAES encryption at rest
90 daysEnvelope key rotation
7 yearsImmutable audit retention
Trust architecture

Six layers of protection

Identity

SAML 2.0, SCIM, OIDC and adaptive MFA. Device posture evaluated per session, not per login.

Encryption

Envelope encryption with AES-256-GCM. BYOK and HYOK supported on Business and Sovereign plans.

Network

Private interconnects, IP allow-listing, VPC endpoints and optional on-premises gateway appliances.

Threat detection

Behavioural analytics, ransomware entropy detection and anomaly scoring with automated isolation.

Compliance

Continuous evidence collection for SOC 2, ISO 27001, TISAX, GDPR, CCPA and export control.

Resilience

Multi-AZ storage, cross-region replication, 15-minute RPO options and tested DR runbooks.

Certifications

Audit-ready, today

SOC 2 Type II
ISO 27001
ISO 27017
ISO 27018
TISAX AL3
GDPR
CCPA
ITAR
EAR
EU dual-use
Data residency

Where your bytes live

You choose a primary region at tenant creation. Replicas are kept within the same jurisdiction unless you opt into cross-region DR.

EU

Frankfurt, Amsterdam, Dublin. In-country key custody available.

North America

Austin, Portland, Toronto. ITAR-registered facilities.

Asia Pacific

Hsinchu, Bangalore, Singapore, Tokyo. Local law compliance.

Rest of world

Additional sovereign regions available on request.

Security FAQ

Common questions from CISOs

In standard mode, keys are managed in an HSM you control or in a CloudPocket-managed HSM. In HYOK mode, the plaintext key never leaves your infrastructure.

No. Support access requires customer-initiated, time-boxed, audited consent. Every access event is written to your audit log.

All access is least-privilege and role-based. Anomalous download volumes, off-hours access and unusual geographies trigger alerts and optional auto-lock.

Coordinated disclosure with a 90-day standard window. A bug bounty programme is available to Silicium employees and vetted partners.

Under NDA from the CloudPocket Trust Centre. Silicium employees can request access via the internal service portal.