Confidential by design. Compliant by default.
CloudPocket is architected for chip-design data — the most sensitive, most regulated and most valuable IP in the holding.
Six layers of protection
Identity
SAML 2.0, SCIM, OIDC and adaptive MFA. Device posture evaluated per session, not per login.
Encryption
Envelope encryption with AES-256-GCM. BYOK and HYOK supported on Business and Sovereign plans.
Network
Private interconnects, IP allow-listing, VPC endpoints and optional on-premises gateway appliances.
Threat detection
Behavioural analytics, ransomware entropy detection and anomaly scoring with automated isolation.
Compliance
Continuous evidence collection for SOC 2, ISO 27001, TISAX, GDPR, CCPA and export control.
Resilience
Multi-AZ storage, cross-region replication, 15-minute RPO options and tested DR runbooks.
Audit-ready, today
Where your bytes live
You choose a primary region at tenant creation. Replicas are kept within the same jurisdiction unless you opt into cross-region DR.
EU
Frankfurt, Amsterdam, Dublin. In-country key custody available.
North America
Austin, Portland, Toronto. ITAR-registered facilities.
Asia Pacific
Hsinchu, Bangalore, Singapore, Tokyo. Local law compliance.
Rest of world
Additional sovereign regions available on request.
Common questions from CISOs
In standard mode, keys are managed in an HSM you control or in a CloudPocket-managed HSM. In HYOK mode, the plaintext key never leaves your infrastructure.
No. Support access requires customer-initiated, time-boxed, audited consent. Every access event is written to your audit log.
All access is least-privilege and role-based. Anomalous download volumes, off-hours access and unusual geographies trigger alerts and optional auto-lock.
Coordinated disclosure with a 90-day standard window. A bug bounty programme is available to Silicium employees and vetted partners.
Under NDA from the CloudPocket Trust Centre. Silicium employees can request access via the internal service portal.