Information Security Policy
The principles, responsibilities and controls Cloudtuner adopts to safeguard information assets, support business continuity and reduce cybersecurity risks.
Purpose
Cloudtuner is committed to protecting the confidentiality, integrity, and availability of information entrusted to us by our customers, employees, partners, and stakeholders.
This Information Security Policy establishes the principles, responsibilities, and controls adopted by Cloudtuner to safeguard information assets, support business continuity, and reduce cybersecurity risks.
Cloudtuner is operated by:
Roboi Private Limited
India
Robo Intelligence Information Technology LLC
United Arab Emirates
(collectively referred to as "Cloudtuner", "Company", "we", "our", or "us").
Scope
This Policy applies to:
- All Cloudtuner employees, contractors, consultants, interns, and temporary staff
- All information systems operated by Cloudtuner
- Cloud infrastructure
- AI platforms
- Customer dashboards
- APIs
- Managed cloud services
- Cloud security operations
- Customer support operations
- Third-party service providers handling Company information
Information Security Objectives
Cloudtuner aims to:
- Protect customer information from unauthorised access, disclosure, alteration, or destruction
- Maintain secure and resilient cloud services
- Protect intellectual property
- Support regulatory and contractual compliance
- Promote secure software development
- Improve operational resilience
- Continuously strengthen cybersecurity capabilities
Security Principles
Cloudtuner's information security programme is based on the following principles:
- Confidentiality
- Integrity
- Availability
- Least Privilege
- Need-to-Know Access
- Defence in Depth
- Zero Trust principles where practical
- Secure by Design
- Privacy by Design
- Continuous Improvement
Governance
Senior management is responsible for supporting the Company's information security programme.
Cloudtuner maintains security policies, operational procedures, and risk management processes designed to safeguard business operations and customer information.
Employees are expected to understand and comply with applicable security requirements.
Risk Management
Cloudtuner regularly evaluates information security risks by considering:
- Cyber threats
- Infrastructure vulnerabilities
- Operational risks
- Third-party risks
- Insider threats
- Cloud provider risks
- Software vulnerabilities
- Regulatory requirements
Appropriate controls are implemented based on the assessed level of risk.
Access Control
Access to systems and information is granted on the basis of business need.
Cloudtuner follows principles including:
- Role-Based Access Control (RBAC)
- Least Privilege
- Multi-Factor Authentication (MFA) for privileged accounts where supported
- Strong password requirements
- Secure credential management
- Periodic review of user access
- Prompt removal of unnecessary access
Administrative privileges are restricted to authorised personnel.
Data Classification
Information should be classified according to its sensitivity, including categories such as:
- Public
- Internal
- Confidential
- Restricted
Security controls should be proportionate to the sensitivity of the information.
Encryption
Where appropriate, Cloudtuner uses industry-recognised encryption technologies to protect information:
- Encryption in transit
- Encryption at rest
- Secure communication protocols
- Secure key management practices
Infrastructure Security
Cloudtuner implements security controls appropriate to its cloud and operational environments, including, where applicable:
- Network segmentation
- Firewalls
- Secure cloud configurations
- Endpoint protection
- Vulnerability scanning
- Patch management
- Infrastructure monitoring
- Configuration management
- Backup procedures
- Logging and monitoring
Secure Software Development
Cloudtuner follows secure software development practices that may include:
- Secure design principles
- Code reviews
- Dependency management
- Vulnerability remediation
- Security testing
- Secrets management
- Version control
- Change management
- Pre-release validation
Artificial Intelligence Security
Cloudtuner incorporates AI into certain services.
To support responsible AI deployment:
- AI systems are subject to security controls appropriate to their use.
- Access to AI services is restricted to authorised users and systems.
- AI-generated outputs are reviewed where operationally appropriate.
- AI is used to assist, not replace, human decision-making.
Logging and Monitoring
Cloudtuner may collect and retain security logs relating to:
- Authentication events
- Administrative activities
- API usage
- Infrastructure events
- System health
- Security alerts
- Audit records
Logs are used to support security monitoring, troubleshooting, compliance, and incident investigations.
Vulnerability Management
Cloudtuner maintains processes designed to identify and address security vulnerabilities through activities such as:
- Vulnerability scanning
- Security assessments
- Patch management
- Configuration reviews
- Risk-based remediation
Critical issues are prioritised according to risk and operational impact.
Incident Management
Cloudtuner maintains procedures for identifying, assessing, responding to, and recovering from information security incidents.
Where appropriate, incident response activities may include:
- Detection
- Investigation
- Containment
- Eradication
- Recovery
- Lessons learned
- Customer notification where contractually or legally required
Business Continuity
Cloudtuner maintains business continuity and disaster recovery planning intended to support the availability of critical services.
Recovery strategies are reviewed and updated periodically based on business requirements.
Third-Party Security
Cloudtuner may rely on third-party service providers.
Reasonable efforts are made to evaluate security considerations when selecting providers that process or host Company or customer information.
However, Cloudtuner cannot guarantee the security, availability, or operational practices of third-party providers.
Customer Responsibilities
Customers remain responsible for securing their own environments, including:
- Cloud account administration
- Identity and Access Management
- Backup and disaster recovery
- Security configurations
- Regulatory compliance
- User management
- Data governance
- Infrastructure changes
- Security approvals
Cloudtuner provides tools, monitoring, recommendations, and managed services only to the extent agreed under applicable contracts.
Security Awareness
Cloudtuner promotes security awareness among its workforce through appropriate training, internal guidance, and ongoing education on information security responsibilities.
Compliance
Cloudtuner aims to align its security programme with recognised industry practices and applicable legal and regulatory obligations, including those relating to information security, privacy, and cloud services.
Compliance with this Policy does not constitute a guarantee of compliance with any particular law, certification, or regulatory framework unless expressly stated in a separate written agreement.
Security Disclaimer
Cloudtuner follows recognised industry practices designed to protect its systems and customer information. However, no information security programme can eliminate all cybersecurity risks.
Accordingly:
- No security control can guarantee complete protection against every cyber threat.
- Sophisticated attacks, zero-day vulnerabilities, insider threats, cloud provider failures, and force majeure events may affect security despite reasonable safeguards.
- Customers should maintain independent security controls, monitoring, backups, and incident response capabilities.
- Cloudtuner provides commercially reasonable security measures but does not warrant that its services will be uninterrupted, error-free, or immune from cyberattacks.
Except where liability cannot legally be excluded, Cloudtuner shall not be responsible for losses arising from events beyond its reasonable control, including attacks directed at customer-managed infrastructure or third-party service providers.
Policy Violations
Violations of this Policy may result in:
- Removal of system access
- Internal disciplinary action
- Termination of contracts or services
- Legal action where appropriate
Policy Review
This Policy is reviewed periodically and may be updated to reflect changes in technology, business operations, legal obligations, or recognised security practices.
The latest version will be published on the Cloudtuner website.
Contact
Information Security Team
For information security enquiries, incident reporting, or security-related questions, please contact us.
India
Roboi Private Limited
United Arab Emirates
Robo Intelligence Information Technology LLC
Email support@roboi.ai
Website www.cloudtuner.ai
