Self-Hosted

Runs in your Azure subscription. Nothing leaves your tenant.

Read-Only Discovery

Scanning reads metadata only: names, expiry dates, properties. Never secret values.

Not Another Vault

We enhance your Key Vaults. We don't replace them.

Key principle: CertifyClouds stores your operational data in YOUR Azure environment. Our services receive license validation and bounded aggregate fleet-health counters, never secret values or credential metadata. Optional integrations connect only to destinations your administrator approves.

Deployment Architecture

CertifyClouds deploys as a Docker container in your Azure subscription, with all data stored in your own PostgreSQL database.

YOUR AZURE SUBSCRIPTIONContainer App / ACICertifyCloudsApplicationManaged IdentityAzure PostgreSQL(Your Database)• Scan results• Rotation history• Alert rules• Audit logsYour Key VaultsRead metadata (Assets Discovery)Rotate secrets (Automation Rotation - Pro)AWS Secrets Manager(Automation Sync - Pro)Multi-cloud DR syncGCP Secret Manager(Automation Sync - Pro)Multi-cloud DR synclicense.certifyclouds.com(License validation)Sends: License keyReturns: Tier infoReturns: Latest versionLicense validation + update checks

Data Handling

We See

  • Your license key (for validation)
  • Your license tier and features
  • Version check requests

Never Sent To CertifyClouds

  • Your secret values*
  • Your scan results
  • Your Azure credentials
  • Your database contents
  • Your AWS/GCP credentials (Automation Sync)

*During rotation, new credentials are generated via Azure APIs and propagated to dependent resources, all within your environment over TLS using Managed Identity. Values are held in memory only and never persisted or transmitted externally.

Optional hosted AI access: The ENTERPRISE MCP Connector is disabled by default. When your administrator enables it, approved read-only result metadata is sent over TLS to the hosted AI provider you select. CertifyClouds services do not receive those results, and MCP never returns bearer tokens, secret values, private keys, or certificate material. Review the MCP security boundary →

Authentication

CertifyClouds uses Azure Managed Identity - no credentials are stored in the container or configuration files.

How It Works

Application Security

CertifyClouds includes built-in defences against brute-force and session hijacking attacks. All values are configurable via environment variables:

Permission Matrix

CertifyClouds requests only the minimum permissions needed for each feature.

PermissionScopePurposeRequired For
ReaderSubscriptionList Key Vaults and resourcesAll features
Key Vault ReaderPer Key VaultRead vault metadata and propertiesAssets Discovery
Key Vault Secrets UserPer Key VaultRead a certificate's backing secret (PFX) during rotationAutomation Rotation (Pro)
Key Vault Secrets OfficerPer Key VaultCreate and update secretsAutomation Rotation (Pro)
Key Vault Certificates OfficerPer Key VaultCreate and update certificatesAutomation Rotation (Pro)
Application.Read.AllGraph API (Tenant)Read App Registration credential metadata (read-only)Assets Discovery (Starter)
Application.ReadWrite.AllGraph API (Tenant)Rotate App Registration secretsAutomation Rotation (Pro)

Important: Assets Discovery uses read-only permissions - the application reads secret metadata (names, expiry dates) but never the actual secret values. Automation Rotation in Pro and Enterprise generates new credentials via Azure APIs and propagates them to dependent resources. Secret values are handled in memory within your environment and never persisted or transmitted externally.

This lists the core least-privilege roles. For the complete, authoritative permission reference (including key rotation, full-stack rotation, SSO, and B2C tenant scanning), see the Azure permissions guide in our documentation.

Encryption

Data at Rest

Data in Transit

Network Security

Outbound Connections

CertifyClouds makes these outbound calls:

DestinationPurposeFrequency
license.certifyclouds.comLicense validationOn startup + hourly heartbeat
management.azure.comAzure Resource Manager APIDuring scans/operations
*.vault.azure.netKey Vault data planeDuring scans/rotations
graph.microsoft.comApp Registration rotationAutomation Rotation only
secretsmanager.*.amazonaws.comAWS Secrets ManagerAutomation Sync only
secretmanager.googleapis.comGCP Secret ManagerAutomation Sync only

Compliance Support

CertifyClouds helps organizations gather evidence for credential-lifecycle controls across multiple frameworks:

Important: CertifyClouds is an evidence aggregator for Azure credential-lifecycle controls. We are not a certified compliance product. We do not hold SOC 2, ISO 27001, HIPAA, or PCI-DSS certification, and we are not a Business Associate under HIPAA (we do not require, accept, or process PHI). The framework mappings we provide identify what violates each control and recommend customer-side remediation. Your overall compliance depends on your Azure tenant configuration, your processes, and audits performed by your own auditors. Full compliance disclaimer →

License Server

The license server validates your license key and returns your entitlements.

What Happens

Offline Operation

Security Questions?

If you have security questions or need additional documentation for your security review, contact us at [email protected].