We assess your cloud without ever holding access to it.

Before you let an assessment tool near a regulated environment, you need to know what it can reach, who can see the results, and what happens to the data afterwards. This page answers those three questions — it is written for the security questionnaire, not the sales deck.

Enterprise security requirements — built into every layer.

CloudTwyst's security model rests on four principles: engagement-scoped access, transparent audit, a data lifecycle that ends in deletion, and a connector that never gives us a way in.

Role-Based Access Control
Five defined roles, each scoped to an engagement rather than the whole tenant. Customer roles never reach beyond their own assessment, and separation of duty is enforced between the team that assesses and the customer who signs off.
  • Platform Admin — all engagements, user and platform administration
  • Assessor — assigned engagements only; cannot sign off or purge
  • Customer Admin — own engagement; export and sign-off rights
  • Customer Viewer — own engagement, read only
  • Auditor — audit stubs and exported reports only, never live assessment data
Immutable Audit Trails
Every action, approval, exception, and configuration change is logged with timestamp, actor identity, and full context. Tamper-evident records designed for regulatory evidence and forensic investigation.
  • Immutable log storage with cryptographic integrity verification
  • Full actor attribution for every platform action
  • Change management logging with before/after state capture
  • Exportable audit packages for compliance audits
  • Configurable retention with archival policy support
Data Lifecycle & Purge
Every engagement runs a defined lifecycle that ends in deletion. Once the customer signs off, your assessment data is purged — what remains is a tamper-evident audit stub proving the engagement happened, not the findings themselves.
  • Lifecycle: draft → collecting → assessed → remediating → report delivered → signed off → purged
  • Two-step OTP sign-off before any engagement can be closed
  • Sign-off starts a 30-day retention countdown, then automatic purge
  • Three pre-configured retention paths per engagement
  • Zero customer insight data retained after purge — audit stub only
Read-Only Connector — No Inbound Access
CloudTwyst never connects to your cloud. The connector runs inside your own environment, calls provider APIs locally, and submits results outbound to a single ingest endpoint. There is no inbound connection, no agent, no write access and no persistent access to revoke.
  • Azure — PowerShell connector with Managed Identity ARM template
  • AWS — read-only IAM role scoped to Security Hub and Config
  • GCP — Service Account with Security Command Center read scope
  • 4-hour short-lived engagement token, scoped to one assessment
  • TLS validation and connector version enforcement on every submission

Four frameworks, scored control by control.

CloudTwyst Security Assess evaluates your cloud environment against four frameworks, producing a per-control gap analysis, a posture score, and a prioritised remediation backlog for each.

Framework Control scope Output Status
NIS2 — EU Network & Information SecurityArticle 21 controls mapped and scoredPosture score, gap count, remediation backlogScored
ISO 27001 — Information Security ManagementISO 27001:2022 Annex A control evaluationPosture score, gap count, remediation backlogScored
DORA — Digital Operational Resilience ActICT risk management and resilience controlsPosture score, gap count, remediation backlogScored
GDPR — General Data Protection RegulationTechnical safeguard assessmentPosture score, gap count, remediation backlogScored

Review our full security documentation.

Book a security-focused technical session with the CloudTwyst team — we'll walk through our security model in detail and answer your organisation's specific questions.

Request Security Documentation Security consulting →