CloudTwyst is built from the ground up for enterprise security requirements — from granular access control to data sovereignty, audit evidence, and secure integrations. Security is not added on top. It is structural.
CloudTwyst's security model is designed around four principles: controlled access, transparent audit, policy-driven governance, and secure data handling.
CloudTwyst maps platform controls to major compliance frameworks — reducing the effort required to demonstrate compliance and collect audit evidence.
| Framework | Support model | Evidence collection | Status |
|---|---|---|---|
| ISO 27001 — Information Security Management | Pre-mapped control library with continuous monitoring | Automated — real-time | Native |
| NIS2 — EU Network & Information Security | Risk management and incident controls mapped to platform | Automated — real-time | Native |
| DORA — Digital Operational Resilience Act | ICT risk and resilience controls with policy enforcement | Automated — on-demand | Native |
| GDPR — General Data Protection Regulation | Access control, audit trail, and data handling controls | Automated — audit export | Supported |
| SOC 2 Type II | Security, availability, and confidentiality trust criteria | Automated — continuous | Supported |
| CSRD — Carbon & Sustainability Reporting | Carbon footprint reporting from cloud workload data | Automated — scheduled | Native |