Compliance
Certifications, standards alignment, and audit reports.
Certifications
SOC 2 Type 2
Certified. Audit period: October 2024 – September 2025. Auditor: CyberGuard Compliance, LLP. Covers security and availability trust services criteria. Zero exceptions noted.
✓ CertifiedFinOps Certified Platform
The FinOps Foundation awards the FinOps Certified Platform designation to commercial software that accurately aligns with the FinOps Framework. Explore the full directory of foundation-vetted tools on the official FinOps Foundation Landscape.
✓ CertifiedAWS ISV Accelerate Partner
Recognized AWS partner with co-sell support and AWS Marketplace integration for streamlined procurement.
Verified PartnerAWS Cloud Operations Competency
AWS Cloud Operations Competency for Cost Management — validated by AWS for delivering proven cost optimization solutions.
Competency AchievedISO 27001
Standards Alignment
CloudFix aligns with the CIS AWS Foundations Benchmark where applicable to our infrastructure. This includes:
- IAM password policies and MFA enforcement
- Logging configuration (CloudTrail enabled)
- Encryption at rest and in transit
- Security group restrictions
- VPC flow logs
CloudFix follows the AWS Well-Architected Security Pillar principles:
- Implement a strong identity foundation: IAM roles with least privilege, no long-lived credentials
- Enable traceability: All fix operations are logged and auditable via CloudTrail
- Apply security at all layers: VPC isolation, security groups, encryption everywhere
- Automate security best practices: CloudFormation-based onboarding, SSM-based change management
- Protect data in transit and at rest: TLS 1.2+ and AES-256
CloudFix is available on AWS Marketplace and has passed AWS's security review process for listed products. This includes:
- Product security assessment by AWS
- Secure integration patterns validated
- Compliance with AWS Marketplace terms
- Standardized billing through AWS
Downloadable Documents
Access our compliance and security documentation. SOC 2 reports require a signed NDA.
SOC 2 Type 2 Report
Requires NDA. Independent auditor report on CloudFix's control design.
AWS Partner Verification
Verify CloudFix's AWS partner status and competencies.
Penetration Test Summary
Requires NDA. Summary of most recent third-party penetration test results.
Terms of Service
CloudFix and RightSpend terms of service, subscription terms, and usage policies.
API Documentation
REST API guide, endpoint reference, and integration examples for ITSM platforms and other integrations.
Architecture Diagrams
Solution architecture and ITSM integration data flow diagrams for enterprise security reviews.