SAFETY MEASURES
Your Data, Your Cloud: Fortified Security, Limitless Trust
Security at whitesky.cloud: a strategic, multilayered priority.
What
At whitesky.cloud, our mission is to create a safe, simple, and affordable edge cloud service, with security embedded across every layer of our infrastructure. We take a strategic, multilayered approach to security, ensuring robust protection for your applications and data.
-
Continuous, automated scanning
Our platform code, developed by our in-house team, is continuously scanned with Aikido, which checks it against a comprehensive security vulnerability database and provides immediate feedback for rapid remediation.
-
Vulnerability assessments
With OpenVAS we use to perform continuous vulnerability assessments on our server nodes and cloudspaces, reinforcing our infrastructure’s defenses.
-
Centre for Cyber Security
As a registered entity with Belgium's Centre for Cyber Security (CCB), our domains receive regular scans to meet national cybersecurity standards.
Why?
By integrating these tools, practices, and assessments, we offer a secure, reliable, and transparent cloud environment, delivering on our promise of a safe, simple, and affordable edge cloud service for all clients.
Our security strategy and transparancy
At whitesky.cloud, transparency is a cornerstone of our security strategy. We openly communicate about vulnerabilities and the steps we take to resolve them, ensuring our clients remain informed and confident in the safety of their data.
Safe code
Results of previous Pentest and Actions Taken
In our previous pentests, we identified and addressed several key areas to strengthen our platform’s security:
-
HTML Template Injection and XSS
Potential vulnerabilities were found where user input could be manipulated. Immediate actions were taken to reinforce protections, ensuring no harmful code could be executed on our platform.
-
Directory Listing
A configuration issue was identified that could expose internal files. We promptly adjusted settings to prevent any unauthorized access.
-
Outdated Services
Some parts of our server infrastructure were flagged as outdated. These have now been updated to the latest, most secure versions available.
-
Password Policy
We upgraded our password policy to require multi-factor authentication (MFA) for all applications, ensuring an added layer of protection for user accounts.
-
Information Disclosure
We implemented additional safeguards to ensure no unnecessary information is exposed, further protecting both our customers and our infrastructure.
Security posts
- Date: 06/08/2024
Unlocking the world of pentesting
- 4 min read
- Date: 31/08/2023
The sovereign cloud, the only way to comply with legislation
- 4 min read
- Date: 01/08/2023
Good read: Strengthening security in a multi-SaaS cloud environment
- 0 min read