Cloudscape security and deployment overview: data flow, permissions, encryption, and compliance
Cloudscape includes security and deployment features that help you manage how data is collected, stored, and protected. This article gives you an overview of data flow, access controls, encryption methods, and compliance practices so you can better understand how the platform supports a secure deployment.
Deployment model and data flow
CloudScape supports both on-premises (FlexDeploy) and SaaS deployment models. With FlexDeploy, inventory and performance metrics remain on-site. Subscription, licensing, and authentication are managed centrally.
Scope of data collected
CloudScape collects inventory, performance, and connectivity data.
Sensitive process arguments can be removed using the Scrub Process Arguments setting in RN150.
See: What CloudScape collects
Data protection and encryption
- RN150 uses AES-256 to store credentials and 4096-bit GPG encryption for data exports
- HTTPS secures communication with FlexDeploy and AWS services
- SaaS environments use encryption at rest and in transit (EBS, RDS, S3)
- SSL validation is enforced unless disabled by a proxy
External connectivity
Review required endpoints and connectivity requirements:
Deployment requirements
Data residency and compliance
CloudScape stores data in the Flexera cloud on AWS. Data is encrypted and protected using established compliance controls.
User access and RBAC
CloudScape supports three roles:
- Subscription administrator
- Read/write
- Read-only
External identity provider (IdP) integration is not supported.
MFA and authentication
- MFA is enforced for appliances and the CloudScape portal
- Supported methods include SMS and email
- Single sign-on (SSO) and external IdP integration are not supported
Privileged credentials
For RN150, you need the following privileged credentials:
-
vCenter: Read-only access
-
Standalone ESXi hosts: Root access
-
CyberArk: Supports credential vaulting
Secrets management
Credentials are stored locally using AES-256 encryption or in a CyberArk vault.
See: CyberArk integration
Network placement
You determine network placement and segmentation during deployment.
Logging and monitoring
Logs are retained for 60 days. You can forward logs to an external syslog system if needed.
Data integrity
CloudScape uses strict typing and validation to help maintain data accuracy.
System updates and patch management
Appliances automatically install curated OS security updates every 24 hours.
Vendor support and remote access
Support access is available only when you enable Advanced Debugging during a support session.
DNS and certificates
Replace default self-signed certificates with certificates issued by your internal PKI.
See: Certificate management
Threat modeling and risk assessment
CloudScape undergoes internal threat modeling. The RN150 appliance is hardened based on the CIS Debian Benchmark. SSL validation is enforced unless disabled by a proxy.