Security Policies &
Compliance Documentation

Version   1.0
Effective   June 2026
Owner   Todd Densmore, CloudFive
Contact   todd@cloudfive.net
Review cycle   Annual
CONFIDENTIAL — Shared under mutual NDA. These documents are proprietary to CloudFive and may not be reproduced, distributed, or disclosed outside your organization without prior written consent.

Contents

1
Information Security Policy
Core security controls, access management, and data classification
2
Data Handling & Privacy Policy
How CloudFive collects, processes, stores, and deletes client data
3
Incident Response Policy
Detection, containment, notification, and post-mortem procedures
4
Vulnerability Management Policy
Continuous scanning, patch cadence, and remediation SLAs
5
Business Continuity & Disaster Recovery
RPO/RTO targets, backup strategy, and continuity procedures
6
Subprocessor List
Third-party tools and cloud services used in client engagements
Policy 1 of 6

Information Security Policy

Effective: June 2026  ·  Owner: Todd Densmore  ·  Review: Annual

1. Purpose

This policy establishes the security controls and practices CloudFive uses to protect the confidentiality, integrity, and availability of client data and systems. It applies to all services delivered by CloudFive and all systems, devices, and accounts used in the delivery of those services.

2. Scope

This policy applies to all CloudFive systems, cloud environments, client data, and third-party integrations used during an engagement. It covers all delivery personnel operating under the CloudFive umbrella.

3. Information Classification

4. Access Control

5. Endpoint Security

6. Network Security

7. Data Handling

8. Third-Party & Subprocessors

Third-party services used in client engagements are documented in the Subprocessor List (Policy 6). CloudFive does not share client data with third parties except as required to deliver the agreed scope of work. All third-party tools are reviewed for SOC 2 compliance or equivalent prior to use with client data.

9. Policy Review

This policy is reviewed annually and updated within 30 days of any material change in infrastructure, tooling, or regulatory requirements.

10. Contact

Security inquiries: todd@cloudfive.net

Policy 2 of 6

Data Handling & Privacy Policy

Effective: June 2026  ·  Owner: Todd Densmore  ·  Review: Annual

1. Purpose

This document describes how CloudFive collects, uses, stores, protects, and deletes data belonging to clients, their customers, and other third parties. CloudFive's default position is data minimization: we access and retain only what is necessary to deliver the agreed scope of work.

2. Data Categories Processed

CategoryExamplesBasis for processing
Client operational dataDatabases, logs, files shared for analysisContractual necessity
Client contact dataName, email, phone of client personnelContractual necessity
End-user PII (if applicable)Names, emails in client systemsClient instruction only; DPA required
Financial dataInvoice data, payment recordsLegal obligation

3. Data Collection

4. Data Storage

5. Data Access

6. Data Retention & Deletion

7. Data Sharing

CloudFive does not sell, rent, or share client data. The only permitted disclosures are subprocessors necessary to deliver the service, legal requirements (client notified where legally permissible), and client-directed sharing.

8. Breach Notification

In the event of a confirmed data breach affecting client data, CloudFive will notify affected clients within 72 hours of confirmation. Notification will include the nature of the breach, data affected, mitigation steps taken, and recommended client actions.

9. Contact

Data handling inquiries: todd@cloudfive.net

Policy 3 of 6

Incident Response Policy

Effective: June 2026  ·  Owner: Todd Densmore  ·  Review: Annual

1. Purpose

This policy defines how CloudFive detects, responds to, and recovers from security incidents affecting client data or CloudFive systems.

2. What Constitutes an Incident

3. Incident Severity

4. Response Phases

Phase 1 — Detection & TriageIdentify the incident through monitoring alerts (AWS GuardDuty, CloudTrail anomalies, endpoint alerts) or external report. Assess severity. Assign P-level. Begin incident log.
Phase 2 — ContainmentIsolate affected systems (revoke credentials, quarantine EC2 instances, disable compromised accounts). Preserve evidence before remediation.
Phase 3 — EradicationRemove threat, rotate all potentially exposed credentials, review access logs to identify full scope, patch exploited vulnerability.
Phase 4 — RecoveryRestore systems from clean backups. Verify integrity before returning to production. Monitor closely for 48 hours post-recovery.
Phase 5 — Post-MortemConduct blameless post-mortem within 5 business days. Document timeline, root cause, impact, response actions, and prevention measures.

5. Client Notification

6. Contact

To report a suspected incident: todd@cloudfive.net with subject line [SECURITY INCIDENT].

Policy 4 of 6

Vulnerability Management Policy

Effective: June 2026  ·  Owner: Todd Densmore  ·  Review: Annual

1. Purpose

This policy defines how CloudFive identifies, prioritizes, remediates, and tracks security vulnerabilities in its systems and the client environments it manages.

2. Vulnerability Sources

3. Severity & Remediation SLAs

Severity (CVSS)ExamplesRemediation target
Critical (9.0–10.0)Active RCE, Log4Shell-class24 hours
High (7.0–8.9)Auth bypass, data exposure7 days
Medium (4.0–6.9)XSS, privilege escalation30 days
Low (0.1–3.9)Minor info disclosure90 days

4. Patching Procedures

5. Responsible Disclosure

To report a vulnerability: todd@cloudfive.net with subject [VULNERABILITY REPORT]. We acknowledge within 2 business days and request a 90-day coordinated disclosure window.

Policy 5 of 6

Business Continuity & Disaster Recovery Policy

Effective: June 2026  ·  Owner: Todd Densmore  ·  Review: Annual

1. Purpose

This policy defines how CloudFive maintains service continuity and recovers from disruptive events including infrastructure failures, data loss, and personal incapacitation. Given CloudFive's structure as a single-operator consultancy, this policy prioritizes transparency with clients when disruptions occur.

2. Recovery Objectives

System / DataRPO (max data loss)RTO (max downtime)
Client-managed AWS infrastructure24 hours (daily backup)4 hours
Source code (GitHub)0 (push on commit)1 hour
CloudFive internal systems24 hours8 hours
Secrets & credentials0 (1Password sync)1 hour

3. Backup Strategy

4. Scenario Responses

5. Client Notification

CloudFive will notify affected clients within 4 hours of any disruption expected to exceed 2 hours for P1 clients, or 24 hours for P2/P3 engagements. Status updates every 2 hours until resolved.

6. Contact

Todd Densmore — todd@cloudfive.net

Policy 6 of 6

Subprocessor List

Effective: June 2026  ·  Owner: Todd Densmore  ·  Review: Quarterly

The following third-party services may be used in the delivery of CloudFive engagements. Client data is shared with a subprocessor only where required to deliver the agreed scope of work. CloudFive does not use subprocessors for advertising or data monetization.

Infrastructure & Compute

VendorPurposeData sharedHQCompliance
Amazon Web ServicesCloud infrastructure, compute, storage, databasesClient data per engagement scopeUSASOC 2 Type II, ISO 27001, PCI DSS
GitHub (Microsoft)Source code hosting, CI/CDSource code only; no PII without consentUSASOC 2 Type II, ISO 27001

AI & LLM Services (when applicable)

VendorPurposeData sharedHQCompliance
AnthropicClaude API — AI workflow automationPrompt content per engagement; no training on API dataUSASOC 2 Type II
OpenAIGPT API — when specified by client or engagementPrompt content per engagement; Business API no-training opt-outUSASOC 2 Type II

Communication & Productivity

VendorPurposeData sharedHQCompliance
Google WorkspaceEmail, calendar, documentsEmail communications; no client data stored in Docs without consentUSASOC 2 Type II, ISO 27001
ResendTransactional email deliveryEmail address, message contentUSASOC 2 Type II

Security & Operations

VendorPurposeData sharedHQCompliance
1Password (AgileBits)Credential and secret managementEncrypted credential vaults onlyCanadaSOC 2 Type II, ISO 27001

Change Notification

CloudFive will provide 30 days advance notice before adding a new subprocessor that will process client personal data. Contact: todd@cloudfive.net