Cloudtoolz Security

Security overview

CloudToolz is a multi-tenant platform serving membership organisations across the UK, Europe, Asia Pacific and North America. Each client operates on a dedicated, isolated tenant. Our security model is layered: independently certified infrastructure at the foundation, and platform and application controls that are ZENTSO’s own responsibility built on top.

Where is CloudToolz hosted?

CloudToolz is hosted on dedicated servers with Leaseweb, with data residency maintained in-region for each client. All data centres used are ISO 27001 certified. Leaseweb’s data centres are independently certified, including ISO 27001:2022, SOC 1 Type II, SOC 2 and PCI DSS 4.0 (physical security scope), audited by EY and other recognised bodies. Current attestations are available on request.

Hosting Centre UK

Leaseweb, London Data Centre (LON-01), United Kingdom. All data is kept in the UK.

Hosting Centre Germany

Leaseweb, Frankfurt, Germany. All data is kept in Germany.

Hosting Centre Asia Pacific

Leaseweb, Sydney Data Centre (SYD-11), Australia. All data is kept in Australia.

Hosting Centre North America

Leaseweb, Montreal Data Centre (MTL-02), Canada. All data is kept in Canada.

Our hosting provider

Leaseweb, our hosting provider, is headquartered in the Netherlands and operates under EU data-protection frameworks. Leaseweb is a long-standing provider with multiple global data centres and recognised independent certifications, and in 2023 achieved certification under the Climate Neutral Data Centre Pact (CNDCP).

Infrastructure

CloudToolz uses a multi-tier architecture with separate web, database and caching/search tiers. The database, Redis and Elasticsearch servers are accessible only via internal networks.

The application connects to the database using a least-privilege account that cannot access backups, change security settings or decrypt data.

Administrative access to servers is via VPN from whitelisted IP addresses only, secured with multi-factor authentication. All servers are monitored.

How is data stored?

Encryption

Sensitive data is minimised in CloudToolz. Where sensitive data is present, it is encrypted at the application (middleware) layer before it is stored, and isolated per tenant. Data is encrypted in transit using TLS.

As part of our SOC 2 / ISO 27001 readiness programme, we are extending at-rest protection across the storage and backup layers through full disk/VM encryption and native backup encryption, complementing the application-level field encryption already in place.

Data retention and roles

Where CloudToolz integrates with a client CRM, it follows the data retention settings configured in that CRM. Right to erasure is supported for user accounts. In most deployments ZENTSO acts as data processor, with the client as data controller; the specific roles are set out in the contractual documents.

Database backups

Backups are taken on a regular schedule, comprising full, differential and transaction-log backups, and are held on storage separate from the primary database, in-region.

External access control for the web application

All inbound traffic is routed through Cloudflare, which masks origin IP addresses and provides DDoS protection. The web server exposes only port 443.

User accounts are managed via ASP.NET Core Identity, with credentials hashed, and multi-factor authentication enabled by default for administrative accounts.

Application security and assurance

A penetration test is performed on the CloudToolz platform at every major release, in addition to scheduled testing. Applications built on the platform, whether by ZENTSO or by delivery partners, pass through a security review gate before release, with priority on tenant isolation, authentication and payment integration.

ZENTSO is establishing a dedicated security assurance function, reporting to the CTO, responsible for ongoing platform security review, penetration testing and independent assurance.

Payments

CloudToolz supports a range of payment gateways. Card data is never stored or processed on CloudToolz servers. Depending on the gateway, payment capture is handled either by redirect to the gateway’s hosted payment page or via the gateway’s own embedded component; in both cases the card data is handled by the gateway, not by CloudToolz. Our PCI DSS scope is correspondingly limited to the lightweight self-assessment level.

Certification and resilience roadmap

Our infrastructure sits on ISO 27001 and SOC 2 certified data centres today. For the CloudToolz platform layer itself, ZENTSO is progressing toward independent certification (ISO 27001 / SOC 2), building on the governance and assurance function described above.

We are also implementing in-region disaster recovery using Microsoft Azure, with each region’s DR located to preserve the data-residency commitments described above. We are happy to discuss the roadmap and timelines directly.