Trust & Compliance

Information Security Policy

The principles, responsibilities and controls Cloudtuner adopts to safeguard information assets, support business continuity and reduce cybersecurity risks.

Effective1st September 2025Last updated20th July 2026
01

Purpose

Cloudtuner is committed to protecting the confidentiality, integrity, and availability of information entrusted to us by our customers, employees, partners, and stakeholders.

This Information Security Policy establishes the principles, responsibilities, and controls adopted by Cloudtuner to safeguard information assets, support business continuity, and reduce cybersecurity risks.

Cloudtuner is operated by:

  • Roboi Private Limited

    India

  • Robo Intelligence Information Technology LLC

    United Arab Emirates

(collectively referred to as "Cloudtuner", "Company", "we", "our", or "us").

02

Scope

This Policy applies to:

  • All Cloudtuner employees, contractors, consultants, interns, and temporary staff
  • All information systems operated by Cloudtuner
  • Cloud infrastructure
  • AI platforms
  • Customer dashboards
  • APIs
  • Managed cloud services
  • Cloud security operations
  • Customer support operations
  • Third-party service providers handling Company information
03

Information Security Objectives

Cloudtuner aims to:

  • Protect customer information from unauthorised access, disclosure, alteration, or destruction
  • Maintain secure and resilient cloud services
  • Protect intellectual property
  • Support regulatory and contractual compliance
  • Promote secure software development
  • Improve operational resilience
  • Continuously strengthen cybersecurity capabilities
04

Security Principles

Cloudtuner's information security programme is based on the following principles:

  • Confidentiality
  • Integrity
  • Availability
  • Least Privilege
  • Need-to-Know Access
  • Defence in Depth
  • Zero Trust principles where practical
  • Secure by Design
  • Privacy by Design
  • Continuous Improvement
05

Governance

Senior management is responsible for supporting the Company's information security programme.

Cloudtuner maintains security policies, operational procedures, and risk management processes designed to safeguard business operations and customer information.

Employees are expected to understand and comply with applicable security requirements.

06

Risk Management

Cloudtuner regularly evaluates information security risks by considering:

  • Cyber threats
  • Infrastructure vulnerabilities
  • Operational risks
  • Third-party risks
  • Insider threats
  • Cloud provider risks
  • Software vulnerabilities
  • Regulatory requirements

Appropriate controls are implemented based on the assessed level of risk.

07

Access Control

Access to systems and information is granted on the basis of business need.

Cloudtuner follows principles including:

  • Role-Based Access Control (RBAC)
  • Least Privilege
  • Multi-Factor Authentication (MFA) for privileged accounts where supported
  • Strong password requirements
  • Secure credential management
  • Periodic review of user access
  • Prompt removal of unnecessary access

Administrative privileges are restricted to authorised personnel.

08

Data Classification

Information should be classified according to its sensitivity, including categories such as:

  • Public
  • Internal
  • Confidential
  • Restricted

Security controls should be proportionate to the sensitivity of the information.

09

Encryption

Where appropriate, Cloudtuner uses industry-recognised encryption technologies to protect information:

  • Encryption in transit
  • Encryption at rest
  • Secure communication protocols
  • Secure key management practices
10

Infrastructure Security

Cloudtuner implements security controls appropriate to its cloud and operational environments, including, where applicable:

  • Network segmentation
  • Firewalls
  • Secure cloud configurations
  • Endpoint protection
  • Vulnerability scanning
  • Patch management
  • Infrastructure monitoring
  • Configuration management
  • Backup procedures
  • Logging and monitoring
11

Secure Software Development

Cloudtuner follows secure software development practices that may include:

  • Secure design principles
  • Code reviews
  • Dependency management
  • Vulnerability remediation
  • Security testing
  • Secrets management
  • Version control
  • Change management
  • Pre-release validation
12

Artificial Intelligence Security

Cloudtuner incorporates AI into certain services.

To support responsible AI deployment:

  • AI systems are subject to security controls appropriate to their use.
  • Access to AI services is restricted to authorised users and systems.
  • AI-generated outputs are reviewed where operationally appropriate.
  • AI is used to assist, not replace, human decision-making.
13

Logging and Monitoring

Cloudtuner may collect and retain security logs relating to:

  • Authentication events
  • Administrative activities
  • API usage
  • Infrastructure events
  • System health
  • Security alerts
  • Audit records

Logs are used to support security monitoring, troubleshooting, compliance, and incident investigations.

14

Vulnerability Management

Cloudtuner maintains processes designed to identify and address security vulnerabilities through activities such as:

  • Vulnerability scanning
  • Security assessments
  • Patch management
  • Configuration reviews
  • Risk-based remediation

Critical issues are prioritised according to risk and operational impact.

15

Incident Management

Cloudtuner maintains procedures for identifying, assessing, responding to, and recovering from information security incidents.

Where appropriate, incident response activities may include:

  • Detection
  • Investigation
  • Containment
  • Eradication
  • Recovery
  • Lessons learned
  • Customer notification where contractually or legally required
16

Business Continuity

Cloudtuner maintains business continuity and disaster recovery planning intended to support the availability of critical services.

Recovery strategies are reviewed and updated periodically based on business requirements.

17

Third-Party Security

Cloudtuner may rely on third-party service providers.

Reasonable efforts are made to evaluate security considerations when selecting providers that process or host Company or customer information.

However, Cloudtuner cannot guarantee the security, availability, or operational practices of third-party providers.

18

Customer Responsibilities

Customers remain responsible for securing their own environments, including:

  • Cloud account administration
  • Identity and Access Management
  • Backup and disaster recovery
  • Security configurations
  • Regulatory compliance
  • User management
  • Data governance
  • Infrastructure changes
  • Security approvals

Cloudtuner provides tools, monitoring, recommendations, and managed services only to the extent agreed under applicable contracts.

19

Security Awareness

Cloudtuner promotes security awareness among its workforce through appropriate training, internal guidance, and ongoing education on information security responsibilities.

20

Compliance

Cloudtuner aims to align its security programme with recognised industry practices and applicable legal and regulatory obligations, including those relating to information security, privacy, and cloud services.

Compliance with this Policy does not constitute a guarantee of compliance with any particular law, certification, or regulatory framework unless expressly stated in a separate written agreement.

21

Security Disclaimer

Cloudtuner follows recognised industry practices designed to protect its systems and customer information. However, no information security programme can eliminate all cybersecurity risks.

Accordingly:

  • No security control can guarantee complete protection against every cyber threat.
  • Sophisticated attacks, zero-day vulnerabilities, insider threats, cloud provider failures, and force majeure events may affect security despite reasonable safeguards.
  • Customers should maintain independent security controls, monitoring, backups, and incident response capabilities.
  • Cloudtuner provides commercially reasonable security measures but does not warrant that its services will be uninterrupted, error-free, or immune from cyberattacks.

Except where liability cannot legally be excluded, Cloudtuner shall not be responsible for losses arising from events beyond its reasonable control, including attacks directed at customer-managed infrastructure or third-party service providers.

22

Policy Violations

Violations of this Policy may result in:

  • Removal of system access
  • Internal disciplinary action
  • Termination of contracts or services
  • Legal action where appropriate
23

Policy Review

This Policy is reviewed periodically and may be updated to reflect changes in technology, business operations, legal obligations, or recognised security practices.

The latest version will be published on the Cloudtuner website.

Contact

Information Security Team

For information security enquiries, incident reporting, or security-related questions, please contact us.

India

Roboi Private Limited

United Arab Emirates

Robo Intelligence Information Technology LLC