Security
Last updated: 2026-07-08
Security is foundational to how the Aral Cloud platform, operated by ADSTORE LLC, is built and run. This page summarizes our controls and how to report issues.
1. Tenant isolation
Each customer runs in an isolated private network overlay. Virtual machines are separated at layer 2 (per-tenant bridges with port isolation) and layer 3 (default-deny forwarding), so tenants cannot reach each other on the internal network.
2. Encryption
Traffic to the platform is served over TLS. Secrets at rest — storage credentials, tokens, backup credentials — are encrypted with AES-256-GCM envelope encryption. Managed database and volume snapshots stay within your account.
3. Authentication
Accounts support strong passwords, TOTP two-factor authentication and WebAuthn passkeys. Sessions use short-lived access tokens with an httpOnly refresh cookie; API and automation use scoped bearer tokens you can revoke at any time.
4. Network protection
Public endpoints sit behind an edge gateway with WAF rules and rate limiting. Private-only resources are never exposed to the internet. Floating-IP NAT is scoped per tenant to prevent cross-tenant traffic misdelivery.
5. Access control
Resources are scoped by organization and project; a token only reaches resources in its scope. Internal service-to-service traffic runs on an authenticated message bus with per-node credentials.
6. Backups & recovery
The control plane is backed up with point-in-time recovery and off-host copies. You remain responsible for backups of data inside your own resources; we provide volume snapshots and managed-database backups to help.
7. Responsible disclosure
If you discover a vulnerability, please report it privately to support@aralcloud.uz before public disclosure. We investigate all reports and will acknowledge your contribution.
INN 312519231 · Tashkent, Uzbekistan · support@aralcloud.uz