Security & Trust

Trust is an engineering practice. Here is how we run it.

Every CirOps engagement involves real access - to infrastructure, to configuration, sometimes to systems that run your product in production. We document and enforce our security practices the same way we engineer client infrastructure: with specificity, accountability, and no assumptions.

Agreed notification

Documented escalation

OIDC

Zero static credentials

SOC2-aligned

Best practices

Credentials & Secrets

Scoped credentials and documented access paths.

CirOps operates a vault-based secrets management practice for client engagements. Here is what that means in practice:

Vault-based secrets storage.

Credentials, API keys, and access tokens used in CirOps-managed engineering workflows are stored in Zoho Vault with role-based access, audit logging, and session-scoped retrieval. Our documented practice prohibits passing secrets through email, chat, or unencrypted channels.

OIDC machine authentication.

Where client environments support it, CirOps engineers configure and use OIDC-based authentication for machine-to-cloud access - eliminating static credentials entirely and replacing them with short-lived, cryptographically signed tokens issued per workflow run.

Temporary cloud access.

Client access is designed around provider-native roles or identities, temporary credentials, automated rotation, or OIDC federation. AWS IAM roles and STS sessions are examples of these controls.

Least-privilege by default.

Access roles scoped to CirOps engineers are defined with minimum required permissions for the specific engagement. We do not request admin-level access unless an engagement specifically requires it, and even then it is time-bound and auditable.

Explore cloud security engineering →

Data Handling

Your data stays in your environment.

CirOps engineers access client infrastructure to assess, build, and operate - not to extract. Our data handling commitment:

What we access.

During engagements, CirOps engineers access cloud console configurations, IaC definitions, log data, and cost and usage reports. We do not access application-layer data (databases, user records, payment data) unless an engagement specifically requires it, in which case access is scoped, logged, and agreed in advance.

Where it lives.

Production data remains in your cloud environments. CirOps does not copy, export, or store client data to our own systems. Any outputs we produce - IaC code, runbooks, architecture documentation - are delivered to you as part of the engagement and removed from our working environments at close.

Retention.

We retain engagement documentation (architecture notes, delivery records) only for the duration agreed in your contract. After that period, client artifacts are deleted from CirOps systems.

AI-assisted tooling and your data.

CirOps engineers use AI-assisted tools for IaC generation, cost anomaly detection, and incident root cause analysis. These tools operate on configuration and telemetry data within your environment. No client configuration data is transmitted to external AI services without your explicit, documented consent. See how CirOps works for full detail on how AI-assisted operations work in practice.

Engagement Terms

Confidentiality is standard, not optional.

CirOps signs non-disclosure agreements before any engagement begins - including initial architecture reviews and discovery calls where sensitive system details may be shared.

We work with your template or provide ours. Either way, confidentiality protection is in place before a single diagram is reviewed or a single credential is shared.

Engagement terms protect your intellectual property in the deliverables we produce. IaC code, runbooks, and architecture documentation created for your environment belong to you.

To request our standard NDA or engagement terms, contact connect@cirops.io.

Zero Trust Access

Access is granted per session, not per relationship.

CirOps applies zero-trust principles to every client environment we operate in. In practice, that means:

OIDC-based access for automation.

CI/CD pipelines, deployment workflows, and operational automation are authenticated via OIDC federation - no static credentials in pipeline configuration, no secrets checked into version control.

Short-lived credentials for human access.

Engineers access client environments through provider-native roles or identities that issue temporary credentials. AWS STS is one example. Sessions expire according to the access policy agreed for the engagement.

Just-in-time access for support operations.

For on-call and incident response, access is granted for the duration of the incident and revoked on resolution. Access events are logged with timestamps, engineer identity, and action scope.

Immutable audit trail.

Client access is recorded through the platform audit logging configured for the environment. AWS STS and CloudTrail are examples; Google Cloud and Microsoft Azure equivalents are used where applicable. Log access and retention follow the agreed engagement controls.

Incident Response

A documented path for client notification.

If a security incident occurs in a client environment during a CirOps engagement, we follow a defined response protocol:

1

Contain

Immediate action to limit the scope of the incident - isolating affected resources, revoking compromised credentials, or halting in-flight deployments.

2

Notify

Notify the named client contacts through the agreed escalation path and within the contractual notification window.

3

Analyze

Root cause analysis conducted in parallel with containment. We do not wait until the incident is resolved to begin investigating the cause.

4

Report

Written post-incident report delivered to the client: timeline, root cause, remediation actions taken, and recommended hardening steps.

You maintain incident command throughout. CirOps operates in support of your team, not around it.

Compliance Posture

Aligned to industry security frameworks.

CirOps's internal security practices are designed to align with SOC 2 Trust Service Criteria and ISO 27001 principles - covering access control, incident response, data handling, and operational security. Clients in regulated industries (fintech, health-tech) may request a security questionnaire response or a summary of our controls mapping.

This page describes CirOps's own engagement practices, including access, secrets, evidence handling, and incident response. It does not make CirOps an auditor of itself or of customers. Client delivery is described separately under Cloud Security, Cloud Compliance Readiness, and Managed Cloud Security Posture.

Certifications

Technical delivery credentials

Credentials and capability areas relevant to an engagement are confirmed during discovery.

AWS

AWS Certified Solutions Architect – Professional
AWS Certified DevOps Engineer – Professional
AWS Certified Advanced Networking – Specialty
AWS Certified Security – Specialty
AWS Certified Solutions Architect – Associate
AWS Certified Developer – Associate
AWS Certified SysOps Administrator – Associate
AWS Certified Cloud Practitioner
AWS Certified AI Practitioner

Kubernetes

Certified Kubernetes Administrator (CKA)
Certified Kubernetes Security Specialist (CKS)
Certified Kubernetes Application Developer (CKAD)
Kubernetes and Cloud Native Security Associate (KCSA)
Kubernetes and Cloud Native Associate (KCNA)

Google Cloud

Google Cloud Professional Cloud Architect
Google Cloud Associate Cloud Engineer

Azure

Microsoft Azure Fundamentals (AZ-900)
Microsoft Azure AI Fundamentals (AI-900)
Microsoft Azure Data Fundamentals (DP-900)
Microsoft Security, Compliance, and Identity Fundamentals (SC-900)

HashiCorp

HashiCorp Certified: Terraform Associate

Common questions about security and access

Start with a no-cost Architecture Review.

If you have questions about our security practices before committing to an engagement, we are happy to answer them directly. Send questions to connect@cirops.io or request a discussion. When you are ready to move forward, the Cloud Architecture Review is a structured assessment of your current infrastructure.