Exactly the access we need. Nothing more.
Cloud Parity asks for the least access that makes recovery possible - and never asks for more.
What we ask for
Two grants, created once during onboarding. That is the entire request.
| Where | Access | Why |
|---|---|---|
| Your primary subscription | Read-only | Cloud Parity reads your resources and how they depend on each other. It cannot change, delete, or encrypt anything in the environment it protects. |
| Your recovery subscription | Permission to build | Recoveries and scheduled restore tests need to create resources - but only in the isolated subscription you set aside for them. |
How we hold that access
Read-only where it counts
Backup never needs write access. Your production environment stays exactly as it was, whether we are backing it up or not.
Your data stays in your cloud
Databases, storage, disks, and secrets replicate directly into your own recovery subscription. They never pass through our infrastructure.
Granted by you, revocable by you
Access is created once during onboarding from a template you review and run yourself, and you can withdraw it at any time.
What we store - and what we refuse to
Stored by Cloud Parity
- Resource configurations and the dependency graph
- Encrypted at rest and isolated per customer. This is the backup.
- Operational metadata
- Names, versions, and timestamps used to show what is protected and whether it is current.
Never stored, by design
- Your secrets
- Your application data - databases, blobs, and disks replicate directly into your recovery subscription, never through Cloud Parity
Built for the ransomware case, not just the outage
Your recovery environment lives in a separate subscription - a separate blast radius. An attacker who takes your primary cannot reach it, and cannot quietly destroy the copies waiting there for you.
Talk to us before your security team does
We’re in early access: SOC 2 is on our roadmap and an independent penetration test precedes general availability. Until then we do it the direct way - a working session with your security team, every question answered in full.