Cloud Parity
Sign inSee your recovery plan
Security & access model

Exactly the access we need. Nothing more.

Cloud Parity asks for the least access that makes recovery possible - and never asks for more.

What we ask for

Three grants, created once during onboarding. That is the entire request.

WhereAccessWhy
Your primary subscription - inventoryRead-onlyCloud Parity reads your resources and how they depend on each other. It cannot change, delete, or encrypt anything in the environment it protects.
Your primary subscription - backupPermission to request a backup, and to write itAsking Azure for a backup is itself a write. Cloud Parity can request one and land the copy in the resource group you create and designate - nothing else in your primary environment.
Your recovery subscriptionPermission to buildRecoveries and scheduled restore tests need to create resources - but only in the isolated subscription you set aside for them.

How we hold that access

Two writes, and nothing else

Backup writes exactly two things, both inside your subscription: a request for an Azure backup, and the copy it produces - into a resource group you create and scope yourself.

Your data stays in your cloud

Databases, storage, disks, and secrets replicate directly into your own recovery subscription. They never pass through our infrastructure.

Granted by you, revocable by you

Access is created once during onboarding from a template you review and run yourself, and you can withdraw it at any time.

What we store - and what we refuse to

Stored by Cloud Parity

Resource configurations and the dependency graph
Encrypted at rest and isolated per customer. This is the backup.
Operational metadata
Names, versions, and timestamps used to show what is protected and whether it is current.

Never stored, by design

  • Your secrets
  • Your application data - databases, blobs, and disks replicate directly into your recovery subscription, never through Cloud Parity

Built for the ransomware case, not just the outage

Your recovery environment lives in a separate subscription - a separate blast radius. An attacker who takes your primary cannot reach it, and cannot quietly destroy the copies waiting there for you.

Talk to us before your security team does

We’re in early access: SOC 2 is on our roadmap and an independent penetration test precedes general availability. Until then we do it the direct way - a working session with your security team, every question answered in full.