Public Cloud Security Guidance for Customers

(Aligned with ISO/IEC 27017 Cloud Security Controls)

1. Overview

This document provides security guidance for customers using our cloud services. Certain requirements may also be incorporated into applicable contractual agreements, acceptable use policies, or terms of service.

Our cloud services are designed to support secure and reliable business operations. To maintain a secure cloud environment, customers / visitors are expected to follow the security practices outlined below when accessing, managing, and using our cloud-hosted services.


2. Shared Responsibility Model

Cloud security is a shared responsibility between the cloud service provider and customers.


Our Responsibilities:

We are responsible for:

  • Securing the underlying cloud infrastructure.

  • Protecting network, platform, and physical hosting environments.

  • Monitoring service availability and security events.

  • Managing infrastructure vulnerabilities and security updates.

  • Maintaining backup, disaster recovery, and business continuity capabilities.

  • Implementing technical and organizational security controls to protect hosted services.


Customers are responsible for:

  • Managing user accounts and access permissions.

  • Protecting authentication credentials.

  • Securing devices used to access cloud services.

  • Protecting data uploaded to cloud services.

  • Ensuring users comply with organizational security requirements.

  • Reporting suspected security incidents or unauthorized activity.

  • Ensuring that personal information uploaded to cloud services is collected, processed, transferred, and retained in accordance with applicable privacy and data protection laws.


3. User Access and Authentication


To protect customer accounts and data, users should:

  • Use strong and unique passwords.

  • Customers should require Multi-Factor Authentication (MFA) for all administrative accounts and for all users wherever available.

  • Never share login credentials with others.

  • Immediately change passwords if compromise is suspected.

  • Review user access regularly and remove access when no longer required.


4. Protection of Information

Customers should apply appropriate safeguards to the information they store or process within the cloud service.


Users are encouraged to:

  • Classify data according to its sensitivity.

  • Limit access to confidential information on a need-to-know basis.

  • Encrypt sensitive files before sharing where appropriate.

  • Avoid storing unnecessary personal or regulated information.

  • Verify recipients before sharing information externally.


Secure Use of Cloud Services:

Users should have no expectation of privacy when using company-provided cloud services except as required by law.


Customers should:

  • Access cloud services only through approved methods and secure networks.

  • Keep operating systems, browsers, and applications up to date.

  • Use endpoint protection software on devices accessing cloud services.

  • Avoid downloading data to unmanaged or public devices.

  • Log out of services when work is complete, especially on shared devices.


Monitoring and Security Logging:

Customers retain ownership of data they upload, store, or process through the cloud services. Use of such data is governed by applicable contractual agreements and privacy notices.


To help protect the cloud environment:

  • Security-related activities may be logged and monitored in accordance with applicable law, privacy requirements, and company policies.

  • Logs may be used to investigate suspicious activity, operational issues, or security incidents.

  • Monitoring is conducted to protect the confidentiality, integrity, and availability of cloud services.

  • Unauthorized attempts to access systems or information would be investigated and escalated as deemed necessary.


5. Incident Reporting

Customers should promptly report any actual or suspected information security incident that may affect the confidentiality, integrity, or availability of cloud services or information.


Examples of reportable incidents include:

  • Suspected account compromise or unauthorized access.

  • Loss, theft, or disclosure of sensitive information.

  • Malware, ransomware, or malicious activity affecting cloud-connected devices.

  • Unauthorized changes to cloud resources or configurations.

  • Security vulnerabilities identified within the cloud service.

  • Any event that could impact the security or availability of cloud services.

Security incidents should be reported as soon as reasonably practicable by contacting the Information Security team at cso@areteir.com.

When reporting an incident, customers should provide available details, including the nature of the incident, affected systems or data, date and time of occurrence, and related details.

Security researchers and customers who identify vulnerabilities are encouraged to report them through designated channels. Reported vulnerabilities will be assessed and remediated according to risk and operational requirements.

Timely reporting enables rapid investigation, containment, remediation, and recovery activities to minimize the impact of security incidents and support the continued protection of customer information and cloud services.

Security reports will be acknowledged within a commercially reasonable period.


6. Business Continuity and Availability

We maintain processes to support service resilience and recovery. Customers should also:

  • Maintain copies of critical business data where appropriate.

  • Understand recovery requirements for their business processes.

  • Establish contingency procedures for critical operations.

  • Review business continuity arrangements periodically.

Arete does not warrant or control the security, availability, or performance of third-party services integrated by customers. As cloud services may depend on underlying third-party cloud providers, software vendors, telecommunications providers, and other technology partners, service restoration and recovery activities may be subject to dependencies outside of our direct control.


Customers should be aware that:

  • The availability and recovery of certain services may depend on the performance, availability, and recovery capabilities of underlying cloud service providers, Original Equipment Manufacturers (OEMs), telecommunications carriers, and other third-party service providers.

  • Incident response, problem resolution, maintenance activities, and service restoration timelines may be influenced by the response and recovery commitments of the respective vendor, OEM, or service provider.

  • While we coordinate and actively engage with relevant third parties during service disruptions, we cannot guarantee recovery or restoration timeframes that are dependent upon external parties.

  • Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs), where defined, may be impacted by third-party outages, force majeure events, or circumstances outside our reasonable control.

We will make reasonable efforts to communicate material service disruptions, planned maintenance activities, and recovery status updates to affected customers and will work collaboratively with service providers and OEMs to restore services as quickly as practicable.


Limitation of Responsibility

To the extent permitted by applicable law and contractual agreements, service availability, incident response, and recovery activities that are dependent upon third-party providers are subject to the operational capabilities, support arrangements, and service commitments of those providers. As a result, recovery and resolution timelines may vary based on the nature of the incident and the responsiveness of the applicable cloud provider, vendor, OEM, or other third-party service provider.

This approach reflects shared responsibility and supplier dependency principles commonly outlined and applied in cloud environments and supports transparency regarding service resilience expectations.


7. Third-Party Integrations

When using third-party applications or integrations with cloud services, customers should:

  • Evaluate the security of third-party providers before enabling access.

  • Grant only the permissions necessary for business purposes.

  • Review and remove unused integrations regularly.

  • Ensure third-party services comply with applicable security and privacy requirements.


Customer Cooperation During Service Interruptions

In the event of a service disruption, security incident, maintenance activity, third-party dependency issue, or other operational requirement affecting cloud services, customers may be required to perform specific actions to support service restoration, risk mitigation, or business continuity activities.

Such actions may include, but are not limited to:

  • Follow temporary workarounds or alternative processing procedures communicated by Arete personnel.

  • Applying vendor-recommended patches, upgrades, or security updates.

  • Disconnecting, modifying, or reconfiguring affected integrations.

  • Validating application functionality following restoration activities.

  • Providing required information to support incident investigation and recovery efforts.

  • Executing customer-controlled recovery or contingency procedures where applicable.

Customers are expected to reasonably cooperate with Arete and, where applicable, the relevant vendor, OEM, cloud provider, or third-party service provider to facilitate the timely resolution of operational, security, and service-related issues.


Dependency on Third-Party Providers

Certain integrations, applications, and services may be dependent upon external vendors, OEMs, cloud providers, telecommunications providers, or other third-party organizations. Resolution timelines, service restoration activities, feature availability, and corrective actions may therefore be subject to the responsiveness, capabilities, and service commitments of the respective third party.

Where customer action is required to support remediation, recovery, security, compliance, or operational continuity, Arete will communicate the required actions and associated timelines to affected customers. Delays in implementing recommended actions may impact service restoration, security posture, functionality, regulatory compliance, or overall business operations.


8. Acceptable Use


Users must not:

  • Attempt to gain unauthorized access to systems or data.

  • Circumvent security controls.

  • Introduce malware or malicious code.

  • Interfere with service availability or performance.

  • Use cloud services for unlawful or unauthorized activities.

Violations may result in suspension of access and further investigation.


9. Security Commitment

We are committed to maintaining a secure cloud environment through risk management, continuous monitoring, incident response, and ongoing improvement of security controls. Customers play an important role in protecting their information and ensuring the secure use of cloud services.

We reserve the right to modify, enhance, or implement additional security controls as necessary to address evolving threats, legal requirements, or operational needs.

Together, these measures help maintain the confidentiality, integrity, and availability of information processed within the cloud environment.

1. Overview

This document provides security guidance for customers using our cloud services. Certain requirements may also be incorporated into applicable contractual agreements, acceptable use policies, or terms of service.

Our cloud services are designed to support secure and reliable business operations. To maintain a secure cloud environment, customers / visitors are expected to follow the security practices outlined below when accessing, managing, and using our cloud-hosted services.


2. Shared Responsibility Model

Cloud security is a shared responsibility between the cloud service provider and customers.


Our Responsibilities:

We are responsible for:

  • Securing the underlying cloud infrastructure.

  • Protecting network, platform, and physical hosting environments.

  • Monitoring service availability and security events.

  • Managing infrastructure vulnerabilities and security updates.

  • Maintaining backup, disaster recovery, and business continuity capabilities.

  • Implementing technical and organizational security controls to protect hosted services.


Customers are responsible for:

  • Managing user accounts and access permissions.

  • Protecting authentication credentials.

  • Securing devices used to access cloud services.

  • Protecting data uploaded to cloud services.

  • Ensuring users comply with organizational security requirements.

  • Reporting suspected security incidents or unauthorized activity.

  • Ensuring that personal information uploaded to cloud services is collected, processed, transferred, and retained in accordance with applicable privacy and data protection laws.


3. User Access and Authentication


To protect customer accounts and data, users should:

  • Use strong and unique passwords.

  • Customers should require Multi-Factor Authentication (MFA) for all administrative accounts and for all users wherever available.

  • Never share login credentials with others.

  • Immediately change passwords if compromise is suspected.

  • Review user access regularly and remove access when no longer required.


4. Protection of Information

Customers should apply appropriate safeguards to the information they store or process within the cloud service.


Users are encouraged to:

  • Classify data according to its sensitivity.

  • Limit access to confidential information on a need-to-know basis.

  • Encrypt sensitive files before sharing where appropriate.

  • Avoid storing unnecessary personal or regulated information.

  • Verify recipients before sharing information externally.


Secure Use of Cloud Services:

Users should have no expectation of privacy when using company-provided cloud services except as required by law.


Customers should:

  • Access cloud services only through approved methods and secure networks.

  • Keep operating systems, browsers, and applications up to date.

  • Use endpoint protection software on devices accessing cloud services.

  • Avoid downloading data to unmanaged or public devices.

  • Log out of services when work is complete, especially on shared devices.


Monitoring and Security Logging:

Customers retain ownership of data they upload, store, or process through the cloud services. Use of such data is governed by applicable contractual agreements and privacy notices.


To help protect the cloud environment:

  • Security-related activities may be logged and monitored in accordance with applicable law, privacy requirements, and company policies.

  • Logs may be used to investigate suspicious activity, operational issues, or security incidents.

  • Monitoring is conducted to protect the confidentiality, integrity, and availability of cloud services.

  • Unauthorized attempts to access systems or information would be investigated and escalated as deemed necessary.


5. Incident Reporting

Customers should promptly report any actual or suspected information security incident that may affect the confidentiality, integrity, or availability of cloud services or information.


Examples of reportable incidents include:

  • Suspected account compromise or unauthorized access.

  • Loss, theft, or disclosure of sensitive information.

  • Malware, ransomware, or malicious activity affecting cloud-connected devices.

  • Unauthorized changes to cloud resources or configurations.

  • Security vulnerabilities identified within the cloud service.

  • Any event that could impact the security or availability of cloud services.

Security incidents should be reported as soon as reasonably practicable by contacting the Information Security team at cso@areteir.com.

When reporting an incident, customers should provide available details, including the nature of the incident, affected systems or data, date and time of occurrence, and related details.

Security researchers and customers who identify vulnerabilities are encouraged to report them through designated channels. Reported vulnerabilities will be assessed and remediated according to risk and operational requirements.

Timely reporting enables rapid investigation, containment, remediation, and recovery activities to minimize the impact of security incidents and support the continued protection of customer information and cloud services.

Security reports will be acknowledged within a commercially reasonable period.


6. Business Continuity and Availability

We maintain processes to support service resilience and recovery. Customers should also:

  • Maintain copies of critical business data where appropriate.

  • Understand recovery requirements for their business processes.

  • Establish contingency procedures for critical operations.

  • Review business continuity arrangements periodically.

Arete does not warrant or control the security, availability, or performance of third-party services integrated by customers. As cloud services may depend on underlying third-party cloud providers, software vendors, telecommunications providers, and other technology partners, service restoration and recovery activities may be subject to dependencies outside of our direct control.


Customers should be aware that:

  • The availability and recovery of certain services may depend on the performance, availability, and recovery capabilities of underlying cloud service providers, Original Equipment Manufacturers (OEMs), telecommunications carriers, and other third-party service providers.

  • Incident response, problem resolution, maintenance activities, and service restoration timelines may be influenced by the response and recovery commitments of the respective vendor, OEM, or service provider.

  • While we coordinate and actively engage with relevant third parties during service disruptions, we cannot guarantee recovery or restoration timeframes that are dependent upon external parties.

  • Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs), where defined, may be impacted by third-party outages, force majeure events, or circumstances outside our reasonable control.

We will make reasonable efforts to communicate material service disruptions, planned maintenance activities, and recovery status updates to affected customers and will work collaboratively with service providers and OEMs to restore services as quickly as practicable.


Limitation of Responsibility

To the extent permitted by applicable law and contractual agreements, service availability, incident response, and recovery activities that are dependent upon third-party providers are subject to the operational capabilities, support arrangements, and service commitments of those providers. As a result, recovery and resolution timelines may vary based on the nature of the incident and the responsiveness of the applicable cloud provider, vendor, OEM, or other third-party service provider.

This approach reflects shared responsibility and supplier dependency principles commonly outlined and applied in cloud environments and supports transparency regarding service resilience expectations.


7. Third-Party Integrations

When using third-party applications or integrations with cloud services, customers should:

  • Evaluate the security of third-party providers before enabling access.

  • Grant only the permissions necessary for business purposes.

  • Review and remove unused integrations regularly.

  • Ensure third-party services comply with applicable security and privacy requirements.


Customer Cooperation During Service Interruptions

In the event of a service disruption, security incident, maintenance activity, third-party dependency issue, or other operational requirement affecting cloud services, customers may be required to perform specific actions to support service restoration, risk mitigation, or business continuity activities.

Such actions may include, but are not limited to:

  • Follow temporary workarounds or alternative processing procedures communicated by Arete personnel.

  • Applying vendor-recommended patches, upgrades, or security updates.

  • Disconnecting, modifying, or reconfiguring affected integrations.

  • Validating application functionality following restoration activities.

  • Providing required information to support incident investigation and recovery efforts.

  • Executing customer-controlled recovery or contingency procedures where applicable.

Customers are expected to reasonably cooperate with Arete and, where applicable, the relevant vendor, OEM, cloud provider, or third-party service provider to facilitate the timely resolution of operational, security, and service-related issues.


Dependency on Third-Party Providers

Certain integrations, applications, and services may be dependent upon external vendors, OEMs, cloud providers, telecommunications providers, or other third-party organizations. Resolution timelines, service restoration activities, feature availability, and corrective actions may therefore be subject to the responsiveness, capabilities, and service commitments of the respective third party.

Where customer action is required to support remediation, recovery, security, compliance, or operational continuity, Arete will communicate the required actions and associated timelines to affected customers. Delays in implementing recommended actions may impact service restoration, security posture, functionality, regulatory compliance, or overall business operations.


8. Acceptable Use


Users must not:

  • Attempt to gain unauthorized access to systems or data.

  • Circumvent security controls.

  • Introduce malware or malicious code.

  • Interfere with service availability or performance.

  • Use cloud services for unlawful or unauthorized activities.

Violations may result in suspension of access and further investigation.


9. Security Commitment

We are committed to maintaining a secure cloud environment through risk management, continuous monitoring, incident response, and ongoing improvement of security controls. Customers play an important role in protecting their information and ensuring the secure use of cloud services.

We reserve the right to modify, enhance, or implement additional security controls as necessary to address evolving threats, legal requirements, or operational needs.

Together, these measures help maintain the confidentiality, integrity, and availability of information processed within the cloud environment.

EXPLORE