Terms of Service

Last updated: March 3, 2026

1. Service Description

Cloud Evidence (“the Service”) provides automated compliance evidence collection and framework mapping for AWS cloud infrastructure. The Service scans AWS resource configuration metadata via a read-only IAM role deployed in your account and generates compliance reports, scores, and exportable evidence packages.

2. Account & Access

  • You must provide a valid email address to create an account.
  • You are responsible for maintaining the security of your account credentials.
  • You are responsible for the IAM role deployed in your AWS account and may revoke access at any time by deleting the CloudFormation stack.

3. Permitted Use

The Service is intended for internal compliance monitoring and audit evidence generation. You may export and share evidence packages with your auditors, compliance teams, and authorized third parties as needed for your compliance program.

4. Data Ownership

  • Your data: you retain full ownership of your AWS configuration metadata and the compliance evidence generated from it.
  • Our service: Cloud Evidence retains ownership of the scanning engine, framework mappings, risk models, and platform software.

5. Read-Only Access

The Service operates exclusively through a read-only IAM role. We do not create, modify, or delete any resources in your AWS account. Our scanner collects configuration metadata only — we never access the contents of your S3 objects, databases, or application data.

6. Service Level

We strive for continuous availability but do not guarantee a specific uptime SLA during the current product phase. Scheduled maintenance windows will be communicated via email. Scan results are retained for 400 days.

7. Limitation of Liability

Cloud Evidence provides compliance evidence and framework mappings as informational tools. The Service does not constitute legal, regulatory, or audit advice. Compliance determinations are ultimately the responsibility of your organization and your auditor. We are not liable for audit outcomes or regulatory decisions based on evidence generated by the Service.

8. Termination

You may terminate your account at any time. Upon termination, we will delete your data in accordance with our Privacy Policy. We reserve the right to suspend accounts that violate these terms or engage in abusive use of the platform.

9. Changes to Terms

We may update these terms from time to time. Material changes will be communicated via email to the address on your account. Continued use of the Service after changes take effect constitutes acceptance of the updated terms.

10. Contact

For questions about these terms, contact us at legal@cloudevidence.io.