Clausion Cloud Service Security Policy
Nov 26, 2025
Overview
The Clausion Cloud Solution production environment for the Clausion Financial Performance Management (FPM) consists primarily of, so called, front-end client applications, back-end application services, databases, other data storage and integrations accessible as a service (SaaS, Software-as-a-Service) from a public cloud (Microsoft Azure) over the Internet.
Clausion Cloud Environment Logical Architecture Diagram (Single Instance)
The front-end tier or the client applications are as follows (for details, see the Clausion Financial Performance Management user and administration documentation):
- A browser-based user interface (client) application (Clausion Web Client).
- A Microsoft Excel add-in (ClausionDynamic Reporting, DR) that utilizes a secure REST API for accessing financial reporting data using Microsoft Excel spreadsheets.
- An administrative user interface (client) application (Clausion Admin), accessed via a web browser or the Azure Virtual Desktop (AVD)
All communication is encrypted. The network protocol used is HTTPS (minimum required TLS level 1.2, secured with 2048-bit RSA).
The front-end applications are isolated in their own virtual network and public access is only allowed using the HTTPS protocol to TCP port 443 with no other protocols or ports open. Access may be restricted to customer-specified public IP addresses, if required by the customer, but by default access is allowed from any location.
The back-end application services (Clausion Application Server) are also isolated on their own virtual network with no public access from the Internet at all (no open ports or protocols). Front-end applications have no direct connectivity to actual data, but all communication is through the back-end application services, of which there are separate instances for different customers, different front-end applications and integrations (via the, so called Data Uploader - also known as Integration Executor - application service).
The database services have separate databases for each customer and for different purposes (for example, one or more production databases, one or more test databases, etc.). The databases are not accessible at all directly from the public Internet.
The entire system is monitored using Azure services such as Azure Monitor, Azure Application Insights and Azure Security Center. At the application level, events are logged securely in customer-specific data containers based Azure Storage Accounts. The logs are not accessible at all directly from the public Internet.
General Principles
The following principles, for example, are used to secure the access to the cloud platform:
- Strong password policies.
- Protection of the devices used to access the platform.
- Principle of least privileges. (Minimum rights that enable users to perform only the tasks they are meant to do.)
- Use of additional authentication. (A security mechanism, where a user or a service uses two independent methods to authenticate his access.)
- Use of separate administration accounts.
- Directory segregation (for example, production environment segregation from pre-production or development environments).
- Internal role and responsibility definitions.
- Group-based admin rights.
- Data encrypted at rest.
Network Access Policy
Endpoints
Network endpoints (whether public or private) and Domain Name Service (DNS) names are managed by insightsoftware Cloud Operations.
IP restrictions for customer's public IP addresses may be configured when requested by the customer.
All network communication protocols are always encrypted (connections without data encryption is not allowed).
Communication with the front-end services is only permitted through firewalls, its Distributed Denial of Service (DDoS) resistance framework. Only specific and necessary network ports, and no other network ports or protocols, are open either the to the public network, or from other than restricted IP addresses when IP address restrictions are in use.
Network Isolation
Different functional service layers (front-end applications, back-end application services and components, databases) are separated into their own respective virtual networks, and access is controlled by, so called, network security groups (security rules that allow or deny inbound network traffic to, or outbound network traffic from, several resources) and network security policies.
Identity Management
Clausion Cloud service access by customer users is done through Azure AD (Active Directory) for non-platform customers, or Azure B2C for platform customers.
For non-platform customers using Azure AD: User accounts are created either in theClausion Cloud service's Azure AD or in the customer's own Azure AD. When the customer's own Azure AD is used, the customer's own account policies apply (for password, multi-factor authentication, etc.) and the user account is invited as a "guest" user into the Clausion Cloud service's Azure AD.
For platform customers using Azure B2C is used. User accounts are managed in the manner as non-platform customers.
The industry standard OAuth 2.0 protocol is used for authorization (access delegation) to the Clausion Cloud front-end application services. As of the April, 2022, product release, also OKTA directory authentication/authorization to the service is possible.
Two-factor-authentication (2FA) is supported via the Microsoft Azure AD Multi-Factor Authentication (MFA) for customers using client applications (Clausion Web Client, ClausionDynamic Reporting). Currently 2FA/MFA is optional for Clausion Cloud customers.
Access for administrators to the Clausion Admin client is supported either through a web browser or the Azure Virtual Desktop (AVD) application connects securely through the Azure platform using Microsoft Remote Desktop infrastructure and Azure services. All related resources remain within the Clausion Cloud environment and are managed by insightsoftware Cloud Operations.
Access to specific resources is controlled by Role-Based Access Control (RBAC) policies.
Application level user roles / rights can be managed by the customer's admin users, service access user accounts are managed by Clausion Customer Support.
Password Policy
A password policy is applied to all user accounts that are created and managed directly by the Clausion Cloud service. By default, an account is locked out after 10 unsuccessful sign-in attempts with the wrong password. The user is locked out for one minute. Further incorrect sign-in attempts lock out the user for increasing durations of time.
Users are asked to re-confirm their authentication information after 180 days.
Passwords must not contain the user ID, and need to be at least 8 characters long, with at least 3 of the following: uppercase letters, lowercase letters, numbers, and symbols.
Custom Policies
Custom policies for customers to be negotiated and agreed upon separately with Clausion. E.g., for log file retention times and automatic deletion or archiving of old data.
Integrations
Customer system integrations can be implemented using a variety of methods, but they are always done securely with encrypted connections (transport protocols).
Typically, the integration in Azure is implemented via the use of an Azure Storage Account Service.
Access to the Storage Account is restricted via HTTPS (TLS 1.2 or higher) and a Shared Access Signature (SAS). A SAS is a signed URI that grants secure, delegated access to specific resources. The URI includes a token with query parameters defining permissions and expiry. The signature, generated from these parameters and signed with the account key, is validated by Azure Storage to authorize access.
In the Clausion Cloud service, the SAS token is created with a fixed expiry and only the expiration date is stored in the customer configuration system, not the original SAS token that is provided to the customer using a secure means (such as encrypted email to the designated contact person). If the customer loses the SAS token or for some other reason a new SAS token is created, and the previous expiration date is replaced in the customer configuration data system by the new one.
Access to the Storage Account can also be limited to customer-specified IP addresses.
Azure Monitor and Azure Storage logs are used to monitor the use of Storage Accounts.
Azure Policies and Role-Based Access Control (RBAC) are used to manage Storage Account control and creation.
Separation of Development, Test and Production Environments
Product development and product R&D testing is conducted in separate environments with no connection and access to the customer production environments.
The customer production environment consists of a separate environment with customer production and customer test instances, as well as a further separate staging area for production infrastructure development and testing. Access to the customer production environments is controlled and monitored.
Security
At insightsoftware, we are highly committed to information security and compliance with applicable regulations. We have invested significant time and efforts to design an Information Security Management System that complies with ISO/IEC 27001:2022 standard requirements.
We also have processes in place to comply with the European Union (EU) General Data Protection Regulation (GDPR) that mandates numerous privacy arrangements and controls designed to protect personal data, many of which are also recommended by ISO/IEC 27001:2022 standard.
Security Auditing
Since data security is essential to insightsoftware customers, we take the security of data very seriously and have implemented strong security controls around the Clausion Cloud service to protect all data we process or store.
Our information security program is based on defense in depth and layered security principles which cover people, processes, and technology for all forms of assets (physical and electronic).
The system is designed to apply high-level security models, from coding to implementation, which are regularly audited to meet ISO 27001 standard.
Clausion Financial Performance Management achieved Information Security Management System - ISO/IEC 27001:2022 certification in 06/2024.