CloudGuard CNAPP Privacy Data Sheet

CloudGuard CNAPP

This Privacy Data Sheet explains how Check Point's Cloud Native Application Protection Platform ["CloudGuard CNAPP"] processes personal data.

About CloudGuard CNAPP

CloudGuard CNAPP is an integral component of the CloudGuard Cloud Native Security platform, enabling you to prevent threats and prioritize risks across your cloud applications, networks, and workloads. CloudGuard CNAPP object-mapping algorithms integrate cloud inventory and configuration details with real-time monitoring data from multiple sources, such as VPC Flow Logs, CloudTrail, Amazon GuardDuty, AWS Inspector, and Check Point's Threat Cloud feeds. The result is contextualized information utilized within the CloudGuard platform to enhance visualization, querying, intrusion alerts, and policy violation notifications.

How Does Check Point Comply With Applicable Data Protection Regulations?

What Types Of Personal Data Does CloudGuard CNAPP Process?

CloudGuard CNAPP may process the following data:

Why Does CloudGuard CNAPP Process Data?

CloudGuard CNAPP processes data to deliver comprehensive cloud security and risk management across your cloud environments. By analyzing data from cloud applications, networks, and workloads, it can:

For more information on the purposes for which we process personal data, please visit our Privacy Policy.

What is the Duration and Frequency of Processing?

Data is shared with CloudGuard CNAPP throughout the subscription term.

What are the Retention Periods?

Data Type Retention Period
Basic personal data (name, username and corporate email address) Subscription term. Additional retention periods vary based on the purchased license: 1 month,3 months,6 months,or 1 year.
Metadata extracted from AWS/Azure CloudGuard Intelligence Retained for the subscription term. An extended retention period can be purchased as an optional paid add-on.
Logs derived from API calls Retained for 1 year
Alerts Retained for 1 year
Audit Logs Retention duration varies per preference-6 months or 1 year. For Microsoft Azure-3 years.
Workload data for AWP SaaS scanning Such data is scanned for vulnerabilities and deleted immediately

Where Is Personal Data Stored?

Check Point engages third-party Sub-processors in connection with the provision of the Check Point’s products and services. The list of Sub-processors is available at our Sub-Processors Page.

Privacy Options

We provide the following tools, empowering our customers to select their data and privacy preferences:

Authorized Access To Personal Data

Customer Access

Access to data is controlled by customer’s selected administrators. Only users authorized by the administrators can access data. All access and any action taken by administrators or by their authorized users are fully logged.

Data contained within the customer’s CloudGuard CNAPP environment may be accessed by Check Point’s support and R&D teams for troubleshooting and security purposes. Such access is granted only to those authorized representatives for which the access is necessary to perform their intended functions. Any access to specific customer data by Check Point personnel requires prior approval.