Documentation

How Saporo Cloud works

A plain-language tour of what Saporo Cloud is, how your dedicated instance is set up, how we secure and back it up, and how you choose where your data lives.

What is Saporo Cloud?

Saporo Cloud is the fully managed edition of Saporo's identity security posture management platform. You get your own dedicated instance — the same product our on-premise customers run — set up for you in minutes, in the country and jurisdiction you choose. You own your data and your results; we run, secure, back up and keep the platform up to date for you.

  • A dedicated instance per customer — never shared with anyone else
  • Choose where it runs — the EU, France, Switzerland or the United States
  • One address: saporo.cloud to sign in, your own private subdomain for the product
  • Fully managed — we handle hosting, security, updates and backups

Access and sizing

During onboarding, the Saporo team gathers what is needed to size your instance correctly: which data sources you want Saporo to analyse (Active Directory, Entra ID / Azure, AWS, Google and more), roughly how large your environment is, and the region you prefer. Read-only inventory scripts can help collect those figures without storing the results.

  • Pick the data sources Saporo should connect to
  • Your environment size selects the right performance tier automatically
  • Read-only inventory scripts make sizing effortless — nothing is stored
  • Adjust region or size later with a redeployment

Up and running in minutes

When you click Deploy, we automatically build a brand-new, hardened instance dedicated to you — typically in under 30 minutes, with live progress in your dashboard and an email the moment it's ready. The one step on your side is to connect your environment by running the Saporo Cloud Agent — a ready-to-run appliance (OVA/VHD) or a small download — and entering the one-time claim code. Once that claim code is activated, the agent links to your instance automatically. If a deployment ever fails, the half-built instance is cleaned up automatically, so you're never left with stray resources or surprise costs.

  • We build, harden and connect your instance — typically in under 30 minutes
  • Your one easy step: run the Saporo Cloud Agent and enter the claim code; after activation, it connects automatically
  • Live progress in your dashboard; an email when it's ready
  • Automatic clean-up if a deployment can't complete

Security & compliance

Your instance is isolated from every other customer — its own dedicated environment, with no shared application network. All traffic to it is encrypted, and your off-site backups are encrypted with a key unique to your instance. Access is locked down by default: administrator sign-in requires multi-factor authentication, and any access by Saporo staff is least-privilege, time-limited and fully audited. We continuously monitor each instance for security events.

  • Dedicated, isolated instance — no shared tenancy
  • Encrypted connections; off-site backups encrypted per instance
  • Multi-factor authentication for administrator accounts
  • Audit logs retained for 12 months
  • Continuous security monitoring — events logged and audited

Backups & disaster recovery

Your data is protected by several independent layers of backup, taken automatically every day and kept to a defined retention schedule. Off-site copies are stored in a separate cloud and country, so even the loss of an entire data centre is recoverable. We verify backups on a regular schedule, so they're there when they're needed.

  • Multiple independent backup layers, taken daily
  • Off-site copies kept in a separate cloud and country
  • Disaster-recovery ready — designed to survive a full data-centre loss
  • Backups verified on a regular schedule

Where your data lives

You choose the country and jurisdiction for your instance during onboarding, and everything — your instance and all of its backups — stays there. Pick the option that matches your data-residency and sovereignty requirements.

  • European Union — hosted by OVHcloud
  • France, sovereign-grade — hosted by 3DS Outscale (SecNumCloud certified)
  • Switzerland — hosted by Infomaniak
  • United States — hosted on AWS or Microsoft Azure

Logging in and using Saporo

Once your instance is ready, sign in at saporo.cloud with the account created for you by the Saporo team. You land on your portal first — where you manage your license, data collectors, team and password — and open your dedicated Saporo instance in one click from there. The product itself works exactly like the on-premise edition, because it is the same product.

  • Sign in once at saporo.cloud, then open your instance from the portal
  • Multi-factor authentication is carried through end to end
  • Password changes sync to your instance automatically
  • Invite the rest of your team from inside the product

Need more?

Evaluating Saporo for an on-premise, air-gapped, government or sovereign-cloud deployment? Or have a security, compliance or contractual question? Get in touch and we'll connect you with the right team.