Outbound verification required
For unexpected sensitive communications, our representative must be able to provide a valid verification method before requesting operational changes, privileged access, or confidential discussion.
To help protect partners from phishing, spoofing, and social engineering, Cloud System Manager follows a zero-trust communication protocol for sensitive technical and corporate communications.
Cloud System Manager personnel will not ask you to change system settings, approve access, share credentials, discuss sensitive operations, or disclose protected information through an unauthenticated communication path.
Any unexpected phone call, video conference, email exchange, or message involving sensitive operations should be verified through your established secure client channel before you proceed.
Use this guidance whenever a person claims to represent Cloud System Manager and requests access, action, or discussion involving sensitive systems or operations.
For unexpected sensitive communications, our representative must be able to provide a valid verification method before requesting operational changes, privileged access, or confidential discussion.
During an unexpected call, meeting, or email exchange, a Cloud System Manager representative may provide a temporary verification token, prearranged code, or other approved validation method.
Use your secure Client Portal, if provisioned, or your established primary account channel to verify the representative before taking action. Do not use unauthenticated public communication paths for sensitive requests.
If an individual claiming to be from Cloud System Manager contacts you and cannot or will not provide a valid verification method, end the communication and report the incident through your established primary account channel.
Cloud System Manager does not require clients or partners to rely on unauthenticated public contact paths for sensitive technical requests.
Employment verification requests require the official verification phone number and access code provided directly by the employee or former employee.
This process is separate from client representative verification and is designed to protect employee privacy.