Snapshot 19515
Normalized text
Scripts and page chrome removed; this is what change detection compares.
CloudFiles Trust Center Security documentation, ready for your review Certifications, audit reports and security policies for the teams evaluating CloudFiles. Most requests are approved within one business day. Request access to documents Sign in Approved requests get a sign-in link by email, usually within one business day. Our commitment to your data CloudFiles surfaces your files on the record rather than taking custody of them. Your documents stay in the storage you already run, what we do process stays inside the data-residency region you choose, and every claim on this page is backed by a document you can read. Use this Trust Center to review our security posture and request the documentation your team needs. SOC 2 Type II ISO 27001:2022 Certified ISO 27017:2015 Certified ISO 27018:2019 Certified HIPAA Compliant GDPR Compliant How access works 1 Request access with your work email Tell us who you are and what you are evaluating. It takes under a minute. 2 We approve and email you a sign-in link Usually within one business day. The link signs you in, so there is no password to create. 3 Accept the confidentiality agreement and download One click-through agreement, then the full document set opens for you. Already have access? Sign in Sent here by someone at CloudFiles? Use the link in their email and you will go straight to the documents. Documents Public documents open immediately. Everything else opens once your access request is approved and you have accepted the confidentiality agreement. Certifications 4 documents ISO 27001:2022 Certificate Our current ISO/IEC 27001:2022 certificate of registration. Certification is confirmed by an independent surveillance audit every year and by recertification every three years. Certified since 2024-09-09Audited annually Request access ISO 27017:2015 Certificate Our current ISO/IEC 27017:2015 certificate for cloud security controls. Certification is confirmed by an independent surveillance audit every year and by recertification every three years. Certified since 2024-09-09Audited annually Request access ISO 27018:2019 Certificate Our current ISO/IEC 27018:2019 certificate for protection of personal data in the cloud. Certification is confirmed by an independent surveillance audit every year and by recertification every three years. Certified since 2024-09-09Audited annually Request access SOC 2 Type II Report Enterprise The full independent SOC 2 Type II audit report, for enterprise customers and qualified prospects. The SOC 2 Type II report for the period ending July 2026 is expected in September 2026 and will replace this one. v2025Updated 2025-09-05 Request access Reports 5 documents Penetration Test Report: Web Application Enterprise The most recent independent third-party penetration test of the CloudFiles web application. Covers the CloudFiles Viewer, the share-link viewer, including links served on your own custom domain. Relevant if you use CloudFiles document sharing. v2026-09Updated 2026-09-15 Remediation Summary What CloudFiles changed in response to each finding, and the status of each on re-test. v1.0Updated 2026-09-10 Request access Penetration Test Report: Network Security Enterprise The most recent independent third-party penetration test of the CloudFiles network perimeter. Covers the CloudFiles network perimeter and applies to every CloudFiles product. v2026-09Updated 2026-09-16 Request access HIPAA Compliance Report The current HIPAA compliance report for the CloudFiles platform. v2025-10Updated 2025-10-10 Request access GDPR Compliance Report The current GDPR compliance report for the CloudFiles platform. v2025-09Updated 2025-09-26 Request access Network Diagram The production network of the CloudFiles platform: one region drawn, four deployed, with a component table and the review and approval line. v1.0Updated 2026-09-10 Request access Policies 18 documents Information Security Policy The overarching policy that governs the CloudFiles information security management system. v2.0Updated 2026-08-22 Request access Access Control Policy How access to systems and data is granted, reviewed and revoked. v2.0Updated 2026-08-20 Request access Acceptable Usage Policy The rules for how personnel may use CloudFiles systems and information. v2.0Updated 2026-08-24 Request access Encryption and Key Management Policy Cryptographic standards and how keys are generated, stored and rotated. v2.0Updated 2026-08-20 Request access Business Continuity and Disaster Recovery Procedure How CloudFiles maintains and restores service through a disruption. v2.0Updated 2026-08-24 Request access Logging and Monitoring Policy What is logged, how logs are protected and how they are reviewed. v2.0Updated 2026-08-23 Request access Human Resource Security Policy Screening, onboarding, training and offboarding controls for personnel. v2.0Updated 2026-08-22 Request access Data and Record Retention and Deletion Policy How long records are kept and how they are securely destroyed. v2.0Updated 2026-08-24 Request access Information Security Incident Management Policy How security incidents are detected, escalated, handled and reviewed. v2.0Updated 2026-08-23 Request access Risk Management Procedure How information security risks are identified, assessed and treated. v2.0Updated 2026-08-24 Request access Secure Development and Maintenance Policy Secure coding, review, testing and change control for the platform. v2.0Updated 2026-08-24 Request access Backup Policy/Procedure Backup scope, frequency, protection and restoration testing. v2.0Updated 2026-08-20 Request access Network Security Policy Network segmentation, perimeter controls and secure configuration. v2.0Updated 2026-08-22 Request access Anti-Malware Policy Protection against malicious software across endpoints and workloads. v2.0Updated 2026-08-24 Request access Password Policy Credential strength, storage, rotation and multi-factor requirements. v2.0Updated 2026-08-22 Request access Physical and Environmental Security Policy Physical access and environmental controls, including inherited cloud controls. v2.0Updated 2026-08-24 Request access Information Classification and Asset Management Procedure How information is classified and how assets are inventoried and handled. v2.1Updated 2026-08-31 Request access Supplier Management Policy How suppliers and sub-processors are assessed, contracted and reviewed. v2.0Updated 2026-08-24 Request access Legal 3 documents Data Processing Addendum Public Our DPA, including the Standard Contractual Clauses and the sub-processor list in Annex III. Updated 2026-08-06 View Privacy Policy Public How CloudFiles collects, uses and protects personal data. Updated 2026-08-06 View Terms of Service Public The terms that govern use of the CloudFiles service. Updated 2026-08-06 View Security at CloudFiles The short version of what we do and where the detail lives. The full statement is on our public security page. Your files stay yours CloudFiles surfaces files on the record rather than taking custody of them. Documents stay in the storage you already connect: SharePoint, OneDrive, Google Drive, Amazon S3 and Azure Blob Storage. Data residency Choose your region when your organisation connects: United States (the default), European Union, United Kingdom or Australia. Your data does not leave the region you selected. Encryption TLS 1.2 or higher in transit and AES-256 at rest. CloudFiles never holds the encryption keys for your connected storage, including bring-your-own S3 and Azure Blob. Document AI Document AI runs on Amazon Bedrock inside your selected residency region, with zero data retention. No document is ever used to train a model, and there is no secondary purpose. Authentication On Salesforce there is no separate CloudFiles login: the Salesforce session is the authentication, so your SSO, identity provider and MFA apply. The HubSpot web app signs in through Google or Microsoft. Retention and deletion A 30-day export window after a subscription ends, then deletion, with backup copies purged in the ordinary rotation. Written certification of deletion is available on request. Read the full security page Sub-processors The complete and authoritative list of CloudFiles sub-processors is published in Annex III of our Data Processing Addendum, together with the role each one plays and where it processes data. We give 30 days notice of any change, with a right to object. Read Annex III in the DPA Frequently asked questions What security measures does CloudFiles implement to protect the application? CloudFiles employs an enterprise-grade Web Application Firewall (WAF) that continuously updates to block emerging threats. DDoS protection is layered at both the application and network levels, minimizing disruption risks. The platform is hosted on AWS with containerized infrastructure, reducing server-level vulnerabilities, and third-party penetration tests are conducted regularly to validate security defenses. What authentication methods are used for CloudFiles? CloudFiles relies on secure token-based authentication methods. API access is managed via API Keys used as bearer tokens, while user access is handled through OAuth 2.0 Single Sign-On. Is data encrypted in transit and at rest with CloudFiles? Yes. All communication is encrypted using TLS 1.2 or higher, ensuring secure data transfer between clients and the platform. Data at rest is encrypted with AES-256, one of the strongest industry standards, across multiple availability zones for durability and resilience. This dual approach ensures that both live traffic and stored data are fully protected. How do I get the SOC 2 report? The SOC 2 Type II report is available to enterprise customers and qualified prospects, under a confidentiality agreement. Request access above and tell us what you are evaluating, and we will grant the enterprise document set. Who are your sub-processors? Our sub-processors are listed in Annex III of the Data Processing Addendum at https://www.cloudfiles.io/dpa, which is the single authoritative list. We give 30 days notice of any change, with a right to object. How do I report a security issue? Email [email protected]. We respond within 2 business days. Ready to review the documentation? Request access with your work email. Most requests are approved within one business day. Request access to documents Sign in