CloudFiles Trust Center
Security documentation, ready for your review
Certifications, audit reports and security policies for the teams evaluating CloudFiles. Most requests are approved within one business day.
Approved requests get a sign-in link by email, usually within one business day.
Our commitment to your data
CloudFiles surfaces your files on the record rather than taking custody of them. Your documents stay in the storage you already run, what we do process stays inside the data-residency region you choose, and every claim on this page is backed by a document you can read. Use this Trust Center to review our security posture and request the documentation your team needs.
How access works
Request access with your work email
Tell us who you are and what you are evaluating. It takes under a minute.
We approve and email you a sign-in link
Usually within one business day. The link signs you in, so there is no password to create.
Accept the confidentiality agreement and download
One click-through agreement, then the full document set opens for you.
Documents
Public documents open immediately. Everything else opens once your access request is approved and you have accepted the confidentiality agreement.
No documents match that. Clear the filter to see everything.
Certifications
4 documentsCertification is confirmed by an independent surveillance audit every year and by recertification every three years.
Certification is confirmed by an independent surveillance audit every year and by recertification every three years.
Certification is confirmed by an independent surveillance audit every year and by recertification every three years.
The SOC 2 Type II report for the period ending July 2026 is expected in September 2026 and will replace this one.
Reports
5 documentsPolicies
18 documentsLegal
3 documentsSecurity at CloudFiles
The short version of what we do and where the detail lives. The full statement is on our public security page.
Your files stay yours
CloudFiles surfaces files on the record rather than taking custody of them. Documents stay in the storage you already connect: SharePoint, OneDrive, Google Drive, Amazon S3 and Azure Blob Storage.
Data residency
Choose your region when your organisation connects: United States (the default), European Union, United Kingdom or Australia. Your data does not leave the region you selected.
Encryption
TLS 1.2 or higher in transit and AES-256 at rest. CloudFiles never holds the encryption keys for your connected storage, including bring-your-own S3 and Azure Blob.
Document AI
Document AI runs on Amazon Bedrock inside your selected residency region, with zero data retention. No document is ever used to train a model, and there is no secondary purpose.
Authentication
On Salesforce there is no separate CloudFiles login: the Salesforce session is the authentication, so your SSO, identity provider and MFA apply. The HubSpot web app signs in through Google or Microsoft.
Retention and deletion
A 30-day export window after a subscription ends, then deletion, with backup copies purged in the ordinary rotation. Written certification of deletion is available on request.
Sub-processors
The complete and authoritative list of CloudFiles sub-processors is published in Annex III of our Data Processing Addendum, together with the role each one plays and where it processes data. We give 30 days notice of any change, with a right to object.
Frequently asked questions
CloudFiles employs an enterprise-grade Web Application Firewall (WAF) that continuously updates to block emerging threats. DDoS protection is layered at both the application and network levels, minimizing disruption risks. The platform is hosted on AWS with containerized infrastructure, reducing server-level vulnerabilities, and third-party penetration tests are conducted regularly to validate security defenses.
CloudFiles relies on secure token-based authentication methods. API access is managed via API Keys used as bearer tokens, while user access is handled through OAuth 2.0 Single Sign-On.
Yes. All communication is encrypted using TLS 1.2 or higher, ensuring secure data transfer between clients and the platform. Data at rest is encrypted with AES-256, one of the strongest industry standards, across multiple availability zones for durability and resilience. This dual approach ensures that both live traffic and stored data are fully protected.
The SOC 2 Type II report is available to enterprise customers and qualified prospects, under a confidentiality agreement. Request access above and tell us what you are evaluating, and we will grant the enterprise document set.
Our sub-processors are listed in Annex III of the Data Processing Addendum at https://www.cloudfiles.io/dpa, which is the single authoritative list. We give 30 days notice of any change, with a right to object.
Email security@cloudfiles.io. We respond within 2 business days.
Ready to review the documentation?
Request access with your work email. Most requests are approved within one business day.