CloudFiles Trust Center

Security documentation, ready for your review

Certifications, audit reports and security policies for the teams evaluating CloudFiles. Most requests are approved within one business day.

Approved requests get a sign-in link by email, usually within one business day.

Our commitment to your data

CloudFiles surfaces your files on the record rather than taking custody of them. Your documents stay in the storage you already run, what we do process stays inside the data-residency region you choose, and every claim on this page is backed by a document you can read. Use this Trust Center to review our security posture and request the documentation your team needs.

SOC 2 Type II
ISO 27001:2022 Certified
ISO 27017:2015 Certified
ISO 27018:2019 Certified
HIPAA Compliant
GDPR Compliant

How access works

1

Request access with your work email

Tell us who you are and what you are evaluating. It takes under a minute.

2

We approve and email you a sign-in link

Usually within one business day. The link signs you in, so there is no password to create.

3

Accept the confidentiality agreement and download

One click-through agreement, then the full document set opens for you.

Already have access? Sign in Sent here by someone at CloudFiles? Use the link in their email and you will go straight to the documents.

Documents

Public documents open immediately. Everything else opens once your access request is approved and you have accepted the confidentiality agreement.

Certifications

4 documents
ISO 27001:2022 Certificate
Our current ISO/IEC 27001:2022 certificate of registration.

Certification is confirmed by an independent surveillance audit every year and by recertification every three years.

Certified since 2024-09-09Audited annually
ISO 27017:2015 Certificate
Our current ISO/IEC 27017:2015 certificate for cloud security controls.

Certification is confirmed by an independent surveillance audit every year and by recertification every three years.

Certified since 2024-09-09Audited annually
ISO 27018:2019 Certificate
Our current ISO/IEC 27018:2019 certificate for protection of personal data in the cloud.

Certification is confirmed by an independent surveillance audit every year and by recertification every three years.

Certified since 2024-09-09Audited annually
SOC 2 Type II Report Enterprise
The full independent SOC 2 Type II audit report, for enterprise customers and qualified prospects.

The SOC 2 Type II report for the period ending July 2026 is expected in September 2026 and will replace this one.

v2025Updated 2025-09-05

Reports

5 documents
Penetration Test Report: Web Application Enterprise
The most recent independent third-party penetration test of the CloudFiles web application.
v2025-08Updated 2025-08-13
Penetration Test Report: Network Security Enterprise
The most recent independent third-party penetration test of the CloudFiles network security.
v2025-08Updated 2025-08-13
HIPAA Compliance Report
The current HIPAA compliance report for the CloudFiles platform.
v2025-10Updated 2025-10-10
GDPR Compliance Report
The current GDPR compliance report for the CloudFiles platform.
v2025-09Updated 2025-09-26
Network Diagram
The CloudFiles platform network architecture diagram.

Policies

18 documents
Information Security Policy
The overarching policy that governs the CloudFiles information security management system.
v2.0Updated 2026-08-22
Access Control Policy
How access to systems and data is granted, reviewed and revoked.
v2.0Updated 2026-08-20
Acceptable Usage Policy
The rules for how personnel may use CloudFiles systems and information.
v2.0Updated 2026-08-24
Encryption and Key Management Policy
Cryptographic standards and how keys are generated, stored and rotated.
v2.0Updated 2026-08-20
Business Continuity and Disaster Recovery Procedure
How CloudFiles maintains and restores service through a disruption.
v2.0Updated 2026-08-24
Logging and Monitoring Policy
What is logged, how logs are protected and how they are reviewed.
v2.0Updated 2026-08-23
Human Resource Security Policy
Screening, onboarding, training and offboarding controls for personnel.
v2.0Updated 2026-08-22
Data and Record Retention and Deletion Policy
How long records are kept and how they are securely destroyed.
v2.0Updated 2026-08-24
Information Security Incident Management Policy
How security incidents are detected, escalated, handled and reviewed.
v2.0Updated 2026-08-23
Risk Management Procedure
How information security risks are identified, assessed and treated.
v2.0Updated 2026-08-24
Secure Development and Maintenance Policy
Secure coding, review, testing and change control for the platform.
v2.0Updated 2026-08-24
Backup Policy/Procedure
Backup scope, frequency, protection and restoration testing.
v2.0Updated 2026-08-20
Network Security Policy
Network segmentation, perimeter controls and secure configuration.
v2.0Updated 2026-08-22
Anti-Malware Policy
Protection against malicious software across endpoints and workloads.
v2.0Updated 2026-08-24
Password Policy
Credential strength, storage, rotation and multi-factor requirements.
v2.0Updated 2026-08-22
Physical and Environmental Security Policy
Physical access and environmental controls, including inherited cloud controls.
v2.0Updated 2026-08-24
Information Classification and Asset Management Procedure
How information is classified and how assets are inventoried and handled.
v2.1Updated 2026-08-31
Supplier Management Policy
How suppliers and sub-processors are assessed, contracted and reviewed.
v2.0Updated 2026-08-24

Legal

3 documents
Data Processing Addendum Public
Our DPA, including the Standard Contractual Clauses and the sub-processor list in Annex III.
Updated 2026-08-06
Privacy Policy Public
How CloudFiles collects, uses and protects personal data.
Updated 2026-08-06
Terms of Service Public
The terms that govern use of the CloudFiles service.
Updated 2026-08-06

Security at CloudFiles

The short version of what we do and where the detail lives. The full statement is on our public security page.

Your files stay yours

CloudFiles surfaces files on the record rather than taking custody of them. Documents stay in the storage you already connect: SharePoint, OneDrive, Google Drive, Amazon S3 and Azure Blob Storage.

Data residency

Choose your region when your organisation connects: United States (the default), European Union, United Kingdom or Australia. Your data does not leave the region you selected.

Encryption

TLS 1.2 or higher in transit and AES-256 at rest. CloudFiles never holds the encryption keys for your connected storage, including bring-your-own S3 and Azure Blob.

Document AI

Document AI runs on Amazon Bedrock inside your selected residency region, with zero data retention. No document is ever used to train a model, and there is no secondary purpose.

Authentication

On Salesforce there is no separate CloudFiles login: the Salesforce session is the authentication, so your SSO, identity provider and MFA apply. The HubSpot web app signs in through Google or Microsoft.

Retention and deletion

A 30-day export window after a subscription ends, then deletion, with backup copies purged in the ordinary rotation. Written certification of deletion is available on request.

Sub-processors

The complete and authoritative list of CloudFiles sub-processors is published in Annex III of our Data Processing Addendum, together with the role each one plays and where it processes data. We give 30 days notice of any change, with a right to object.

Frequently asked questions

CloudFiles employs an enterprise-grade Web Application Firewall (WAF) that continuously updates to block emerging threats. DDoS protection is layered at both the application and network levels, minimizing disruption risks. The platform is hosted on AWS with containerized infrastructure, reducing server-level vulnerabilities, and third-party penetration tests are conducted regularly to validate security defenses.

CloudFiles relies on secure token-based authentication methods. API access is managed via API Keys used as bearer tokens, while user access is handled through OAuth 2.0 Single Sign-On.

Yes. All communication is encrypted using TLS 1.2 or higher, ensuring secure data transfer between clients and the platform. Data at rest is encrypted with AES-256, one of the strongest industry standards, across multiple availability zones for durability and resilience. This dual approach ensures that both live traffic and stored data are fully protected.

The SOC 2 Type II report is available to enterprise customers and qualified prospects, under a confidentiality agreement. Request access above and tell us what you are evaluating, and we will grant the enterprise document set.

Our sub-processors are listed in Annex III of the Data Processing Addendum at https://www.cloudfiles.io/dpa, which is the single authoritative list. We give 30 days notice of any change, with a right to object.

Email security@cloudfiles.io. We respond within 2 business days.

Ready to review the documentation?

Request access with your work email. Most requests are approved within one business day.