Browse docs
Docs / Admin & IT / Trust & Compliance

Trust & Compliance

A map for security reviews and procurement. Everything here links to the details; nothing here is a certification we don't hold.

Compliance posture today#

AskStatus
SOC 2On the roadmap (Type I first, then Type II); no formal audit has begun. We answer security questionnaires directly and walk teams through the architecture on request.
FedRAMPRoadmap only. Swarmfile is not FedRAMP-authorized - talk to us before planning around it.
DPAThere's no published, pre-signed DPA today. Start the conversation via contact us and we'll tell you exactly what we can sign and work through your paper.
Subprocessor listBelow, plus the service-provider disclosure in the Privacy Policy.
Security questionnaire / security packageAnswered directly, alongside the Security Architecture whitepaper.
EU / US data residencyAvailable today, free on every paid plan, chosen at org creation - see Data Residency.
Bring-your-own storageAvailable on Enterprise: your own S3-compatible bucket becomes the org's block storage - see Bring Your Own Storage.
Self-hosted control planeAvailable on Enterprise: the same control-plane code on infrastructure you operate, on a self-hostable runtime compatible with the platform it's built on - see Deployment Topologies. A fully air-gapped deployment is on the roadmap.
SAML SSOAvailable on Enterprise via an adapter; OIDC SSO is self-serve on Pro and above - see Identity.

Subprocessors#

These are the third parties that process data for the hosted service, verified from the product's own integrations:

SubprocessorRoleWhat it can access
Cloudflare (Workers, R2, Pages, KV/D1)Hosting for the hub, identity service, dashboard, and default block storage; optional Turnstile bot check at signup/contact; optional Workers Containers for video previewsEncrypted blocks for private projects; unencrypted for Free-plan/public projects by design; request metadata
PostmarkNotification and account email deliveryRecipient addresses and the notification content (event metadata, never file contents)
StripeBilling and paymentsAccount and payment details; never file content
iroh / N0 relay networkNAT traversal for peer-to-peer connections when a direct path failsConnection metadata; relayed traffic is end-to-end encrypted between peers
GoogleGoogle Analytics on the public marketing/docs pages only (not loaded on public project pages, Explore, the signed-in dashboard, or app routes); Google Fonts site-widePage-view metadata (URLs, referrer, approximate location) from analytics; font requests carry the page URL as referrer. No project or file content
GitHubDistribution of the git-LFS agent installer and release artifactsDownload metadata only

With Bring Your Own Storage, block storage moves out of Cloudflare and into your own cloud account; with Dedicated Storage, it moves into a bucket exclusively yours on our infrastructure. Cloud-only mode removes the peer-to-peer path entirely.

Data lifecycle commitments#

  • What's stored: file content (encrypted according to the project's tier), block metadata, project history, and the activity/audit events described in Telemetry & Data Collection.
  • Retention: history, trash, and audit rows default to 90 days and are configurable 1-3650 days per org (users can set their own window). See Operations.
  • Deletion: canceling or an unresolved payment failure starts a 28-day grace period with access blocked and reminder emails, after which the org's data and the owner's account (if it has no other org) are permanently deleted. The org owner can also delete an organization immediately from the dashboard. See Data Portability & Offboarding.
  • Export: there is no lock-in format - the mount is a drive, so teams copy files out with normal tools; the activity feed exports to CSV; Branch Mirror continuously exports real files to a bucket you control. There is no indefinite post-cancellation read state, so export before you cancel.

Encryption you can point at#

  • At rest: AES-256-GCM for private projects on paid plans, with per-project keys; Free-plan and public projects are plaintext by design, and some git-LFS uploads (direct stock-client uploads, and 64 MiB+ uploads through the built-in agent) are stored without application-layer encryption. The full tier comparison and exceptions are in Security Architecture.
  • End-to-end (opt-in, Pro+): the key never reaches our servers; recovery is the customer's responsibility via device transfer and recovery keys.
  • In transit: TLS to the hub and storage; QUIC with end-to-end encryption between peers.

Security contact#

  • Vulnerability reports: the security page directs you to the contact form - put "Security vulnerability" in your message so it reaches the right people. Please include reproduction details and give us reasonable time before public disclosure.
  • Everything else (DPA, questionnaires, incident questions): contact us and mark the request as a security review.

What is not available yet#

Procurement checklists often include these; we don't claim them today:

  • SOC 2 report, penetration-test summary, or a public trust portal.
  • A managed SIEM/streaming export (CSV export and webhooks exist - Operations).
  • Legal hold / retention immutability, DLP watermarking, and share-link domain allowlists (roadmap).
  • A fully air-gapped deployment (the self-hosted control plane exists on Enterprise; air-gapped operation is roadmap).

If one of these is a hard requirement, tell us during the review and we'll talk sequencing honestly rather than work around it.

Where to start a security review#

  1. Security Architecture - tiers, threat model, what each party can see.
  2. Security - operational controls (encryption, integrity, quarantine, cloud-only mode).
  3. Network Requirements - every host, port, and direction.
  4. Telemetry & Data Collection - what is measured and what never leaves unencrypted.
  5. Data Portability & Offboarding - exit path and deletion timing.