{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"action-verb","name":"Action Verb","domain":"files.com","category":"Cloud storage","one_liner":"Files.com moves and manages every file your business depends on — across any cloud and any partner, from one","trust_center_url":"https://trust.files.com/","security_page_url":null,"url":"https://certreports.com/vendors/action-verb/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"hipaa","framework_name":"HIPAA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states that it will sign a business associate agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/action-verb/hipaa","evidence":[{"source_type":"trust_center","source_name":"Action Verb trust centre (Vanta)","url":"https://trust.files.com/","fetched_at":"2026-09-18 23:08:40.385737+00","content_hash":"82615a7cf82b2739638b4fcf4d33a1b1b0f93d428c57e28f8f92752446bf754a","wayback_url":null,"quote":"HIPAA","confidence":1}]},{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/action-verb/soc-2","evidence":[{"source_type":"trust_center","source_name":"Action Verb trust centre (Vanta)","url":"https://trust.files.com/","fetched_at":"2026-09-18 23:08:40.385737+00","content_hash":"82615a7cf82b2739638b4fcf4d33a1b1b0f93d428c57e28f8f92752446bf754a","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"fedramp","framework_name":"FedRAMP","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a FedRAMP authorization on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states FedRAMP 20x on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/action-verb/fedramp","evidence":[{"source_type":"trust_center","source_name":"Action Verb trust centre (Vanta)","url":"https://trust.files.com/","fetched_at":"2026-09-18 23:08:40.385737+00","content_hash":"82615a7cf82b2739638b4fcf4d33a1b1b0f93d428c57e28f8f92752446bf754a","wayback_url":null,"quote":"FedRAMP 20x","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS - SAQ D, SP and ROC Prep on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/action-verb/pci-dss","evidence":[{"source_type":"trust_center","source_name":"Action Verb trust centre (Vanta)","url":"https://trust.files.com/","fetched_at":"2026-09-18 23:08:40.385737+00","content_hash":"82615a7cf82b2739638b4fcf4d33a1b1b0f93d428c57e28f8f92752446bf754a","wayback_url":null,"quote":"PCI DSS - SAQ D, SP and ROC Prep","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: EU-US Certification","issued_at":"2016-10-04","expires_at":"2027-08-13","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/action-verb/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/7618","fetched_at":"2026-09-17 15:50:11.775486+00","content_hash":"2229d0b008bf02336f527d359a0ca594a9db7f01de80c928d43d05fe985a33c2","wayback_url":null,"quote":"Action Verb LLC: Active: EU-US Certification","confidence":1}]}],"brief":null,"legal_docs":[{"kind":"privacy","url":"https://www.files.com/legal/privacy","availability":"public","detail":null,"as_of":"2026-09-18"}],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T09:12:11.122Z"}