The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
Regulatory evidence
iManage was founded in 1995 and initially merged with Interwoven in
For each regulation, how many of the requirements it places on your vendors iManage’s public evidence reaches. Open one for every item with its date and source.
What the vendor lists, typed; public items can be read now, the rest are available on request.
57 documents listed on iManage’s trust centre
compliance.imanage.comAnswers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Where data is hosted or processed
Who does iManage use as the data center service providers for cloudimanage (CiM)?
“iManage utilizes several data center service providers to support its services: Microsoft Azure: For Microsoft-owned data centers, iManage provides a virtual operating environment in Microsoft Azure to host its Cloud services. iManage manages and monitors the platform on Microsoft infrastructure (routers, servers, switches). Microsoft is responsible for perimeter and physical security, power, and fire/environmenta...”
as of 21 Sep 2026Source
Where data is hosted or processed
How are data center service providers utilized for imanage.work Customers?
“For imanage.work Customers, iManage employs a similar approach with the following details: iManage-Owned Data Centers: iManage-owned data centers located in co-location facilities (provided by Centersquare or NEXTDC) are used to support services for imanage.work Customers. In these facilities, iManage deploys its hardware in a secure cage. Access is strictly limited to authorized iManage personnel, and the co-loca...”
as of 21 Sep 2026Source
Encryption
How does iManage protect data at rest using encryption in On-Premises Deployments?
“iManage does not provide encryption for on-premises solutions as a productized feature; Customers are responsible for implementing their backend encryption solutions.”
as of 21 Sep 2026Source
Encryption
How is encryption key management, including key rotation, handled within the iManage Cloud?
“See the controls below. Key Management : iManage has a documented encryption key management system. Unique Customer Library Encryption Keys (LEKs) are generated for each Customer and managed securely. The Primary Encryption Keys (PEKs) are stored in segregated secure environments (such as Azure Key Vault) to ensure that no single person can access the entire key set. A Customer Managed Encryption Key (CMEK) soluti...”
as of 21 Sep 2026Source
Encryption
Is iManage email encrypted?
“iManage uses Microsoft Outlook, which uses opportunistic Transport Layer Security (TLS) to encrypt the connection with a recipient’s email provider. However, with TLS, the message might no longer be encrypted after it reaches the recipient’s email provider. In other words, TLS encrypts the connection, not the message. When email is filed into iManage applications using the iManage mail filing system, the data in t...”
as of 21 Sep 2026Source
Encryption
Does iManage have Encryption Key Management Policies or Standards?
“iManage’s encryption key management policies and standards define the lifecycle, rotation, and ownership requirements for encryption keys. iManage-issued keys use automated key policies, while Customers using Customer Managed Encryption Keys (CMEK) would enter their encryption key details via the iManage Control Center. Key management is fully automated, and all encryption keys are stored in separate, secure areas...”
as of 21 Sep 2026Source
Encryption
How does iManage protect data at rest using encryption in the Azure Blob Storage (Cloudimanage)?
“The cloudimanage (CiM) Work 10 application encrypts each Customer document (file) when it is created (uploaded) or saved, using a unique, randomly generated file encryption key (FEK) and the Bouncy Castle AES-256 for Java encryption service. The Work 10 encrypted file is then encrypted by Microsoft Azure when it is stored at rest in Azure Blob Storage using the AES-256-GCM server-side encryption key, which is vali...”
as of 21 Sep 2026Source
Penetration testing
Does iManage perform penetration testing?
“iManage has annual application and network penetration testing performed by accredited third-party penetration testers (ioSENTRIX, a US-based cybersecurity consulting firm founded in 2017). Our Application Security team also performs ad-hoc application penetration testing as needed.”
as of 21 Sep 2026Source
Data retention and deletion
How are Customer data retention and return managed within the iManage Cloud?
“Customer data management includes several safeguards and recovery options: Deletion Process: Authorized Customer users can delete files uploaded to the iManage Cloud. Deleted files are moved to a “Trash” folder, preventing immediate permanent loss and allowing Customer administrators to recover them. Backup and Journaling: If files are cleared from the Trash, they may be recoverable from system backups retained fo...”
as of 21 Sep 2026Source
Data retention and deletion
Who is responsible for records retention in the iManage Cloud, and what is the process?
“Records retention within the iManage Cloud is a shared responsibility: Customer as Data Controller: Customers are responsible for the retention, modification, and disposal of records stored in the iManage Cloud. Service Provision: iManage stores Customer data as part of the subscribed cloud service and retains it until the Cloud Services Agreement expires. Optional Management Tools: For added convenience, iManage...”
as of 21 Sep 2026Source
Data retention and deletion
What is iManage’s policy for data retention after a Customer’s subscription ends or is terminated?
“iManage provides a defined period during which Customer data is retained after subscription termination to facilitate data extraction: Retention Period: Customer data is retained for 90 days after the subscription expires or is terminated, providing sufficient time for data extraction. Post-Retention Deletion: After 90 days, the Customer’s account is disabled, and all Customer data is deleted within 90 days, excep...”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.