
Qumulo
Security and trust center evidence
Store, manage, and simplify all your unstructured data and hybrid workflows in one platform, anywhere - at the edge, in the core, or in any
Summary
Qumulo has 3 vendor-stated rows, and 1 expired in the CertReports index, last verified 18 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 18 Sep 2026, CertReports holds 3 vendor-stated rows and 1 expired row for Qumulo, drawn from its trust centre (Vanta) and the Data Privacy Framework list. Qumulo states on its trust centre that it holds that it will sign a business associate agreement, a SOC 2 Type II report and a data processing agreement, captured 18 Sep 2026; these are vendor statements, not independent confirmations. Qumulo previously appeared with EU-US Data Privacy Framework evidence, but the listing is no longer active and CertReports found no renewal as of 17 Sep 2026. No public evidence was found for ISO/IEC 27001, PCI DSS and FedRAMP as of 18 Sep 2026; that is a gap in the public record, not a finding of non-coverage, and the vendor can supply it under NDA.
- HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured), vendor-stated as of 18 Sep 2026
- SOC 2: Vendor states SOC 2 on its trust centre, vendor-stated as of 18 Sep 2026
- EU-US Data Privacy Framework: Inactive, expired as of 17 Sep 2026
Facts only, each dated; nothing here is inferred, scored or advised.
Evidence count
0verified rows
Compliance grid
- HIPAAVendor-stated
Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)
as of 18 Sep 20261 source
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 18 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 18 Sep 20261 source
EU-US Data Privacy FrameworkExpiredInactive
as of 17 Sep 20261 source
Legal artefacts
Subprocessors (15)
- DatadogCloud monitoring · United States
- ELElastioSecurity · Reston, Virginia
- GWGoogle WorkspaceDocument management · United States
- M3M3terFinance and payments · UK
Microsoft AzureCloud provider · United States
MongoDB AtlasData storage and processing · United States- NENeurealmProfessional services · United States, India
OktaIdentity provider · United States- PagerDutyCloud monitoring · United States
- SASalesforceSales · United States
- SendGridMarketing · Denver, Colorado
SlackCollaboration · United States- STStatsigProduct · Bellevue, Washington
- WIWorkato IncOther · United States
- ZOZoomCollaboration · United States
Change history
- 18 Sep 2026Subprocessor added: SalesforceSalesforce appeared on the subprocessor list.
- 18 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 18 Sep 2026HIPAA evidence addedA HIPAA row entered the index with state Vendor-stated.
- 18 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
- 18 Sep 2026Subprocessor added: DatadogDatadog appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: ElastioElastio appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: Google WorkspaceGoogle Workspace appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: M3terM3ter appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: Microsoft AzureMicrosoft Azure appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: MongoDB AtlasMongoDB Atlas appeared on the subprocessor list.