Our commitment to security compliance
We build a secure, compliant environment for your business by:
Standardizing: Maintaining certifications against the industry’s most rigorous standards.
Governing: Enforcing policies built on global best practices and regulatory requirements.
Validating: Conducting continuous audits and risk assessments to proactively address emerging threats.
Certifications
We validate our security posture through independent third-party audits and certifications. This approach ensures proactive threat management and helps you meet critical security and privacy requirements.
SOC 2, developed by AICPA, assesses the information security controls of service providers to manage risks in outsourced services handling customer data. The SOC 2 Attestation may be requested here.
ISO/IEC 27001 outlines requirements for creating, maintaining, and improving an ISMS to help organizations secure their information assets. The ISO Certification may be requested here.
Payment Card Industry (PCI) provides standards to protect cardholder data. Companies that accept, store, transmit, or affect the security of the cardholder environment must comply with PCI standards. The PCI DSS Attestation of Compliance (AOC) may be requested here.
FedRAMP sets security standards for cloud products used by U.S. government agencies. Cloudera maintains a FedRAMP Moderate authorization for its Cloudera for Government offering. You can find us on the FedRAMP Market Place here.
CyberEssentials+ provides a strong baseline for cybersecurity for organizations in the UK. The CyberEssentials certificate may be requested here.
GovRAMP establishes security standards for cloud solutions used by state and local governments. You can find us on the GovRAMP Authorized Product List here.
The ENS (Esquema Nacional de Seguridad) defines the mandatory security standards for cloud services utilized by Spanish public administrations. The ENS Certificate may be requested here.
TISAX
TISAX is an assessment and exchange mechanism established by the German Association of the Automotive Industry (VDA) for evaluating information security against the VDA Information Security Assessment (ISA). More information may be found here.
Regulatory Compliance
Cloudera maintains industry-standard measures to comply with applicable global laws, rules and regulations, including GDPR. Our products and services are designed with features that help customers meet their own legal and compliance obligations. For information about Cloudera’s data practices, see our Privacy Statement and Product & Service Data Policy.
