Compliance frameworks, security audits, and quality certifications this company maintains.
Cloudflare complies with the California Consumer Privacy Act and CPRA for its enterprise customers and the users whose traffic flows through Cloudflare's global network, providing data access, deletion, and opt-out mechanisms as required.
Cloudflare supports HIPAA compliance for healthcare organizations using Cloudflare's network security and Zero Trust products, providing Business Associate Agreements and compliant data handling for healthcare customer traffic and access logs.
Cloudflare's SOC 2 Type II report covers security, confidentiality, and availability controls audited annually by an independent third party.
Cloudflare's Information Security Management System has been certified against ISO 27001:2022 by an accredited third-party auditor since 2019.
Regulatory
FedRAMP Moderate
CertifiedCloudflare has achieved FedRAMP Moderate Authorization to Operate, enabling US federal agencies to use Cloudflare's services in official capacity.
Cloudflare is assessed annually as a Level 1 Service Provider under PCI DSS, meeting the highest standard for handling payment card data securely.
Cloudflare maintains GDPR compliance including EU Standard Contractual Clauses, data processing agreements, and regional data residency options for European customers.
Cloudflare is certified under ISO 27701, the international privacy information management standard extending ISO 27001 with GDPR and CCPA alignment.
Cloudflare's cryptographic modules used in government and regulated environments comply with FIPS 140-2 validated standards for encryption.
Cloudflare holds Cloud Security Alliance STAR Level 2 certification, demonstrating rigorous third-party assessment of cloud-specific security controls.