Is this your company?Buyers are checking Cloudcard here. Claim cloudcard.us free to control the listing, earn the badge buyers trust, and see who's evaluating you.
We give students and employees the freedom to snap a selfie and sign their cardholder agreement from the control of their phone, tablet, or computer. And we do so with a deep commitment to security. Learn more about our security controls and policies below. For system status, visit [status.onlinephotosubmission.com](https://status.onlinephotosubmission.com/) or [status.cloudcard.ca](https://status.cloudcard.ca/)
SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Other certifications
List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Cloudcard SOC 2 compliant?
Cloudcard is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Cloudcard SOC 2 Type I or Type II?
Cloudcard is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Cloudcard's SOC 2 for a vendor risk assessment?
Yes. Cloudcard's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Cloudcard penetration tested?
Cloudcard hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Cloudcard secure?
Security isn't a single yes/no, but Cloudcard is SOC 2 Type II compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Cloudcard have a bug bounty or vulnerability disclosure program?
Cloudcard hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@cloudcard.us or via a /security page (Cloudcard lists a security contact).
Who are Cloudcard's subprocessors?
Cloudcard lists 3 subprocessors on its trust center, including Amazon Web Services, RemoveBG, ZeroBounce. Buyers use this for fourth-party risk review.
Where does Cloudcard host or store data?
Cloudcard hosts on AWS, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is Cloudcard's trust center or security page?
Cloudcard's trust center is at https://trust.cloudcard.us. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Where can I find CloudCard's Responsible Disclosure Policy?
This policy is available in this Trust Center - see Responsible Vulnerability Disclosure Policy.
Do you have a Bug Bounty Program?
We have a Responsible Vulnerability Disclosure Policy. While we do not offer financial rewards for vulnerability disclosure, we do acknowledge contributions on the CloudCard Responsible Disclosure Acknowledgements page.
How is the model operated by the application?
The AI models operate within the RemotePhoto application to automate the reviewing of submitted photos. Once a photo is uploaded, the AI analyzes it in real-time, providing immediate feedback to the user if the photo meets the necessary criteria or if a new submission is required. This process reduces the need for manual review and accelerates the overall ID issuance workflow.
What technologies are used in the AI?
RemotePhoto employs AI-driven image processing techniques to automate tasks such as cropping, rotating, and classifying photos. Optional features include background removal, facial recognition/comparison, and optical character recognition (OCR) for enhanced verification. Our AI does not use generative techniques, and we do not modify the portion of the image containing the person.
What AI algorithms are used by the application?
The application utilizes neural networks for image analysis tasks. These may include convolutional neural networks (CNNs) for image classification and processing. The system also employs machine learning techniques to improve its accuracy over time through exposure to a diverse set of photo submissions.
What are the inputs to the model?
The primary input is the ID photo submitted by the cardholder via a secure, single-use link. These photos are typically taken with smartphones or webcams and may vary in quality, background, and lighting. RemotePhoto | Quality ID Photos
What are the outputs of the model?
The AI reviews the submitted photos to produce standardized ID images that meet the organization's specifications. This includes ensuring proper cropping, orientation, and background uniformity. The system also determines whether a photo meets the required criteria or needs to be resubmitted. [](https://www.remotephoto.ai/?utm_source=chatgpt.com)
What data sets are used? What is the source of the information used for training?
The training data comprises a variety of ID photo submissions collected over time, encompassing both approved and denied images. This dataset enables the AI to learn the distinguishing features of acceptable ID photos. The sources of these images are the users who submit their photos through the RemotePhoto platform.
Is customer data used to train CloudCard's AI models?
- CloudCard uses proprietary machine learning models to deliver quality ID photos to our customers. - We use de-identified photo data submitted by cardholders to train our machine learning algorithms. - No PII or demographic information is provided to the training algorithms. The photos used for training are entirely anonymous. Even the photo metadata is stripped well before training. So the ML algorithms never even have access to this type of data to prevent biases or superfluous pattern-matching. - We train the models ourselves. We do not contract this out to any third party. - No customer data is retained in the model itself. The resulting artifact is a deep neural network, which contains artificial neurons - not customer data or images. It is similar to training a human bank teller to classify real vs. counterfeit money, the human neural network retains the ability to classify new bills without the human needing to retain the original training bills. - Customers may choose to opt out of allowing their data to be used for training.
Support on AI
For more detailed information on the AI models and their implementation, you may refer to the RemotePhoto Support Center or contact the company directly through their official website. If you have further questions or need additional information, feel free to ask: [sales@cloudcard.us](mailto:sales@cloudcard.us) or support@cloudcard.us
How do you encrypt data at rest?
All our data is stored in AWS, which uses AES-256 for encryption of data at rest.
How do you encrypt data in transit?
All data in transit is encrypted using HTTPS and TLS 1.2 or higher.