Is this your company? Buyers are checking Qumulo here. Claim qumulo.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim freeQumulo
Sourced from public information. Not yet verified by the company.
Qumulo is SOC 2 Type II compliant. Qumulo also holds GDPR, and HIPAA.
About
Qumulo is dedicated to helping our customers understand how we secure customer information, protect individual privacy, and comply with security and privacy laws and standards. If you have any questions that are not answered on this page, please contact [security@qumulo.com](mailto:security@qumulo.com). You can visit the main Qumulo website at [www.qumulo.com](https://qumulo.com/).
Compliance & infrastructure
Documents
2Subprocessors
14- MMicrosoft Azure · Cloud providerUnited States
- DDatadog · Cloud monitoringUnited States
- GGoogle Workspace · Document managementUnited States
- OOkta · Identity providerUnited States
- PPagerDuty · Cloud monitoringUnited States
- SSalesforce · SalesUnited States
- SSlack · CollaborationUnited States
- WWorkato Inc · OtherUnited States
- ZZoom · CollaborationUnited States
- MMongoDB Atlas · Data storage and processingUnited States
- SSendGrid · MarketingDenver, Colorado
- SStatsig · ProductBellevue, Washington
Show all 14 subprocessorsShow fewer
- MM3ter · Finance and paymentsUK
- EElastio · SecurityReston, Virginia
Compliance leadership
The person who leads Qumulo's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Qumulo's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
Updates to our Subprocessor ListMay 2026
Effective immediately (May 2026) we have updated the list of sub-processors used to process personal data in connection with Azure Native Qumulo (ANQ) and Nexus. These sub-processors will assist us in enhancing your overall experience. We have carefully selected these sub-processors to meet the highest privacy and security standards. The new subprocessors are: SendGrid Statsig Elastio M3ter More details about our full list of subprocessors are available here: https://trust.qumulo.com/subprocessors If you have any questions about these changes, do not hesitate to contact us at [dataprivacyoffice@qumulo.com](mailto:dataprivacyoffice@qumulo.com).
New SOC 2 Reports available!May 2026
Qumulo's SOC 2 Type 2 Reports for the period of November 2024 through November 2025 are now available. Contact security@qumulo.com with any questions. View the Nexus SOC 2 Type 2 Report here. View the Enterprise SOC 2 Type 2 Report here.
Report available validating ransomware prevention with Qumulo and anti-virus!Aug 2024
A new independent third party report, commissioned by Superna, shows that anti-virus deployed in a Qumulo environment will instantly stop multiple types of ransomware attacks! Get the resource here: Report on Superna and Qumulo
Notice of Material Change to Privacy NoticeJul 2024
We have updated our Privacy Notice, effective from July 1, 2024, to clarify how we collect, use, disclose and otherwise process personal data in connection with our Services. If you have any questions about these changes, do not hesitate to contact us at [dataprivacyoffice@qumulo.com](mailto:dataprivacyoffice@qumulo.com) To acquire prior versions of this Privacy Notice, contact [dataprivacyoffice@qumulo.com](mailto:dataprivacyoffice@qumulo.com).
New SOC 2 Type II report available!Jun 2024
Qumulo is proud to announce that we have once again completed a SOC 2 Type II assessment with independent, certified audit agency, A-Lign. This report, which covers the period from April 2023 through March 2024, is available by request at trust.qumulo.com/resources to all current customers and prospects who have signed confidentiality agreements with Qumulo. Please contact security@qumulo.com with any questions!
This listing is partial
7/11 details · 64%SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Qumulo SOC 2 compliant?
Is Qumulo GDPR compliant?
Is Qumulo HIPAA compliant?
Is Qumulo SOC 2 Type I or Type II?
Can I use Qumulo's SOC 2 for a vendor risk assessment?
Is Qumulo penetration tested?
Can I get Qumulo's SOC 2 report?
Is Qumulo secure?
Does Qumulo have a bug bounty or vulnerability disclosure program?
Who are Qumulo's subprocessors?
Where does Qumulo host or store data?
Where is Qumulo's trust center or security page?
Do you encrypt data at rest?
Do you support Single Sign-On (SSO)?
Do you have access to the data I store on my Qumulo instance?
How do you handle secure data deletion?
How do you back up my data?
How can I get a full SOC2 Report?
Has Qumulo assessed the "SMB Signing not required" finding reported by my vulnerability scanner?
Is Qumulo affected by CVE-2026-31431 (Copy Fail)?
Is Qumulo affected by CVE-2026-43284 ("Dirty Frag"), the Linux kernel privilege escalation vulnerability?
Is Qumulo affected by CVE-2026-24049, the Python wheel path traversal vulnerability?
Is Qumulo affected by CVE-2025-38561, CVE-2025-39698, or CVE-2025-40019, the Linux kernel vulnerabilities reported in USN-8015-1?
Is Qumulo affected by CVE-2025-68615, the Net-SNMP snmptrapd buffer overflow vulnerability?
Science peers that completed SOC 2

Elaborate

Truelearn LLC

Money Forward i Engineering
