SOC2C

Is this your company? Buyers are checking Qumulo here. Claim qumulo.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Qumulo logo

Qumulo

qumulo.com· 51–200 employees· Security contact
Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Qumulo is SOC 2 Type II compliant. Qumulo also holds GDPR, and HIPAA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Qumulo is dedicated to helping our customers understand how we secure customer information, protect individual privacy, and comply with security and privacy laws and standards. If you have any questions that are not answered on this page, please contact [security@qumulo.com](mailto:security@qumulo.com). You can visit the main Qumulo website at [www.qumulo.com](https://qumulo.com/).

Compliance & infrastructure

Hosting
Azure
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

2

Subprocessors

14
  • M
    Microsoft Azure · Cloud provider
    United States
  • D
    Datadog · Cloud monitoring
    United States
  • G
    Google Workspace · Document management
    United States
  • O
    Okta · Identity provider
    United States
  • P
    PagerDuty · Cloud monitoring
    United States
  • S
    Salesforce · Sales
    United States
  • S
    Slack · Collaboration
    United States
  • W
    Workato Inc · Other
    United States
  • Z
    Zoom · Collaboration
    United States
  • M
    MongoDB Atlas · Data storage and processing
    United States
  • S
    SendGrid · Marketing
    Denver, Colorado
  • S
    Statsig · Product
    Bellevue, Washington
Show all 14 subprocessors
  • M
    M3ter · Finance and payments
    UK
  • E
    Elastio · Security
    Reston, Virginia

Compliance leadership

The person who leads Qumulo's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Qumulo's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Updates to our Subprocessor ListMay 2026

Effective immediately (May 2026) we have updated the list of sub-processors used to process personal data in connection with Azure Native Qumulo (ANQ) and Nexus. These sub-processors will assist us in enhancing your overall experience. We have carefully selected these sub-processors to meet the highest privacy and security standards. The new subprocessors are: SendGrid Statsig Elastio M3ter More details about our full list of subprocessors are available here: https://trust.qumulo.com/subprocessors If you have any questions about these changes, do not hesitate to contact us at [dataprivacyoffice@qumulo.com](mailto:dataprivacyoffice@qumulo.com).

New SOC 2 Reports available!May 2026

Qumulo's SOC 2 Type 2 Reports for the period of November 2024 through November 2025 are now available. Contact security@qumulo.com with any questions. View the Nexus SOC 2 Type 2 Report here. View the Enterprise SOC 2 Type 2 Report here.

Report available validating ransomware prevention with Qumulo and anti-virus!Aug 2024

A new independent third party report, commissioned by Superna, shows that anti-virus deployed in a Qumulo environment will instantly stop multiple types of ransomware attacks! Get the resource here: Report on Superna and Qumulo

Notice of Material Change to Privacy NoticeJul 2024

We have updated our Privacy Notice, effective from July 1, 2024, to clarify how we collect, use, disclose and otherwise process personal data in connection with our Services. If you have any questions about these changes, do not hesitate to contact us at [dataprivacyoffice@qumulo.com](mailto:dataprivacyoffice@qumulo.com) To acquire prior versions of this Privacy Notice, contact [dataprivacyoffice@qumulo.com](mailto:dataprivacyoffice@qumulo.com).

New SOC 2 Type II report available!Jun 2024

Qumulo is proud to announce that we have once again completed a SOC 2 Type II assessment with independent, certified audit agency, A-Lign. This report, which covers the period from April 2023 through March 2024, is available by request at trust.qumulo.com/resources to all current customers and prospects who have signed confidentiality agreements with Qumulo. Please contact security@qumulo.com with any questions!

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Qumulo SOC 2 compliant?
Qumulo is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Qumulo GDPR compliant?
According to Qumulo's public trust center, Qumulo is GDPR compliant. On SOC2C this listing is Listed.
Is Qumulo HIPAA compliant?
According to Qumulo's public trust center, Qumulo is HIPAA compliant. On SOC2C this listing is Listed.
Is Qumulo SOC 2 Type I or Type II?
Qumulo is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Qumulo's SOC 2 for a vendor risk assessment?
Yes. Qumulo's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Qumulo

Reproduced from Qumulo's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do you encrypt data at rest?
Yes. All file data is encrypted at rest by default in Qumulo version 3.1.5 and higher.
Do you support Single Sign-On (SSO)?
Yes. SSO and MFA is available on Qumulo Core 5.2.5.1 and higher.
Do you have access to the data I store on my Qumulo instance?
No, Qumulo does not have access to your file data. If you enable Cloud Based Monitoring for your cluster, Qumulo will collect metrics about the health of your cluster. If you enable Remote Support, Qumulo support engineers will have access to your cluster and the logs necessary to troubleshoot and resolve issues, but not your file data.
How do you handle secure data deletion?
Qumulo has media disposal procedures and policies, and the lifecycle management company we utilize provides certificates of destruction for required resources. Disk retention is available for customers with on-prem deployments who wish to retain and destroy old disks according to their own data deletion policies and practices. For cloud offerings in AWS and GCP, please review their data destruction statements. For the Azure Native Qumulo managed service, the Azure data-destruction statement is available here.
How do you back up my data?
Qumulo does not back up and restore customer data. Customers can manage backup and recovery of their Qumulo instance according to your enterprise BC/DR policy. For customers who require support for immutable point-in-time data, Qumulo ships with Snapshot Locking and Replication functionality that can be set to your specifications based on your data handling policies. These features ship as part of your standard Qumulo software subscription at no extra cost to you, and support many use cases, such as litigation holds, business continuity and disaster recovery, and ransomware protection.