Trust Center CloudFire
The always-up-to-date, verifiable hub where you can find out how we protect your data
Many of the certifications you see here are not required by law.
However, we chose them anyway, because cloud data security is how we work every single day, across every environment and process we manage—it’s not just a clause in a contract.
Compliance with laws and regulations
We follow all legal requirements, regulations, and codes of conduct—not because we are asked to, but because it is the absolute minimum standard for truly protecting your data.
Going beyond compliance
We have chosen standards and certifications that go beyond the minimum legal requirements. Data security is a responsibility we take seriously and one we share with you.
ISO Certifications
Since 2023, we have subjected our services and infrastructure to annual audits, with an external body verifying both what we claim and what we actually do.
Cert. No. IT23-13504A
ISO 9001:2015 — Quality
Our quality management system: verified behaviors and procedures, not just promises.
Cert. IT23‑13504D
ISO/IEC 27001:2022 — Information Security
The benchmark standard: a structured control program for all cloud services.
View certificate →Cert. N. IT23-13504D
ISO/IEC 27017:2015 — Cloud Security
Controls designed for cloud environments. Few Italian providers offer them.
View certificate →Cert. N. IT23-13504D
ISO/IEC 27018:2019 — Personal Data in the Cloud
Along with 27017, this places us among the few Italian providers certified for both cloud standards.
View certificate →ACN Qualified
Each CloudFire service and infrastructure is individually assessed by the National Cybersecurity Agency, with a dedicated report for each.
QC1 Qualification
IaaS Services
The services known as “CloudFire VMware as a Service” and “CloudFire Openstack as a Service” are certified.
View certificate →QC1 Qualification
SaaS Services
The service known as “CloudFire Veeam Cloud Platform” is certified.
View certificate →
Safety is how we work, not just a certificate
Behind our certifications lies an Information Security Management System (ISMS) integrated with ISO 27001, Legislative Decree 231, and privacy regulations. A single, unified system that oversees all of this, every single day.
Risk management
Access control
Incident Management
Vulnerability
configurations
backup
Logging & monitoring
Network security
Change management
Asset management
Training & Awareness
Audit
KPI & periodic reviews
Privacy and GDPR in practice
We constantly document policies and define processes, roles, and responsibilities. ISO/IEC 27018 is particularly significant to us, as it specifically addresses the protection of personal data in cloud services.
Privacy notices and processes
Mapped treatments and updated information for every service
Roles and responsibilities
Data controller, managers, and designated personnel, with a dedicated DPO
Data Protection Officer
A dedicated point of contact for data protection.
ISO/IEC 27018
External proof that personal data in the cloud is managed according to the standard.
Privacy policy
Governance also follows precise rules
Beyond protecting data, we are committed to acting with integrity in everything we do. To this end, we have adopted the 231/2001 Model, incorporating a code of ethics and an active whistleblowing channel, all fully integrated into our existing systems.
231/2001 Compliance Model
Procedures and tools integrated into the systems we already use, not a separate system.
Supervisory Body
Monitor the model's performance and compliance over time.
Whistleblowing channel
Secure reporting for everyone, with protection for the whistleblower.
Open Whistleblowing channel →Essential subject, a work in progress
CloudFire is an essential entity under the NIS2 directive. We are therefore integrating ACN requirements and measures into the system we have already built, avoiding parallel processes.
What's already there
ISO 27001 ISMS, incident management, technical and organizational measures.
What we are completing
Precise integration of NIS2 requirements and ACN measures.
Your data stays in Italy
All our regions are located in Italy within certified data centers. Data residency is guaranteed—not just as a clause, but as a core architectural principle.
MI1
Milan
Data4 data center in Milan.
MI2
Siziano
Vaultica datacenter in Siziano.
RM1
Rome
Aruba Data Center in Rome.
Security is a shared responsibility
What is protected depends on the service. In general, we at CloudFire handle the management and security of the cloud infrastructure, while you manage the guest operating system and application software. Here is the breakdown by level.
Level
On-Premises
IaaS
IaaS Managed
Platform
Software
Applications
Client
Client
Client
Client
CloudFire
Data & access
Client
Client
Client
Client
CloudFire
Monitoring
Client
Client
Add-ons
CloudFire
CloudFire
OS
Client
Client
Add-ons
CloudFire
CloudFire
Virtualization
Client
CloudFire
CloudFire
CloudFire
CloudFire
Servers
Client
CloudFire
CloudFire
CloudFire
CloudFire
Storage
Client
CloudFire
CloudFire
CloudFire
CloudFire
Networking
Client
CloudFire
CloudFire
CloudFire
CloudFire
Terms, Conditions, and SLAs
Terms and conditions, usage policies, service sheets, support terms, and Service Level Agreements for each individual service. Everything that governs our contractual relationship, clearly laid out.
Legal Terms
FAQ
Is CloudFire ISO 27001 certified?
Yes, since 2019, with annual renewal audits. The certification covers information security management across all CloudFire cloud services.
Does CloudFire data stay in Italy?
Yes. All CloudFire regions (Milan MI1, Siziano MI2, Rome RM1) are in Italy, in ACN-certified data centers. Data residency on Italian territory is guaranteed.
Is CloudFire enabled for Public Administration (PA)?
Yes. The OpenStack as a Service, VMware as a Service, and Veeam Cloud Platform services hold ACN QC1 qualification, and the infrastructure holds AI1 qualification. CloudFire is also enabled on MEPA.
What does shared responsibility with CloudFire mean?
CloudFire manages and protects the cloud infrastructure (hosts, virtualization, network, physical data center security). The customer manages the guest operating system and application software. The level of responsibility varies by service type (IaaS, IaaS Managed, Platform, SaaS).