Certifications

SOC 2 Certified

SOC 2 Type 2

Certified. Audit period: October 2024 – September 2025. Auditor: CyberGuard Compliance, LLP. Covers security and availability trust services criteria. Zero exceptions noted.

✓ Certified
FinOps Certified Platform

FinOps Certified Platform

The FinOps Foundation awards the FinOps Certified Platform designation to commercial software that accurately aligns with the FinOps Framework. Explore the full directory of foundation-vetted tools on the official FinOps Foundation Landscape.

✓ Certified
AWS Partner

AWS ISV Accelerate Partner

Recognized AWS partner with co-sell support and AWS Marketplace integration for streamlined procurement.

Verified Partner
AWS Cloud Operations Competency

AWS Cloud Operations Competency

AWS Cloud Operations Competency for Cost Management — validated by AWS for delivering proven cost optimization solutions.

Competency Achieved

ISO 27001

CloudFix does not currently hold ISO 27001 certification. Our primary security certification is SOC 2 Type 2, which provides independent third-party assurance over our security, availability, and confidentiality controls. The SOC 2 framework is directly comparable to ISO 27001 in terms of rigor for cloud software providers. We review our certification roadmap annually — please contact us if ISO 27001 is a hard requirement for your procurement process.

Standards Alignment

CloudFix aligns with the CIS AWS Foundations Benchmark where applicable to our infrastructure. This includes:

  • IAM password policies and MFA enforcement
  • Logging configuration (CloudTrail enabled)
  • Encryption at rest and in transit
  • Security group restrictions
  • VPC flow logs

CloudFix follows the AWS Well-Architected Security Pillar principles:

  • Implement a strong identity foundation: IAM roles with least privilege, no long-lived credentials
  • Enable traceability: All fix operations are logged and auditable via CloudTrail
  • Apply security at all layers: VPC isolation, security groups, encryption everywhere
  • Automate security best practices: CloudFormation-based onboarding, SSM-based change management
  • Protect data in transit and at rest: TLS 1.2+ and AES-256

CloudFix is available on AWS Marketplace and has passed AWS's security review process for listed products. This includes:

  • Product security assessment by AWS
  • Secure integration patterns validated
  • Compliance with AWS Marketplace terms
  • Standardized billing through AWS

Downloadable Documents

Access our compliance and security documentation. SOC 2 reports require a signed NDA.

SOC 2 Type 2 Report

Requires NDA. Independent auditor report on CloudFix's control design.

AWS Partner Verification

Verify CloudFix's AWS partner status and competencies.

Penetration Test Summary

Requires NDA. Summary of most recent third-party penetration test results.

Terms of Service

CloudFix and RightSpend terms of service, subscription terms, and usage policies.

Privacy Policy

How CloudFix collects, uses, and protects your information.

Data Processing Addendum

DPA governing the processing of personal data on your behalf.

API Documentation

REST API guide, endpoint reference, and integration examples for ITSM platforms and other integrations.

Architecture Diagrams

Solution architecture and ITSM integration data flow diagrams for enterprise security reviews.

Need documentation for your review?

Request SOC 2 reports, DPA, or other security documents through our secure request form.