Backblaze · Trust Center

Backblaze Trust Center

Trust center

Backblaze publishes a compliance page enumerating its certifications and attestations. There is no dedicated trust.backblaze.com portal; compliance documents and questionnaires are distributed via Whistic, and BAAs / SOC 2 reports are provided on request to eligible customers. Captured from the public compliance page (no automated probe hit; recorded from docs search).

Backblaze maintains a public trust center documenting SOC 2 Type 2, ISO 27001, HIPAA, GDPR, UK GDPR, CCPA/CPRA, PCI-DSS, GovRAMP, TX-RAMP, HECVAT, TPN (Trusted Partner Network) Blue Shield, VPAT (Section 508), and Internet2 Cloud Scorecard compliance.

Cloud StorageObject StorageStorageBackup
Trust center: https://www.backblaze.com/cloud-storage/compliance

Certifications & Compliance

SOC 2 Type 2ISO 27001HIPAAGDPRUK GDPRCCPA/CPRAPCI-DSSGovRAMPTX-RAMPHECVATTPN (Trusted Partner Network) Blue ShieldVPAT (Section 508)Internet2 Cloud Scorecard

Source

Trust Center

Raw ↑
generated: '2026-06-20'
method: searched
probe: false
source: https://www.backblaze.com/cloud-storage/compliance
url: https://www.backblaze.com/cloud-storage/compliance
description: >-
  Backblaze publishes a compliance page enumerating its certifications and
  attestations. There is no dedicated trust.backblaze.com portal; compliance
  documents and questionnaires are distributed via Whistic, and BAAs / SOC 2
  reports are provided on request to eligible customers. Captured from the
  public compliance page (no automated probe hit; recorded from docs search).
certifications:
  - SOC 2 Type 2
  - ISO 27001
  - HIPAA
  - GDPR
  - UK GDPR
  - CCPA/CPRA
  - PCI-DSS
  - GovRAMP
  - TX-RAMP
  - HECVAT
  - TPN (Trusted Partner Network) Blue Shield
  - VPAT (Section 508)
  - Internet2 Cloud Scorecard
notes:
  - SOC 2 Type 2 achieved at the company level (not only data-center level); report available to eligible customers via Sales.
  - ISO 27001 certificates held by the data centers Backblaze predominantly uses; accessible via Whistic.
  - HIPAA Business Associate Agreements executed for Covered Entity customers.
  - PCI-DSS scope covers card processing via Stripe; Backblaze adheres to PCI standards.
request_channels:
  whistic: >-
    Whistic profiles for Education Industry, EU Customers, and All Other
    Customers (documents + security questionnaires).
  sales: BAA requests and SOC 2 report access via Backblaze Sales.
  privacy: https://preferences.backblaze.com
evidence:
  - {source: https://www.backblaze.com/cloud-storage/compliance, kind: compliance-page}
  - {source: https://www.backblaze.com/blog/our-journey-to-soc-2-type-2-certification/, kind: soc2-attestation}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/backblaze-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.