Cloud storage built to help you meet SOC 2 Type 2, HIPAA, GDPR, CCPA/CPRA, and PCI-DSS requirements.

Backblaze B2 Cloud Storage is built to help your organization meet regulatory requirements with third-party certifications, on-demand compliance documentation, and enterprise security controls already in place.
Compliance is a shared responsibility between your organization and your cloud storage provider. Backblaze covers the infrastructure side—our certifications, security controls, and third-party audits are documented below.
Backblaze has achieved Service Organization Control (SOC) 2 Type 2 compliance by an independent third-party firm. Backblaze operates in data centers that are also SOC 2 compliant.
Backblaze can provide a Business Associate Agreement (BAA) upon request for business customers who are Covered Entities under the Health Insurance Portability and Accountability Act (HIPAA).
Backblaze is listed as a Progressing Product in the State Risk and Authorization Management Program (GovRAMP) Authorized Product List.
Backblaze is listed in the Texas Risk and Authorization Management Program (TX-RAMP) Certified Cloud Products list with a Certification Status of TX-RAMP Provisional.
Backblaze completed the Higher Education Community Vendor Assessment Tool (HECVAT) lite and full version 3.06 assessments. Documents can be accessed via Whistic.
Backblaze utilizes Stripe to store and process card information, which, combined with internal security controls, contributes to Backblaze’s adherence to Payment Card Industry Data Security Standard (PCI-DSS) requirements.
Backblaze obtained Trusted Partner Network (TPN) Blue Shield status which is aligned with the Motion Picture Association (MPA) Content Security Best Practices (CSBP) framework.
Backblaze operates primarily in data centers that hold International Organization for Standardization (ISO) 27001 certificates, which can be accessed via Whistic.
Backblaze adheres to General Data Protection Regulation (GDPR) privacy policies. Data Processing Agreement Addendums (DPAs) for EEA/EU and UK residents are available for compliance standards.
Backblaze satisfies California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA) privacy obligations, including consumer requests, data inventory, and a privacy notice.
Backblaze obtained a Voluntary Product Accessibility Template (VPAT) report documenting compliance with Section 508 accessibility guidelines. This report can be accessed via Whistic.
Backblaze has completed the Internet2 Cloud Scorecard for research and educational institutions, and connects to the Internet2's network as part of the Internet2 Peer Exchange (I2PX) program.
Adding Backblaze to our infrastructure allowed us to satisfy our insurance carrier’s requirements. We could prove that we’re maintaining immutable backups on third-party servers located across the country that comply with industry standards for data security.
Access and download Backblaze’s compliance documents and completed questionnaires for the Education Industry,
To manage the personal data collected by Backblaze, please fill out the Privacy Request Form.
To formally request not to sell or share your personal information, please fill out this form.
Yes. Backblaze can provide a Business Associate Agreement (BAA) upon request for business customers who are Covered Entities under HIPAA. A BAA establishes the responsibilities of Backblaze as a business associate when handling protected health information (PHI) on your behalf.
Backblaze currently offers 3 profiles on Whistic: Education Industry, EU Customers, or All Other Customers. Once you have signed up, or signed in, you will be able to view or download the applicable documents and questionnaires.
Backblaze holds or supports the following compliance certifications and frameworks: SOC 2 Type 2, HIPAA, GDPR and UK GDPR, CCPA/CPRA, PCI-DSS, GovRAMP Progressing Snapshot, TX-RAMP Provisional, ISO 27001 (via certified data centers), TPN Blue Shield, HECVAT, VPAT (Section 508), and Internet2.
The Backblaze Storage Cloud also provides a range of security-related services to safeguard account access and the data within accounts, such as multi-factor authentication, application keys, access management controls, server-side encryption (SSE), and Object Lock immutability. Data is stored in infrastructure designed for 11 nines durability, equipped with best-in-class security features and staffed 24/7/365.
Regulatory compliance in cloud storage means your cloud provider's infrastructure, security controls, and data handling practices meet the requirements of the laws and industry standards that apply to your organization. When you store data with Backblaze B2, you get third-party-audited certifications and compliance documentation you can present to auditors, insurers, and enterprise partners.