Certification Reports and Resources

Download certification reports to understand how independent auditors have vetted our processes.

Certification reports

Please visit our Security Reports & Certifications Center for access to our SOC 2 Type II Report, PCI-DSS SAQ-A, CIS Benchmarks, and colocated data center certifications (e.g., ISO 27001, SOC Reports, PCI-DSS, etc).
soc2

SOC 2 Type II and SOC 3 Type II

DigitalOcean maintains a SOC 2 Type II and SOC 3 Type II certification, issued by our independent auditor, Schellman & Company. By achieving compliance with this globally recognized information security controls framework, DigitalOcean demonstrates a commitment to protecting sensitive customer and company information.

cis

CIS Benchmarks

Through our CIS Foundations and CIS Services Benchmarks, we empower our customers with actionable resources to better secure their infrastructure. And, because CIS Benchmarks are aligned to various security frameworks by design, customers can reference our Benchmarks as a resource for their respective compliance programs.

prp

Global PRP Certification

DigitalOcean maintains compliance with rigorous privacy and data protection standards, as evidenced by our Global Privacy Recognition for Processors (Global PRP) certification. With this certification, DigitalOcean demonstrates our commitment to prioritizing security and confidentiality in data processing operations to maintain trust with our customers.

dss

PCI-DSS

DigitalOcean maintains a Zero-Footprint data policy by way of our PCI-DSS SAQ-A validation. Through our attestation, DigitalOcean commits to not storing, processing, or transmitting cardholder data within our administrative environment.

csa

CSA Self-Assessment

DigitalOcean has achieved Cloud Security Alliance (CSA) STAR Level 1 which addresses fundamental security principles across 16 domains to help cloud customers assess the overall security risk of our services.

Data Center Certifications

DigitalOcean partners with various colocated data center providers around the world to deliver on our mission of democratizing the cloud, invigorate product velocity, and promote predictable economics for our customers. Each of these colocated facilities maintains a unique certification suite that can be accessed through our Security Reports & Certifications Center. The following table outlines the certifications available within each facility.
ISO 9001ISO 14001ISO 22301ISO 27001ISO 45001ISO 50001PCI-DSSSOC 1 Type IISOC 2 Type II
AMS2
AMS3
ATL1
BLR1
FRA1
LON1
NYC1
NYC2
NYC3
SFO1
SFO2
SFO3
SGP1
SYD1
TOR1

AMS2

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

AMS3

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

ATL1

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

BLR1

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

FRA1

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

LON1

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

NYC1

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

NYC2

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

NYC3

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

SFO1

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

SFO2

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

SFO3

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

SGP1

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

SYD1

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

TOR1

ISO 9001
ISO 14001
ISO 22301
ISO 27001
ISO 45001
ISO 50001
PCI-DSS
SOC 1 Type II
SOC 2 Type II

If you have other compliance-related questions, please reach out to trust@digitalocean.com.

Transparency Report

Read all available reports

Like all cloud computing companies, we occasionally receive requests from government agencies regarding one of the servers in our network. To protect our customers, our policy is to fully (and transparently) comply with the legal process, provided that it is legally valid with respect to where the data in question resides.

We stand with our customers when governments ask us for data. We don't disclose user content to law enforcement without proper legal process and we inform users about government data requests unless legally prevented. Our transparency reports outline the requests we receive from law enforcement agencies and explain our commitment to being responsible cloud providers.

Get started for free

Sign up and get $200 in credit for your first 60 days with DigitalOcean.*

*This promotional offer applies to new accounts only.