SaaS Ranking

Cloudinary

What Cloudinary publishes, measured on their own site. Every result below links the page we found it on, or lists the addresses we checked.

Vendor site: cloudinary.com · category: Digital asset management

Data processing agreement

No data processing agreement found.

Checked 8 addresses on 2026-08-31.

Show the 8 addresses we checked
  1. https://cloudinary.com/legal/dpa – reached, no match (HTTP 404)
  2. https://cloudinary.com/dpa – reached, no match (HTTP 404)
  3. https://cloudinary.com/legal/data-processing-agreement – reached, no match (HTTP 404)
  4. https://cloudinary.com/data-processing-agreement – reached, no match (HTTP 404)
  5. https://cloudinary.com/legal/data-processing-addendum – reached, no match (HTTP 404)
  6. https://cloudinary.com/legal/gdpr – reached, no match (HTTP 404)
  7. https://cloudinary.com/trust/dpa – reached, no match (HTTP 404)
  8. https://cloudinary.com/privacy/dpa – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Subprocessor list

The actual list is published, not just a promise to keep one.

Source: https://cloudinary.com/trust/subprocessors · checked 2026-08-31

Data location stated

The hosting location is stated on a public page.

Source: https://cloudinary.com/trust · checked 2026-08-31

Status page with history

A public status page with incident history.

Source: https://status.cloudinary.com/ · checked 2026-08-31

Public pricing

Actual numbers on a public page.

Source: https://cloudinary.com/pricing · checked 2026-08-31

Certifications named

SOC 2 or ISO 27001 named on a public page.

Source: https://cloudinary.com/trust · checked 2026-08-31

Uptime SLA with a figure

An availability commitment with a figure.

Source: https://cloudinary.com/integrations/slack · checked 2026-08-31

HTTPS enforced with HSTS

No enforced HTTPS with HSTS found.

Checked 2 addresses on 2026-08-31.

Show the 2 addresses we checked
  1. http://cloudinary.com/ – redirects to https://cloudinary.com/
  2. https://cloudinary.com/ – no HSTS header

Is this wrong? Send us the URL

No third-party tracking before consent

No consent-free first load found.

Checked 1 address on 2026-08-31.

Show the 1 address we checked
  1. https://cloudinary.com/ – third-party requests before any interaction: cdn-4.convertexperiments.com, cdn.cookielaw.org, cdn.debugbear.com, cdn.jsdelivr.net, fonts.googleapis.com, geolocation.onetrust.com, pagead2.googlesyndication.com, script.crazyegg.com, www.googletagmanager.com

Is this wrong? Send us the URL

security.txt (RFC 9116)

Not measured. The vendor’s server blocked or rate-limited our crawler, so this was not measured.

Show the 1 address we checked
  1. https://cloudinary.com/.well-known/security.txt – blocked or unavailable (HTTP 403)

Is this wrong? Send us the URL

Notice before subprocessors change

Not measured. This criterion was added after the latest run, so it has not been measured yet. The next run covers it.

Named privacy contact

Not measured. This criterion was added after the latest run, so it has not been measured yet. The next run covers it.