Federal Risk and Authorization Management Program (FedRAMP)
Files.com holds a FedRAMP 20x Class A Certification for its Secure File Orchestration Software-as-a-Service Platform, granted by FedRAMP on August 26th, 2026.
Files.com is listed in the FedRAMP Marketplace under FedRAMP ID FR2630354495, and the Certification Package described on this page is the package FedRAMP reviewed. The offering is in the Ongoing Certification Phase.
Class A Certification has no fixed expiration date. It remains in effect for as long as Files.com continues to satisfy the applicable Class A Ongoing Certification requirements. Where an agency's use case or data impact level calls for a higher class, Files.com will pursue the Class B, C, or D Certification that use case requires.
This page is the human-readable form of the FedRAMP Certification Data that CDS-CSO-PUB requires providers to publish. Its machine-readable equivalent is the Certification Package Overview JSON, linked below, and the two carry the same information and are updated together.
Certification at a glance
- FedRAMP ID — FR2630354495
- FedRAMP Marketplace listing — https://www.fedramp.gov/marketplace/products/FR2630354495/
- Provider — Action Verb LLC dba Files.com
- UEI Number — E41FM27LQUY7
- Certification Profile — Type 20x, Path Program, Class A
- Service Model — Software as a Service (SaaS)
- Deployment Model — Public Cloud
- Business Category — Data Management; Storage
- Overall security categorization — Moderate
- Next Ongoing Certification Report — October 1st, 2026
- FedRAMP Recognized independent assessment service — None engaged. Not required at Class A, where certification rests on an approved alternative security framework. See Independent assessment below.
Machine-readable Certification Package Overview: https://filescorp.hosted-by-files.com/Compliance-Hosting/FedRAMP-JSON/files-com-fedramp-certification-data.json
Served with cross-origin headers permitting retrieval from fedramp.gov. This page is its human-readable equivalent; a reader arriving at either can reach the other.
About the Offering
Files.com is a Software-as-a-Service platform with one unified application and API to manage, store, and transfer files across your organization.
Product website: https://www.files.com
Product logo: https://filescorp.hosted-by-files.com/Compliance-Hosting/FedRAMP-Logo/files-pinwheel.svg
Services included in the certification
Four services are in the FedRAMP Minimum Assessment Scope.
| Service | What it covers | Confidentiality | Integrity | Availability | Overall |
|---|---|---|---|---|---|
| Core File Orchestration/MFT Platform | Transfer engine, workflows, and automation | Moderate | Moderate | Moderate | Moderate |
| Managed Storage | Customer files at rest | Moderate | Moderate | Moderate | Moderate |
| Admin/Management Console & Access Control | Single sign-on, user and permission management | Moderate | Moderate | Moderate | Moderate |
| API layer | Programmatic access to the Files.com platform | Moderate | Moderate | Moderate | Moderate |
How to read the security categories
These are security categories in the sense of NIST FIPS 199: the characterization of an information system based on the potential impact that a loss of confidentiality, integrity or availability would have on organizational operations, assets or individuals. FedRAMP often refers to them as impact levels. There are three:
| Level | Potential impact of a loss |
|---|---|
| Low | Limited adverse effect on operations, assets or individuals |
| Moderate | Serious adverse effect on operations, assets or individuals |
| High | Severe or catastrophic adverse effect on operations, assets or individuals |
Each of the three objectives is categorized separately, and the overall categorization of a system is the highest of the three — the high-water mark. All four Files.com services are Moderate on each objective, so each is Moderate overall, and so is the offering.
Two things these categories are not. They are not the certification class. Files.com holds a Class A certification; the class describes the certification pathway and the assessment requirements that go with it, while Moderate describes the impact of a loss. FedRAMP is transitioning from impact-level language to Class A–D designations and is showing previous impact levels alongside classes until December 31st, 2026.
And they are not the trust services categories of the SOC 2 examination. Those are Security, Availability and Confidentiality — a different triad from a different framework, and they appear under Independent assessment below. Confidentiality and Availability appear in both by coincidence of vocabulary, not because they mean the same thing.
Not included in the FedRAMP Minimum Assessment Scope
Three resources are outside the scope, each because it handles no federal customer data and does not affect the confidentiality, integrity or availability of data handled by the offering.
- Public marketing site — https://www.files.com
- Public product documentation — https://www.files.com/docs
- Service availability reporting — https://status.files.com. Deliberately excluded and deliberately hosted externally on Atlassian Statuspage, so that availability information stays reachable during a disruption of the offering itself.
The Files.com Desktop App, mobile applications, command line interface and on-premise Agent are installed on customer systems and are not operated by Files.com in a shared responsibility model. FedRAMP places separately delivered software of that kind outside its statutory scope, so those clients are not certified services.
Configuration for Federal tenant accounts
FedRAMP Security Mode is enabled and disabled by the Federal tenant's own Site Administrator. Files.com does not apply it unilaterally, does not impose a compliance posture on a customer site, and does not withhold the ability to change it. While the mode is enabled, no administrator can relax a setting it locks at any privilege level.
The six values the mode sets and locks are these, as published in the configuration guidance at https://www.files.com/docs/settings-and-usage/security/fedramp-security-mode:
| Setting | What the mode enforces |
|---|---|
| SMS as a two-factor authentication method | Unavailable |
| Legacy insecure ciphers for SFTP | Disabled |
| Weak Diffie-Hellman parameters for SFTP | Disabled |
| SSL on all FTP connections | Required |
| Per-user FTP SSL overrides | Disabled |
| Data routing | Confined to United States regions |
Customer file contents are stored in United States regions for as long as the mode is enabled, and an attempt to assign a folder to a region outside the United States is refused.
TLS 1.2 as the minimum for all communication is a platform default rather than one of the six. It holds for every Files.com account, established in the engineering configuration of the transport modules and verified by the service auditor, so a Federal tenant receives it whether or not the mode is enabled. It is stated here because an agency needs to know the minimum, not because the mode imposes it.
While the mode is enabled it applies sitewide, across every Workspace, and admits no exception at the folder level. Workspace Administrators can neither enable nor disable it nor relax anything it locks. An attempt to modify a governed setting is refused.
Child Sites are governed from the parent. A Child Site is a separate site rather than a Workspace, so the parent enforces the mode on it through a Child Site Management Policy. Setting the mode in that policy adds the six enforced values to it and locks them on every Child Site the policy covers; a Child Site Administrator cannot relax any of them or disable the mode while the policy holds it. A hierarchical account structure therefore cannot be used to establish a less restricted scope beneath a governed site, because the parent — not the child — decides whether the policy carries the mode. Full guidance is at https://www.files.com/docs/settings-and-usage/child-sites/child-site-management-policies.
Disabling the mode removes the locks, not the hardened values. Every affected setting returns to the Site Administrator's control at its enforced value, and stays there until someone changes it deliberately. Nothing short of disabling the mode unlocks any part of the set, so an account is either in the governed configuration or visibly not in it.
Enabling the mode is the agency's action, and it is gated.
- A Site Administrator selects FedRAMP Security Mode.
- Two conditions block the change until they are resolved. Any per-user FTP SSL override must be cleared first — the platform does not clear them for the site, deliberately, because a user configured to bypass SSL is often one half of a working exchange with an outside party. And any folder assigned to its own storage region must be returned to the site's default region.
- With both resolved, the mode is enabled and the six values are set and locked.
- Users who authenticate by SMS do not block the change. They are required to set up another factor at their next connection, over file transfer clients as well as the web interface.
- A Site Administrator can disable the mode later. Files.com does not hold that decision, and does not prevent a Federal tenant from leaving the configuration it chose to enter.
Full configuration guidance for the mode is published at https://www.files.com/docs/settings-and-usage/security/fedramp-security-mode.
This matches FedRAMP's own division of responsibility, which requires agencies to review the secure configuration guidance a provider supplies and configure the relevant security settings. Files.com supplies the capability and the guidance; the agency decides whether to enable it and whether to keep it enabled. A Federal tenant account on which the mode has not been enabled, or on which it has been disabled, is not operating in the configuration described on this page.
Once enabled, the mode narrows what a Federal tenant may configure. The Files.com Shared Responsibility Model — https://www.files.com/compliance/overview-and-responsibilities/shared-responsibility-model — describes SSL configuration, security policies, session timeout, storage location and folder-level region overrides as customer responsibilities. For a Federal tenant account operating in FedRAMP Security Mode, those specific settings are locked by the mode and are no longer customer-configurable. The Shared Responsibility Model otherwise applies in full.
Data residency
Stated separately from the information flows below, because where data travels and where it rests are different questions and an agency needs both answered.
At rest. For a Federal tenant account operating in FedRAMP Security Mode, customer file contents are stored only in United States regions. The mode governs the root folder storage region, from which every subfolder inherits, and permits no folder-level override beneath it while it is enabled. The condition is verified before the mode takes effect: it cannot be enabled while any folder is assigned to its own storage region, and those assignments must be returned to the site default first.
In transit. Data routing is confined to United States regions by the mode, which sets and locks the global acceleration routing option so that a site running the mode cannot use closest-server routing. TLS 1.2 is the minimum for all communication as a platform default.
Files.com operates eight global storage regions; the current list is published at https://www.files.com/docs/settings-and-usage/data-governance/global-regions/available-regions. The seven outside the United States are not within the AWS FedRAMP certification boundary, and they are unreachable — for storage or for routing — by an account operating in FedRAMP Security Mode.
One property is stated for completeness. Complete regional confinement also depends on the systems a tenant connects to Files.com — identity providers, remote storage, notification services and integration platforms — residing in the same region; that part is the customer's responsibility. Files.com's collaborative editing environment uses temporary storage and processing in the United States region regardless of the configured storage region, with files not retained beyond an editing session; for a tenant whose designated region is the United States this moves no data outside that region.
Information flows and security categories
Customer data enters the offering over the public internet through the web application, the desktop and mobile applications, the command line interface, the SDKs, or the API. Transfers terminate at the ingress tier, which carries perimeter firewall and web application firewall responsibilities and enforces a default deny-all rule. File contents are written to Amazon S3 and encrypted at rest; metadata is written to Aurora. For a Federal tenant account operating in FedRAMP Security Mode, the S3 storage holding those file contents is in a United States region. Automations and workflows may move files between the Files.com cloud and customer-designated remote endpoints. Administrative and access control operations are authenticated through the identity layer before reaching any data path.
For Federal tenant accounts every one of these flows is confined to United States regions and requires TLS 1.2 or higher.
Five flows are documented in detail, publicly and without authentication, at https://www.files.com/compliance/platform-security/end-to-end-flow-examples: upload from a Files.com client to native storage; upload from an SFTP client; copy or sync from a remote server such as SharePoint or a remote SFTP endpoint; upload from a client directly to a remote destination; and the buffered upload variant.
Detailed network and data flow diagrams are generated from the Terraform infrastructure definition covering production, staging and system boundaries. They depict the United States region; every other region is deployed from the same Terraform templates with the same routes and firewall rules, so the permitted connections between components are identical in each. They are proprietary and are released to agencies and other necessary parties through the Trust Center rather than published.
Third-party information resources
Files.com uses one third-party information resource: Amazon Web Services. Files.com does not outsource any other key component of the platform and does not own or operate data centers.
AWS holds a FedRAMP Certification for its East/West commercial regions under package AGENCYAMAZONEW, Class C at Moderate, in the Ongoing Certification phase. Every AWS service the offering relies on falls within that boundary.
Federal customer data is confined to United States regions by FedRAMP Security Mode, which is precisely the boundary of that AWS certification. Files.com operates in eight global regions; the seven outside the United States are not within it and are unreachable by a Federal tenant account for as long as that account keeps the mode enabled. Because the platform will not enable the mode while any storage remains outside the United States, the alignment with the AWS boundary is verified before the mode takes effect rather than asserted afterwards.
AWS is a critical vendor in the Files.com Risk Register and is reviewed at least annually. Further detail is published at https://www.files.com/compliance/operations/vendor-management-and-oversight.
Cryptographic modules
| Module | Where used | Validated under the NIST Cryptographic Module Validation Program |
|---|---|---|
| AWS Key Management Service hardware security modules | Encryption at rest for customer file contents, AES-256 | Yes — FIPS 140-3 Security Level 3. Inherited control |
| OpenSSL | Proxy servers terminating HTTP and HTTPS traffic | No — not operated in a validated configuration |
| Bouncy Castle | Transfer protocols: SFTP, FTP, FTPS | No — not operated in a validated configuration |
| Go cryptographic module | Files.com on-premise Agent (customer-installed, outside the offering) | No — not operated in a validated configuration |
| HashiCorp Vault | Internal secrets and credentials; not customer file contents | No — standard rather than FIPS-validated build |
Files.com runs current builds of these modules, which is the correct posture for vulnerability management. Validation under the Cryptographic Module Validation Program attaches to specific module versions and does not extend forward to later releases, so running current builds and running validated builds are at present in tension. Files.com has chosen currency and states the consequence rather than implying validation.
Independent assessment
Certification rests on an approved alternative security framework rather than on a FedRAMP independent assessment, which is permitted at Class A.
- Framework — SOC 2 Type II
- Service auditor — KirkpatrickPrice; Joseph Kirkpatrick, CPA, CISSP, CGEIT, CISA, CRISC, QSA
- Examination period — April 1st, 2025 to March 31st, 2026
- Trust Services Categories examined — Security, Availability, Confidentiality. These are the SOC 2 categories, not the FIPS 199 security categories above.
- Report issued — May 18th, 2026
- Exceptions — none noted for any control tested
- Opinion — unqualified. The report's paragraph (a), on the system description, is unconditional. Paragraphs (b) and (c), on suitability of design and on operating effectiveness, hold if the subservice organization and user entities applied the complementary controls assumed in the design of Files.com's controls (report page 7).
- Next examination period — April 1st, 2026 to March 31st, 2027
- Next report anticipated — May 30th, 2027
No FedRAMP Recognized independent assessment service is engaged, and none is required at Class A. There are therefore no FedRAMP independent assessment results to supply. A competitive selection for a FedRAMP Recognized independent assessment service is underway, launching in August 2026, in anticipation of a higher certification class.
The complete SOC 2 Type II report is supplied unredacted, with its management bridge letter and the audit engagement documentation, through the Trust Center.
Documentation supplied for the offering
| Document | Formats | Access |
|---|---|---|
| Security Decision Record — the implementation, validation and assessment position for every FedRAMP rule and Key Security Indicator applicable to this certification | PDF, JSON | Trust Center |
| Mandatory Key Security Indicator Summary — the detailed narrative for the seven indicators FedRAMP mandates at Class A, with the SOC 2 controls that evidence each | Trust Center | |
| Ongoing Certification Reports — quarterly, with an example report supplied alongside the initial certification package | PDF, JSON | Trust Center |
| External Assessment Materials — the complete SOC 2 Type II report, its management bridge letter, and the audit engagement documentation | Trust Center | |
| Policies and procedures, with register — the internal policies and procedures the certification rests on, with a register identifying each by name, file, summary, word count, version, date of last update and related FedRAMP Practices | PDF, CSV | Trust Center |
| Secure configuration guidance — general guidance for securely configuring Files.com | Web page | Public — https://www.files.com/docs/settings-and-usage/security/configuring-filescom-for-maximum-security |
| FedRAMP Security Mode guidance — the restrictions the mode imposes, how a Site Administrator enables and disables it, and the United States region precondition | Web page | Public — https://www.files.com/docs/settings-and-usage/security/fedramp-security-mode |
| Incident evaluation log and incident reports — the FedRAMP reportability evaluation for real incidents with the reason for each determination, and Initial, Ongoing and Final Incident Reports in the FedRAMP format | PDF, JSON | Trust Center |
| Independent penetration test report — the most recent annual third-party penetration test of the web application, public APIs and SDKs, and supporting infrastructure, scoped to include OWASP Top 10 validation | Trust Center | |
| Network and data flow diagrams — generated from the Terraform infrastructure definition and updated quarterly | Images, as one archive | Trust Center — FedRAMP Supporting Documentation |
| FedRAMP Certification Report — FedRAMP's own report granting the Class A Certification, dated August 26th, 2026: the determination, the Validation Report, the Key Security Indicator scorecard with identified risks, and required actions. Published complete and unmodified, as CDS-CSO-FRC requires | Trust Center |
Secure configuration guidance. Two public pages, and a Federal tenant needs both:
- General secure configuration — https://www.files.com/docs/settings-and-usage/security/configuring-filescom-for-maximum-security
- FedRAMP Security Mode — https://www.files.com/docs/settings-and-usage/security/fedramp-security-mode
The second is the one that describes the setting a Federal tenant's Site Administrator must enable, and the conditions attached to enabling it.
Trust Center
The Trust Center is the complete and definitive source for Files.com FedRAMP Certification Data.
You can see everything held there without an account. The resource catalog is public: every document is listed by category with a description and its own access control, alongside the compliance status, a FedRAMP FAQ and a published update history. Thirty-seven documents sit under FedRAMP Documentation. Seeing what exists requires no request — obtaining a document does.
Obtaining a document — request access. Use the control shown beside an individual document, or the full-access request on the landing page, supplying first name, last name, work email, company name, and reason for access, selecting from existing customer, prospective customer, Federal agency for FedRAMP review, or other. Requests are reviewed by the Files.com security team before access is granted. A party who has previously been granted access can use the Reclaim access option. Requests can be made per document, so if you need several documents you may submit several requests; each is recorded and answered separately.
Programmatic access is a separate step. Website access alone does not enable the Trust Center API, which requires an OAuth token. Request one by email from the same work email address as your approved Trust Center account:
| You are | Token issued within | |
|---|---|---|
| A Federal agency or FedRAMP reviewer | fedramp-notifications+tokenrequest@files.com | 1 business day |
| A commercial customer or prospect | compliance@files.com | 2 business days |
Tokens are issued per user and are not transferable. If your mail system will not send to an address containing +, send to fedramp-notifications@files.com instead; the request is handled identically.
Programmatic access is not required to obtain any artifact — everything is available through the Trust Center website, and the Certification Package Overview JSON above needs no token at all.
Contacts
| Role | Contact |
|---|---|
| Security | fedramp-notifications@files.com — the FedRAMP Security Inbox, routed to the Files.com Security and Compliance team |
| Sales | sales@files.com |
| Accountable official for the FedRAMP Certification Package | Sean E. Smith, HCISPP, CISM, CISSP, Chief Information Security Officer — compliance@files.com, 800-286-8372 |
compliance@files.com and fedramp-notifications@files.com are both monitored mailboxes reaching the Files.com Security and Compliance team. A role address is published rather than a personal one so that communications continue to reach an accountable owner across personnel changes.
Certification Package Overview metadata
- Version — matches the Security Decision Record; the current value is in the Certification Package Overview JSON linked above
- Date and time of last update — as above, in the JSON
- Source of update — generated by the Files.com FedRAMP Class A certification package build pipeline from reviewed source documents; authorized by the Chief Information Security Officer
- Official responsible and accountable for this package — Sean E. Smith, HCISPP, CISM, CISSP, Chief Information Security Officer; compliance@files.com, 800-286-8372
This page and the Certification Package Overview JSON carry the same information and are updated together. If you find a discrepancy between them, the JSON is the machine-readable record and this page is its human-readable equivalent; please report it to fedramp-notifications@files.com.