Couchdrop is the modern, cloud platform for SFTP, MFT, and EDI. Automate file transfers, integrate your tools, and exchange files with partners — all without writing code.
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
HIPAA
Public claim of compliance with US health-data privacy and security rules. HIPAA has no certification; compliance is self-attested.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Couchdrop discloses on its trust center. Linked entries have their own profile in the Trust Index.
44% chain trust: 11 of 25 disclosed subprocessors are themselves in the Trust Index.
- DigitalOcean
- Amazon Web Services
- HubSpot
- Stripe
- Microsoft Azure
- Trevor
- Wasabi
- Google Cloud Platform
- PayPal
- Xero
- Mailchimp
- Google Analytics
- Zendesk
- Integromat
- Calendly
- Vultr
- Hotjar Data analytics
- MongoDB Atlas Data storage and processing
- Datadog Cloud monitoring
- Intercom Customer support
- fireflies.ai Sales
- Sentry Cloud monitoring
- CloudFlare Cloud monitoring
- Databricks Data storage and processing
- Fivetran Data storage and processing
Named as a subprocessor by
Organizations in the Trust Index that disclose Couchdrop as a subprocessor.
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.