Trust & Security

Your revenue content is your competitive advantage. We protect it that way.

Mediafly is trusted by the world’s largest manufacturing, CPG, life sciences, and technology enterprises to secure the content, value data, and buyer interactions that power their revenue engines. Security isn’t a feature we added — it’s how the platform was built.

Compliance & certifications

SOC 2 Type II — Mediafly’s platform undergoes annual independent SOC 2 Type II audits covering security, availability, and confidentiality. Our most recent report is available to customers and prospects under NDA.

GDPR — Mediafly maintains a GDPR compliance program including a Data Processing Agreement, EU Standard Contractual Clauses, and a published subprocessor list. See our GDPR commitment and subprocessor pages.

Appinium (a Mediafly company) — SOC 2 certified and a Salesforce AppExchange security-reviewed partner.

Infrastructure & data protection

  • Enterprise cloud infrastructure — Hosted on AWS in a multi-VPC architecture, with network security groups that deny traffic by default and an intrusion detection system monitored by our IT team.
  • Encryption — Data is encrypted in transit using TLS 1.2 in transit with AES 256-bit encryption at rest. Any transfer outside the platform requires approved secure, encrypted methods.
  • Vendor oversight — We annually review SOC reports from our critical subprocessors (including AWS, Google Cloud, Google Workspace, Datadog, Gainsight, and 1Password) to verify their security, availability, and recovery controls.
  • Resilience — Environmental protections, data backup, and recovery infrastructure are designed, monitored, and tested to meet availability commitments.

Secure development

  • Code review is enforced by branch protection — no code reaches production without approved review, and administrators cannot bypass the workflow.
  • Changes are promoted through separate development, staging, and production environments with automated CI/CD.
  • Mediafly products undergo Semi-Annual pen testing on all products.
  • Appinium undergoes semi-annual pen testing.

AI you can govern

Mediafly’s AI is built for enterprise governance: we never train models on your customer data, AI actions are seller-approved rather than autonomous, and every AI-assisted step is captured in a full audit trail. Your content stays yours.

People & process

  • Criminal background checks on all new hires.
  • Annual security awareness training, with signed acknowledgment of our IT
  • Security Policy, verified by management every year.
  • Executive Management Team formally certifies internal control responsibilities annually, covering security, operations, and regulatory compliance.
  • Role-based access controls and enterprise SSO.

Responsible disclosure

We value the work of security researchers. If you believe you have found a vulnerability in a Mediafly product, contact security@mediafly.com. We ask researchers to allow us 60 days to remediate before public disclosure, and we commit to acknowledging reports promptly. Reports may be submitted anonymously.

Access documents

Request our SOC 2 report, security questionnaire responses, or a completed CAIQ: send a request to security@mediafly.com. Data Processing Agreement and subprocessor list: mediafly.com/legal/.