Skip to main content

Your assets, protected

PhotoShelter is committed to providing you with data transparency, privacy, and security.

  • Proprietary, owned-and-operated private cloud across three geographically distributed data centers
  • End-to-end access control management to protect both customer data and employees
  • Continuous monitoring and a documented incident response process
  • PhotoShelter is SOC 2 Type 2 audited and our EU data centers are ISO 27001 certified
A person's profile picture with a lock icon and a shield icon indicating security features.

Trusted by thousands of the fastest-growing brands

Leading brands trust PhotoShelter
with 5B+ assets

  • 14P+

    bytes of data stored on our private cloud

  • 100%

    Object durability: No customer file ever lost

  • 11M+

    users served on our servers globally

How PhotoShelter secures your data

How our team delivers on our commitment to ensure your assets remain protected and compliant

  • Solutions Partner

    Complex password authentication for local accounts

    SSO via SAML 2.0 with LDAP, Active Directory, Microsoft Entra ID, ADFS, Okta, Oracle, Shibboleth

    Detailed usage-rights management

    Granular access controls and permissions

    Share content externally via permanent or temporary links

  • Platform

    Proprietary, owned-and-operated private cloud.

    Three primary data centers: New York, California, United Kingdom

    4 copies of every asset across at least 2 geographically distributed data centers

    Encryption at rest: AES-256×2 or better
    Encryption in transit: TLS 1.2 / 1.3

    SHA checksums on every write, verified on every read, scrubbed monthly

    End-of-life drives physically shredded

  • Governance

    SOC 2 Type 2 audited certified

    ISO 27001 compliant (EU data centers)

    GDPR compliant since 2017

    HIPAA Business Associate Agreements available

    CCPA / CPRA, PIPEDA, FERPA
    EU-US Data Privacy Framework compliant

    WCAG 2.2 AA accessibility

    Annual full audit of Disaster Recovery Plan

Our commitment to compliance

PhotoShelter is committed to privacy and provides a high standard of data protection for all customers worldwide.

Our privacy policy
GDPR
EU-US Data Privacy Framework
CCPA / CPRA: California Consumer Privacy Act & California Privacy Rights Act
PIPEDA: Personal Information Protection and Electronic Documents Act
HIPAA: Health Insurance Portability and Accountability Act
FERPA: Family Educational Rights and Privacy Act
WCAG 2.2 AA: Web Content Accessibility Guidelines

Security features

Private cloud infrastructure

Since 2005 we’ve operated our own proprietary, owned-and-operated private cloud across three geographically distributed data centers, with caching and acceleration nodes across the US, EU, and Asia-Pacific.

Access controls

PhotoShelter provides end-to-end access control management to protect both customer data and employees. Access is provided based on the principle of least privilege, with regular access reviews.

A user interface showing a

Threat detection, monitoring, and incident response

Continuous monitoring and a documented incident response process ensure suspicious activity is identified, contained, and resolved. PhotoShelter maintains a 24/7 DevOps monitoring commitment with a public status page.

A digital interface displays a grid of vibrant, colorful images depicting various activities and scenes, with a prominent blue eye icon in the foreground.

SOC 2 Type 2 & ISO 27001

PhotoShelter is SOC 2 Type 2 audited. Our EU data centers are ISO 27001 certified. Audit reports and certificates are maintained for each data center and can be provided under NDA for enterprise procurement reviews.

An illustration of a certificate displaying SOC 2 Type 2 and ISO 27001 compliance, accompanied by a red award icon.