Compliance and Code of Business
Cellebrite is committed to maintaining the highest standards of compliance and following regulatory measures that ensure that our business operations adhere to industry requirements, laws and regulations.
ISO 27001:2022International standard for managing information security. ISO details requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). Cellebrite undergoes an ISO27001 certification process on an annual basis.
ISO 27017:2015International standard for managing information security for cloud services, supplementing guidance from the ISO 27001 standard with specific guidelines for security controls in a cloud environment. Cellebrite undergoes an ISO27017 certification process on an annual basis.
ISO 14001:2015International standard that outlines the requirements for establishing, implementing, maintaining and continually improving an Environmental Management System (EMS). The standard helps organizations manage their environmental responsibilities in a systematic way that contributes to sustainability, minimizes environmental impact and ensures compliance with relevant laws and regulations.
SOC 2 Type IIThe SOC 2 Type II report presents the controls Cellebrite has established to support operations and compliance. Cellebrite undergoes a SOC 2 Type II certification process on an annual basis. Our SOC 2 Type II report can be shared under a signed NDA. Please contact your account manager to receive the latest version.
SOC 3The SOC 3 report presents a high-level summary of the controls Cellebrite has established to support operations and compliance. Our SOC 3 report is a general-use document that can be shared publicly without an NDA. You can use the link below to download the latest version.
FedRAMP®Cellebrite Government Cloud (CGC) is FedRAMP® High Authorized, the highest impact level in the FedRAMP framework. FedRAMP High applies to cloud systems that handle the federal government’s most sensitive unclassified data—including law enforcement, emergency services, financial, and health information—where a loss of confidentiality, integrity, or availability could have severe or catastrophic consequences.
Authorization requires rigorous security controls, continuous monitoring, and formal approval by a sponsoring federal agency, with CGC’s status publicly listed in the FedRAMP Marketplace , as well as detailed in the Cellebrite Government Cloud Secure Configuration Guide (SCG) and Cellebrite Government Cloud Single Sign-On (SSO) Architecture Guide. Cellebrite Government Cloud achieved FedRAMP High authorization with approval from the U.S. Department of Justice (DOJ), confirming compliance with federal requirements for securely handling sensitive digital evidence.
Code of Business Conduct and EthicsAt Cellebrite, we are dedicated to upholding the highest standards of ethical and lawful conduct. Our Code of Business Conduct and Ethics serves as a comprehensive guide for all employees, ensuring that our actions reflect integrity, respect and accountability. We emphasize the importance of avoiding conflicts of interest, adhering to anti-bribery and anti-corruption laws, fostering a harassment-free workplace and protecting personal data. Additionally, employees are expected to use Cellebrite’s assets responsibly and solely for legitimate business purposes, safeguarding them from misuse, theft or loss.
Our Chief Legal Officer oversees the company’s global compliance program, which receives ongoing support from our in-house legal team. As a global, publicly traded company, our compliance program covers multiple risk areas, including compliance with the Sarbanes-Oxley (SOX) Act. By adhering to these principles, we maintain the trust and confidence of our stakeholders and contribute to a safer world.