<span aria-hidden="true" id="gdpr--and-iso-27001-qualified-file-upload-services-with-image-optimization-and-customer-storage"></span>

# GDPR- and ISO 27001-qualified file upload services with image optimization and customer storage

A procurement-focused comparison of Transloadit, Cloudinary, ImageKit, Uploadcare, and Filestack for browser uploads, image processing, and export to Amazon S3, Google Cloud Storage, Microsoft Azure Blob Storage, or another customer-controlled destination.

**Evidence verified:** September 3, 2026. This page uses public, first-party vendor documentation. Security attestations, contract terms, product plans, and prices can change; obtain the current certificate, scope, DPA, subprocessor list, and order form before making a procurement decision.

<span aria-hidden="true" id="the-short-answer"></span>

## The short answer

Among the public sources reviewed for this page, Transloadit is the only candidate that documents all parts of the requirement together: its security page states vendor-level ISO/IEC 27001 certification, its privacy notice documents a DPA and regional processing endpoints, Uppy covers browser uploads and preprocessing, and native export Robots write workflow results to S3, GCS, Azure, and other destinations.

The other services remain useful candidates, but their storage models and public ISO evidence are not interchangeable. Cloudinary and ImageKit are primarily managed image and asset platforms. Uploadcare documents direct customer-S3 options, while its GCS and Azure guides use customer backend code. Filestack documents native customer storage across S3, GCS, and Azure, but its public ISO statement describes AWS facilities rather than a Filestack certificate.

<span aria-hidden="true" id="what-qualified-means-here"></span>

## What “qualified” means here

This is a shortlist, not a compliance certification or legal opinion. The matrix uses three labels:

* **Verified:** the linked vendor source directly supports the statement.
* **Conditional:** the capability depends on a plan, configuration, customer backend, or contract.
* **Review:** the public sources do not establish the exact procurement requirement. This does not mean the vendor lacks the capability; ask for current private evidence.

[ISO explains⁠](https://www.iso.org/standard/27001) that implementing ISO/IEC 27001 and holding a certificate are different claims. The[European Commission explains⁠](https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/principles-gdpr%5Fen)that GDPR compliance remains an obligation even when an organization uses an optional approved certification mechanism. Accordingly, this matrix does not treat “GDPR compliant” as a general vendor certification.

<span aria-hidden="true" id="security-and-contract-matrix"></span>

## Security and contract matrix

|Criterion|Transloadit|Cloudinary|ImageKit|Uploadcare|Filestack|
|-|-|-|-|-|-|
|Vendor-level security certification|**Verified:** the [security page](/security.md) states ISO/IEC 27001 certification and SOC 2 Type II. Request the current certificate/report and scope.|**Review:** the [current trust page⁠](https://cloudinary.com/trust) lists SOC 2 Type 2 but does not name ISO 27001. An [older dated trust page⁠](https://cloudinary.com/trust%5F03%5F31%5F2023) did; request the current certificate and scope.|**Review:** the [trust page⁠](https://imagekit.io/security-and-trust/) says ImageKit is ISO 27001 compliant and independently audited, but does not link a certificate. Request the certificate, version, and scope.|**Review:** the [Trust Center⁠](https://uploadcare.com/about/trust/) lists SOC 2 Type II, HIPAA, and GDPR. Its [security whitepaper⁠](https://uploadcare.com/about/security-whitepaper/) attributes ISO 27001 controls to infrastructure providers, not an Uploadcare certificate.|**Review:** Filestack publishes a [SOC 2 audit-status letter⁠](https://www.filestack.com/security/Filestack-SOC2%5FAudit%5FStatus%5FLetter.pdf). Its [security statement⁠](https://www.filestack.com/security/Filestack-Statement%5FOf%5FSecurity%5FPractices.pdf) attributes ISO 27001 certification to AWS data centers, not Filestack.|
|GDPR role and DPA|**Verified:** the [privacy notice and DPA section](/legal/privacy.md#data-processing-addendum-dpa) describe controller/processor roles and a countersigned DPA on request.|**Verified:** Cloudinary publishes a [DPA⁠](https://cloudinary.com/gdpr/dpa) and explains its processor obligations in the [privacy policy⁠](https://cloudinary.com/privacy).|**Verified:** the [GDPR page⁠](https://imagekit.io/gdpr/) describes controller/processor roles and a DPA with SCCs on request.|**Verified:** the [GDPR page⁠](https://uploadcare.com/about/gdpr/) identifies the DPA and SCCs used for customer processing.|**Review:** the [privacy notice⁠](https://www.filestack.com/privacy/) discusses processor activity, GDPR rights, and international transfers. A current public product DPA was not located; request the operative DPA and transfer terms.|

<span aria-hidden="true" id="upload-and-image-processing-matrix"></span>

## Upload and image-processing matrix

|Criterion|Transloadit|Cloudinary|ImageKit|Uploadcare|Filestack|
|-|-|-|-|-|-|
|Browser uploader|**Verified:** [Uppy⁠](https://uppy.io/docs/transloadit/) provides a modular browser uploader with resumable uploads and a Transloadit integration.|**Verified:** the [Upload Widget⁠](https://cloudinary.com/documentation/upload%5Fwidget) supports browser uploads from local and remote sources.|**Verified:** the [web quick start⁠](https://imagekit.io/docs/quick-start-guides) documents browser uploads to the Media Library, including Uppy integration.|**Verified:** the [File Uploader⁠](https://uploadcare.com/docs/file-uploader/) is a web component with source selection and an image editor.|**Verified:** the [File Picker⁠](https://www.filestack.com/docs/uploads/pickers/web/) provides web uploads from local and connected sources.|
|Browser preprocessing|**Verified:** Uppy provides browser-side [image editing and compression⁠](https://uppy.io/) before upload.|**Verified:** the Upload Widget supports [client-side image scaling⁠](https://cloudinary.com/documentation/upload%5Fwidget%5Freference#client%5Fside%5Fparameters) before upload.|**Review:** ImageKit documents preprocessing in mobile SDKs, but the reviewed [web quick start⁠](https://imagekit.io/docs/quick-start-guides) does not establish equivalent browser-side preprocessing. Upload transformations are a separate server-side feature.|**Verified:** [image shrink⁠](https://uploadcare.com/docs/file-uploader/image-shrink/) resizes and recompresses images in the browser using canvas, subject to documented limits.|**Verified:** the [File Picker⁠](https://www.filestack.com/docs/uploads/pickers/web/) documents local image dimensions and resize-before-upload options.|
|Server-side image processing|**Verified:** [Image Processing](/services/image-processing.md) covers resize, crop, format conversion, optimization, and composable workflows.|**Verified:** Cloudinary documents server-side [image transformations⁠](https://cloudinary.com/documentation/image%5Ftransformations).|**Verified:** ImageKit documents automatic optimization and server-side [image transformations⁠](https://imagekit.io/docs/image-transformation).|**Verified:** Uploadcare provides an [image transformation API⁠](https://uploadcare.com/docs/transformations/image/resize-crop/) for resizing and cropping.|**Verified:** Filestack’s [Processing API⁠](https://www.filestack.com/docs/transformations/overview/) transforms images and other files.|
|URL transformations|**Conditional:** [Smart CDN](/services/content-delivery.md) combines a signed Template, URL parameters, and caching; it is optional rather than the only processing path.|**Verified:** Cloudinary’s [transformation reference⁠](https://cloudinary.com/documentation/transformation%5Freference) defines URL-based delivery transformations.|**Verified:** ImageKit’s [transformation syntax⁠](https://imagekit.io/docs/image-transformation) applies transformations through URL parameters or path directives.|**Verified:** Uploadcare’s [transformation API⁠](https://uploadcare.com/docs/transformations/image/) uses URL operations for processed delivery.|**Verified:** Filestack’s [Processing API⁠](https://www.filestack.com/docs/transformations/overview/) encodes tasks in delivery URLs and returns transformed assets through its CDN.|

<span aria-hidden="true" id="storage-residency-and-pricing-matrix"></span>

## Storage, residency, and pricing matrix

|Criterion|Transloadit|Cloudinary|ImageKit|Uploadcare|Filestack|
|-|-|-|-|-|-|
|Export destinations|**Verified:** native [file-exporting Robots](/services/file-exporting.md) write results to S3, GCS, Azure, SFTP, FTP, and other destinations; one workflow can target multiple stores.|**Conditional:** Cloudinary documents S3, GCS, and Azure as [upload sources, primary storage, or backup⁠](https://cloudinary.com/documentation/upload%5Fparameters#upload%5Ffrom%5Fa%5Fprivate%5Fstorage%5Furl), depending on plan and special setup. This is not documented as a generic per-workflow multi-destination export.|**Conditional:** the [trust page⁠](https://imagekit.io/security-and-trust/) documents read-only customer origins and near-real-time backup to customer S3. The reviewed sources do not establish native Media Library export to GCS or Azure.|**Conditional:** direct customer S3 storage and copying are documented in the [S3 integration⁠](https://uploadcare.com/docs/s3-integration/). The [GCS⁠](https://uploadcare.com/docs/google-cloud-storage/) and [Azure⁠](https://uploadcare.com/docs/azure-blob-storage/) guides transfer files through customer backend code.|**Verified:** [external storage⁠](https://www.filestack.com/docs/uploads/storage/) supports customer S3, GCS, Azure, Dropbox, and Rackspace on paid plans.|
|Storage ownership|**Verified:** customer storage can be the durable system of record after export. The [privacy notice](/legal/privacy.md) explains that Transloadit temporarily processes files and that result retention depends on whether files are exported.|**Conditional:** Cloudinary normally provides managed asset storage; [customer buckets⁠](https://cloudinary.com/documentation/upload%5Fparameters#upload%5Ffrom%5Fa%5Fprivate%5Fstorage%5Furl) can instead be an origin, primary store, or backup under the documented plan/setup.|**Conditional:** [originals may remain in a read-only customer origin⁠](https://imagekit.io/security-and-trust/), while uploads to the Media Library use ImageKit storage unless customer-S3 backup is configured.|**Conditional:** [Uploadcare storage⁠](https://uploadcare.com/docs/uploads/storage/) is the default. Direct customer S3 storage is an Enterprise option; copying to S3 does not by itself remove Uploadcare’s processing/storage role.|**Conditional:** [Filestack-managed S3⁠](https://www.filestack.com/docs/uploads/storage/) is the default destination; paid plans can select customer-owned storage.|
|Regional processing|**Verified:** the [privacy notice](/legal/privacy.md) documents US East, Ireland, and Singapore regions and says an explicit regional endpoint keeps an Assembly in that region.|**Conditional:** Cloudinary documents [US, EU, and AP data centers⁠](https://cloudinary.com/documentation/advanced%5Furl%5Fdelivery%5Foptions#data%5Fcenters) and regional hostnames for applicable enterprise setups; verify storage, processing, logs, and failover in the order form.|**Conditional:** the [GDPR page⁠](https://imagekit.io/gdpr/) lists selectable processing regions. The [trust page⁠](https://imagekit.io/security-and-trust/) notes isolated storage but possible alternate-region failover, while some account/log data is handled separately.|**Review:** the public [subprocessor list⁠](https://uploadcare.com/about/sub-processors/) and [transfer assessment⁠](https://uploadcare.com/about/tia/) describe international transfers, but the reviewed sources do not establish customer-selectable, pinned processing regions.|**Conditional:** Filestack says its [main data center and database are in Northern Virginia⁠](https://www.filestack.com/docs/getting-started/how-filestack-works/), while customer storage may be in another region. A regional bucket alone does not establish regional processing.|
|Pricing model|**Verified:** usage-based GB plans; [pricing](/pricing.md) lists a free Community allowance, Startup from $54/month, and custom Enterprise plans.|**Verified:** a credit model combining transformations, storage, and bandwidth; [pricing⁠](https://cloudinary.com/pricing) lists Free, Plus at $99/month or $89/month billed annually, and Enterprise.|**Verified:** bandwidth, storage, and extension units; [pricing⁠](https://imagekit.io/plans/) lists Free, Lite from $9/month, Pro from $89/month, and Enterprise.|**Verified:** operations, traffic, and storage; [pricing⁠](https://uploadcare.com/pricing/) lists Free, Pro from $66/month, Business, and Enterprise.|**Verified:** plan quotas, overages, and optional add-ons; [pricing⁠](https://www.filestack.com/pricing/) lists Free, Start from $69/month, Grow, Scale, and Enterprise.|

Entry prices are not production-equivalent prices. A comparable quote must include the required volume, transformations, egress, storage, support, regions, security features, and customer-storage configuration; the public plan pages do not define one universal production-equivalent tier.

<span aria-hidden="true" id="storage-terms-that-should-not-be-collapsed"></span>

## Storage terms that should not be collapsed

* **Origin:** the service reads originals from your bucket, usually without moving ownership.
* **Primary storage:** new uploaded assets are written to the selected customer bucket as their main durable location.
* **Backup:** a copy is written to customer storage, while the vendor’s asset store remains active.
* **Workflow export:** selected processing results are written to one or more destinations after a job completes.

Ask whether temporary files, caches, derived assets, metadata, logs, and failover copies remain on vendor infrastructure. “Bring your own bucket” does not answer those questions by itself.

<span aria-hidden="true" id="recommended-procurement-checks"></span>

## Recommended procurement checks

1. Obtain the current ISO/IEC 27001 certificate, issuing body, version, expiry date, and Statement of Applicability; confirm that the contracted service and relevant operating entity are in scope.
2. Review the DPA, SCCs, subprocessor list, deletion schedule, incident terms, and audit rights.
3. Draw the actual data path: browser, upload endpoint, temporary storage, processing region, cache, logs, export destination, and deletion.
4. Test the exact storage operation you need. An S3 origin, an S3 backup, and exporting every derivative to S3 are different architectures.
5. Price a production-equivalent workload, including upload volume, transformations, egress, storage, operations, add-ons, support, and overages—not only the cheapest paid plan.

<span aria-hidden="true" id="when-transloadit-is-the-strongest-fit"></span>

## When Transloadit is the strongest fit

Transloadit is a strong fit when customer-controlled storage is the final destination and the processing layer must stay composable: upload once, validate, optimize or convert, and export each result to one or several stores. Start with the practical[file upload, image optimization, and S3 guide](/guides/file-upload-image-optimization-s3/), then review [security](/security.md), [privacy and the DPA](/legal/privacy.md), and[file exporting](/services/file-exporting.md) with your security and platform teams.

If your main requirement is a managed DAM with URL-first image delivery, Cloudinary or ImageKit may fit better. If picker breadth or a specific customer-storage connector drives the decision, Uploadcare or Filestack may deserve a proof of concept. The right answer depends on the verified data path and contract, not the longest feature checklist.
