New Disclosure Policy
Cleo Logo

Portal

Start your security review
View & download sensitive information
Ask for information
ControlK

Welcome to Cleo's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this portal to learn about our security posture and request access to our security documentation.

Cleo's role in your supply chain. Cleo is a supplier of software, cloud services, and professional services that support and integrate the movement of B2B data across our customers' ecosystems of partners, marketplaces, and applications. We are not a manufacturer or distributor of physical goods. Because our products form a component of the business operations our customers depend on, we treat the security of what we build, deliver, operate, and support as a shared undertaking: Cleo is accountable for the security of its products and services and of the environments it operates, and our customers are accountable for the configuration, access management, and data handling within their own environments and trading partner relationships. The specific division of responsibility is set out in your agreement with Cleo and in the documentation available through this portal.

Our own supply chain. Cleo maintains a third-party risk management program covering the suppliers and subprocessors we rely on, including due diligence before engagement, annual re-certification, and ongoing monitoring. Our current subprocessors are listed under Legal.

Documents

Featured Documents

REPORTSPentest Report

Self-Assessments

We are working on our security compliance. We can provide completed questionnaires upon request.

Security Grades

We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.

Subprocessors

Portal Updates

2026 Report Availability

Compliance

2026 Report Availability

September 23, 2026

Greetings Cleo Trust Center Readers,

All 2026 certification and compliance audits have been completed, and the documentation is now available. The Cleo ISO27001:2022 certificate, as well as the SSAE-18 suite, SOC 1 Type 2, SOC 2 Type 2, and SOC 3, reports are all now available on the Cleo Trust Center at https://trustcenter.cleo.com.

Please let me know if you have any questions.

Warm Regards,

Edward Brookhouse
Head of Enterprise Risk and Compliance
Cleo
compliance@cleo.com

New Disclosure Policy

General

Subject: New on the Cleo Trust Center: Vulnerability Disclosure Policy

Hello,

Cleo has published its Vulnerability Disclosure Policy (v1.1) to the Cleo Trust Center at https://trustcenter.cleo.com.

The policy establishes a clear, good-faith process for security researchers to report potential vulnerabilities in Cleo-developed products and Cleo-operated services and sets out how Cleo will respond and communicate throughout the process. In summary, it covers:

  • Scope: Cleo Integration Cloud and associated APIs; Cleo Harmony, VLTrader, and LexiCom (supported versions); Cleo Clarify; Cleo Streem; Cleo-operated web properties and customer-facing portals; and Cleo-hosted SaaS environments. Customer-operated installations and third-party systems are out of scope.
  • Safe harbor: Cleo will not pursue legal action against researchers who discover and report vulnerabilities in good faith and in full compliance with the policy.
  • How to report: vulnerability reports go to security@cleo.com, with encrypted submission available on request.
  • Our commitments: acknowledgment within 2 business days, initial triage within 5 business days, status updates at least every 15 business days, and coordinated disclosure with the researcher.
  • Recognition: researchers who consent to attribution are credited in published security advisories and, where applicable, CVE records. Cleo does not currently operate a paid bug bounty program.

What this means for you as a Cleo customer: if you or your security team identify a potential issue in a Cleo product or service, this policy defines how to reach us and what to expect. If you engage third-party researchers or penetration testers against your own Cleo environment, vulnerabilities they discover in Cleo software may be reported to Cleo under this policy, but the policy does not authorize testing of customer-operated installations without your explicit permission.

The policy is owned by the Office of the CISO and is reviewed annually. You can read the full document on the Trust Center.

Questions about the policy can be directed to security@cleo.com. Questions about the Trust Center or your subscription can be directed to compliance@cleo.com.

Thank you for your continued trust in Cleo.

Cleo Security
Office of the CISO
Cleo Communications U.S., LLC

2025 Report Availability

Compliance

Greetings Cleo Trust Center Readers,

All 2025 certification and compliance audits have been completed and the documentation is now available. The Cleo ISO27001:2022 certificate and report, as well as the SSAE-18 suite, SOC 1, SOC 2, and SOC 3, reports are all now available on the Cleo Trust Center at https://trustcenter.cleo.com.

Please let me know if you have any questions.

Warm Regards,

Edward Brookhouse
Head of Enterprise Risk and Compliance
Cleo
compliance@cleo.com

2024 Report Availability

Compliance

Greetings Cleo Trust Center Readers,

All 2024 certification and compliance audits have been completed and the documentation is now available. The Cleo ISO27001:2022 certificate and report, as well as the SSAE-18 suite, SOC 1, SOC 2, and SOC 3, reports are all now available on the Cleo Trust Center at https://trustcenter.cleo.com.

Please let me know if you have any questions.

Warm Regards,

Edward Brookhouse
Head of Enterprise Risk and Compliance
Cleo
compliance@cleo.com

Greetings Cleo Trust Center Readers,

The 2024 Audit season has completed, and our ISO 27001:2022 and SSAE-18 SOC 1 Type 2, SOC 2 Type 2, and SOC 3 reports will be available in a few days.

The certifying auditor body is running behind on delivering our ISO Certificate, but issued a completion notice to fill the gap.

Any customers who would like a copy of the completion letter, please reach out to compliance@cleo.com. All final documents should be ready in a few more days.

Warm Regards,
Edward Brookhouse
Cleo
Head of Enterprise Risk and Compliance
compliance@cleo.com

Q4 2023 Vulnerability Scan Results

Vulnerabilities

Dear Cleo Community,

We are pleased to announce the successful publishing of the Cleo Q4 2023 Vulnerability Scan Results. This comprehensive scan, conducted by a dedicated team of cybersecurity experts, aimed to identify potential vulnerabilities within Cleo Integration Cloud. While we publish this quarterly, I wanted to send a personal note out with our last scan of 2023 thanking all of your for your participation and trust in Cleo.

The Cleo Q4 2023 Vulnerability Scan Results provide valuable insights into the security posture of our software, ensuring that we maintain the highest standards of data protection and integrity. Through rigorous testing and analysis, our team has identified and addressed any potential vulnerabilities, ensuring the continued safety and reliability of our software.

We understand the importance of maintaining a secure environment for our users, and the Cleo Vulnerability Scan Results reflect our commitment to proactive security measures. By regularly conducting vulnerability scans and promptly addressing any identified issues, we strive to provide you with a robust and secure software experience.

We encourage all users to review the Cleo Vulnerability Scan Results, which are now available on our website https://trustcenter.cleo.com. This update aims to foster transparency and trust within our community, allowing you to stay informed about the security measures we undertake to protect your data.

As always, we remain dedicated to continuously improving our software's security capabilities. Your feedback and suggestions are invaluable in this process, so please don't hesitate to reach out to our support team with any questions or concerns.

Thank you for your continued trust in Cleo in 2024. Together, we will ensure a secure and reliable experience.

Edward Brookhouse

Head of Enterprise Risk and Compliance

Cleo

If you need help using this Portal, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo