{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"auth0","name":"Auth0","domain":"auth0.com","category":"Identity and access","one_liner":"Secure users, AI agents, and more with Auth0, an easy-to-implement, scalable, and adaptable authentication and authorization","trust_center_url":"https://security.okta.com/","security_page_url":null,"url":"https://certreports.com/vendors/auth0/security","last_verified_at":"2026-09-21T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"hipaa","framework_name":"HIPAA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states that it will sign a business associate agreement on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/hipaa","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"HIPAA","confidence":1}]},{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/soc-2","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/gdpr","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"fedramp","framework_name":"FedRAMP","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a FedRAMP authorization on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states FedRAMP High on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/fedramp","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"FedRAMP High","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/pci-dss","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"PCI DSS","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"ISO/IEC 27001:2022","confidence":1}]},{"framework":"csa-star","framework_name":"CSA STAR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a CSA STAR Level 1 self-assessment on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states CSA STAR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/csa-star","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"CSA STAR","confidence":1}]},{"framework":"soc-1","framework_name":"SOC 1","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 1 Type II report on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states SOC 1 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/security","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"SOC 1","confidence":1}]},{"framework":"soc-3","framework_name":"SOC 3","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a public SOC 3 report on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states SOC 3 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/security","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"SOC 3","confidence":1}]},{"framework":"iso-27017","framework_name":"ISO/IEC 27017","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27017 certificate on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27017:2015 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/security","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"ISO/IEC 27017:2015","confidence":1}]},{"framework":"iso-27018","framework_name":"ISO/IEC 27018","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27018 certificate on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27018:2019 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/security","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"ISO/IEC 27018:2019","confidence":1}]},{"framework":"govramp","framework_name":"GovRAMP","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an GovRAMP authorization on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states GovRAMP on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/security","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"GovRAMP","confidence":1}]},{"framework":"tisax","framework_name":"TISAX","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an TISAX assessment label on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states TISAX on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/security","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"TISAX","confidence":1}]},{"framework":"c5","framework_name":"BSI C5","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an BSI C5 attestation on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states C5 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/security","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"C5","confidence":1}]},{"framework":"ens","framework_name":"ENS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ENS certificate on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states ENS on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/security","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"ENS","confidence":1}]},{"framework":"irap","framework_name":"IRAP","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an IRAP assessment on its trust centre (Drata) as of 21 Sep 2026.","kind":null,"status_text":"Vendor states IRAP on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"drata","url":"https://certreports.com/vendors/auth0/security","evidence":[{"source_type":"trust_center","source_name":"Auth0 trust centre (Drata)","url":"https://security.okta.com/","fetched_at":"2026-09-21 22:19:48.537609+00","content_hash":"8981020655832f908023a9d89174d34c93d0a5c9a23a646ea75dcb82219f67a3","wayback_url":null,"quote":"IRAP","confidence":1}]}],"brief":{"summary":"Auth0 displays a HIPAA badge on its trust centre as of 21 Sep 2026, though the underlying claim's BAA availability is not captured in the evidence. Auth0 states SOC 2 on its trust centre as of 21 Sep 2026. Auth0 states FedRAMP High on its trust centre as of 21 Sep 2026. As of 21 Sep 2026, Auth0 also states GDPR, PCI DSS, ISO/IEC 27001:2022, CSA STAR, SOC 1 and SOC 3 on its trust centre. As of 21 Sep 2026, Auth0 further states ISO/IEC 27017:2015, ISO/IEC 27018:2019, GovRAMP, TISAX, BSI C5, ENS and IRAP on its trust centre.","bullets":["SOC 2: vendor-stated on trust centre, no report evidence captured (as of 21 Sep 2026).","HIPAA: vendor displays a badge; BAA availability not confirmed (as of 21 Sep 2026).","FedRAMP High: vendor-stated claim, no registry listing found in the evidence (as of 21 Sep 2026)."],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-22 10:07:27.028391+00"},"legal_docs":[{"kind":"ai_policy","url":"https://security.okta.com/","availability":"on_request","detail":"Listed on the trust centre as \"AI Governance\"","as_of":"2026-09-21"},{"kind":"subprocessors","url":"https://security.okta.com/","availability":"on_request","detail":"Listed on the trust centre as \"Sub-processors\"","as_of":"2026-09-21"},{"kind":"dpa","url":"https://security.okta.com/","availability":"on_request","detail":"Listed on the trust centre as \"DPA\"","as_of":"2026-09-21"}],"documents":[{"type":"ai_policy","title":"AI Governance","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"business_continuity","title":"Business Continuity and Disaster Recovery","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"dpa","title":"DPA","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"fedramp_package","title":"FedRAMP High","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"fedramp_package","title":"FedRAMP Moderate","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"insurance","title":"Certificate of Insurance","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"iso_certificate","title":"ISO 27001 / 27017 / 27018","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"iso_certificate","title":"ISO/IEC 27001:2022","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"iso_certificate","title":"ISO/IEC 27001:2022 Compliance with Okta","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"iso_certificate","title":"ISO/IEC 27017:2015","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"iso_certificate","title":"ISO/IEC 27018:2019","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"pci_aoc","title":"PCI DSS","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"pci_aoc","title":"PCI DSS Compliance with Okta","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"pci_aoc","title":"PCI DSS v4.0.0","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"pentest_report","title":"Pentest Reports","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"questionnaire","title":"CAIQ","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"questionnaire","title":"HECVAT","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"security_policy","title":"Access Control","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"security_policy","title":"Access Control Policy","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"soc1_report","title":"SOC 1","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"soc1_report","title":"SOC 1 Report","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"soc2_report","title":"SOC 2","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"soc2_report","title":"SOC 2 Report","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"soc3_report","title":"SOC 3","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"soc3_report","title":"SOC 3 Report","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"subprocessor_list","title":"Sub-processors","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"},{"type":"vpat","title":"VPAT","availability":"on_request","source_url":"https://security.okta.com/","last_seen":"2026-09-21"}],"statements":[],"security_profile":{"iso42001":null,"trains_on_customer_data":null,"data_residency_regions":[],"pen_test_cadence":"report available","as_of":"2026-09-21"},"regulations_url":"https://certreports.com/api/v1/vendors/auth0/regulations/{regulation}","subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-22T10:07:41.093Z"}