{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"beyondtrust","name":"BeyondTrust","domain":"beyondtrust.com","category":"Identity and access","one_liner":"BeyondTrust Corporation is an American company that develops privileged access management (PAM) and vulnerability management software","trust_center_url":"https://trustportal.beyondtrust.com/","security_page_url":null,"url":"https://certreports.com/vendors/beyondtrust/security","last_verified_at":"2026-09-19T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/beyondtrust/soc-2","evidence":[{"source_type":"trust_center","source_name":"BeyondTrust trust centre (Drata)","url":"https://trustportal.beyondtrust.com/","fetched_at":"2026-09-18 22:40:07.070158+00","content_hash":"2f39c28e2b75e01d181ac7fa1ff9eb01f8b19be3d50b60942709796bf078879a","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/beyondtrust/gdpr","evidence":[{"source_type":"trust_center","source_name":"BeyondTrust trust centre (Drata)","url":"https://trustportal.beyondtrust.com/","fetched_at":"2026-09-18 22:40:07.070158+00","content_hash":"2f39c28e2b75e01d181ac7fa1ff9eb01f8b19be3d50b60942709796bf078879a","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"fedramp","framework_name":"FedRAMP","state":"verified_registry","state_label":"Verified","sentence":"Listed in the FedRAMP Marketplace as of 19 Sep 2026.","kind":"authorization","status_text":"FedRAMP Authorized","issued_at":"2024-04-17","expires_at":null,"period_start":null,"period_end":null,"auditor":"A-LIGN Compliance and Security, Inc. dba A-LIGN","impact_level":"Moderate","as_of":"2026-09-19","under_review":false,"source":"fedramp","url":"https://certreports.com/vendors/beyondtrust/fedramp","evidence":[{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2231070252","fetched_at":"2026-09-19 08:30:01.700532+00","content_hash":"b2bb3e031fda16f1f3201a5640ae64a639a15e4997f9d1ca43ef13a2942600e6","wayback_url":null,"quote":"BeyondTrust - BeyondTrust Identity Security For Government: FedRAMP Authorized","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2231070252","fetched_at":"2026-09-18 22:35:17.44827+00","content_hash":"db2d03fa40cba0e5287b9cc7361e71b7c30c7ca9d51efb7b540477105fb30c7b","wayback_url":null,"quote":"BeyondTrust - BeyondTrust Identity Security For Government: FedRAMP Authorized","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2231070252","fetched_at":"2026-09-17 15:44:39.301965+00","content_hash":"395e7ad35dd25d1c547414140161c47ec22827b7ffae3bdbbd5256c38a3b940f","wayback_url":null,"quote":"BeyondTrust - BeyondTrust Identity Security For Government: FedRAMP Authorized","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/beyondtrust/pci-dss","evidence":[{"source_type":"trust_center","source_name":"BeyondTrust trust centre (Drata)","url":"https://trustportal.beyondtrust.com/","fetched_at":"2026-09-18 22:40:07.070158+00","content_hash":"2f39c28e2b75e01d181ac7fa1ff9eb01f8b19be3d50b60942709796bf078879a","wayback_url":null,"quote":"PCI DSS","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/beyondtrust/iso-27001","evidence":[{"source_type":"trust_center","source_name":"BeyondTrust trust centre (Drata)","url":"https://trustportal.beyondtrust.com/","fetched_at":"2026-09-18 22:40:07.070158+00","content_hash":"2f39c28e2b75e01d181ac7fa1ff9eb01f8b19be3d50b60942709796bf078879a","wayback_url":null,"quote":"ISO/IEC 27001:2022","confidence":1}]},{"framework":"iso-27701","framework_name":"ISO/IEC 27701","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27701 certificate on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27701 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/beyondtrust/iso-27701","evidence":[{"source_type":"trust_center","source_name":"BeyondTrust trust centre (Drata)","url":"https://trustportal.beyondtrust.com/","fetched_at":"2026-09-18 22:40:07.070158+00","content_hash":"2f39c28e2b75e01d181ac7fa1ff9eb01f8b19be3d50b60942709796bf078879a","wayback_url":null,"quote":"ISO/IEC 27701","confidence":1}]},{"framework":"iso-27017","framework_name":"ISO/IEC 27017","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27017 certificate on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27017:2015 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/beyondtrust/security","evidence":[{"source_type":"trust_center","source_name":"BeyondTrust trust centre (Drata)","url":"https://trustportal.beyondtrust.com/","fetched_at":"2026-09-18 22:40:07.070158+00","content_hash":"2f39c28e2b75e01d181ac7fa1ff9eb01f8b19be3d50b60942709796bf078879a","wayback_url":null,"quote":"ISO/IEC 27017:2015","confidence":1}]},{"framework":"iso-27018","framework_name":"ISO/IEC 27018","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27018 certificate on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27018:2019 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/beyondtrust/security","evidence":[{"source_type":"trust_center","source_name":"BeyondTrust trust centre (Drata)","url":"https://trustportal.beyondtrust.com/","fetched_at":"2026-09-18 22:40:07.070158+00","content_hash":"2f39c28e2b75e01d181ac7fa1ff9eb01f8b19be3d50b60942709796bf078879a","wayback_url":null,"quote":"ISO/IEC 27018:2019","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: EU-US Certification, SW-US Certification, UK Extension Certification","issued_at":"2016-11-28","expires_at":"2027-03-13","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/beyondtrust/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/6131","fetched_at":"2026-09-17 15:49:22.697025+00","content_hash":"0a734af37377e4e48b99060316ac474c396b1af8606143122be7fce6c83a7b51","wayback_url":null,"quote":"BeyondTrust Corporation: Active: EU-US Certification, SW-US Certification, UK Extension Certification","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/beyondtrust/security","evidence":[{"source_type":"trust_center","source_name":"BeyondTrust trust centre (Drata)","url":"https://trustportal.beyondtrust.com/","fetched_at":"2026-09-18 22:40:07.070158+00","content_hash":"2f39c28e2b75e01d181ac7fa1ff9eb01f8b19be3d50b60942709796bf078879a","wayback_url":null,"quote":"CCPA","confidence":1}]},{"framework":"txramp","framework_name":"TX-RAMP","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an TX-RAMP certification on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states TX-RAMP on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/beyondtrust/security","evidence":[{"source_type":"trust_center","source_name":"BeyondTrust trust centre (Drata)","url":"https://trustportal.beyondtrust.com/","fetched_at":"2026-09-18 22:40:07.070158+00","content_hash":"2f39c28e2b75e01d181ac7fa1ff9eb01f8b19be3d50b60942709796bf078879a","wayback_url":null,"quote":"TX-RAMP","confidence":1}]},{"framework":"irap","framework_name":"IRAP","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an IRAP assessment on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states IRAP on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/beyondtrust/security","evidence":[{"source_type":"trust_center","source_name":"BeyondTrust trust centre (Drata)","url":"https://trustportal.beyondtrust.com/","fetched_at":"2026-09-18 22:40:07.070158+00","content_hash":"2f39c28e2b75e01d181ac7fa1ff9eb01f8b19be3d50b60942709796bf078879a","wayback_url":null,"quote":"IRAP","confidence":1}]}],"brief":{"summary":"BeyondTrust is listed in the FedRAMP registry as Authorized, dated 17 Apr 2024 and audited by A-LIGN Compliance and Security, Inc., as of 19 Sep 2026. BeyondTrust is listed in the EU-US Data Privacy Framework registry as active (EU-US, SW-US, UK Extension Certifications), originally issued 28 Nov 2016 and expiring 13 Mar 2027, as of 17 Sep 2026. BeyondTrust states on its trust centre that it holds SOC 2, GDPR, PCI DSS, and IRAP, as of 18 Sep 2026. BeyondTrust states on its trust centre that it holds ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27017, and ISO/IEC 27018, as of 18 Sep 2026. BeyondTrust also states on its trust centre that it holds CCPA / CPRA and TX-RAMP, as of 18 Sep 2026.","bullets":["FedRAMP: listed as Authorized, effective 17 Apr 2024, audited by A-LIGN Compliance and Security, Inc., as of 19 Sep 2026.","EU-US Data Privacy Framework: listed as active (EU-US, SW-US, UK Extension), issued 28 Nov 2016, expires 13 Mar 2027, as of 17 Sep 2026.","SOC 2, GDPR, PCI DSS, ISO/IEC 27001/27701/27017/27018, CCPA / CPRA, TX-RAMP, and IRAP are vendor-stated on its trust centre, as of 18 Sep 2026; no independent registry listing found for these."],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 11:35:21.597477+00"},"legal_docs":[{"kind":"subprocessors","url":"https://trustportal.beyondtrust.com/","availability":"public","detail":"2 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Gainsight-Salesforce","domain":null,"purpose":null,"location":null,"vendor_url":null},{"name":"Incidents For details regarding the Salesforce","domain":null,"purpose":null,"location":null,"vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-20T06:33:01.613Z"}