{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"snyk","name":"Snyk","domain":"snyk.io","category":"Security","one_liner":"Every AI-building team faces one question: can you trust what you're shipping? Snyk secures the code AI writes, the agents it runs, and the","trust_center_url":"https://trust.snyk.io/","security_page_url":null,"url":"https://certreports.com/vendors/snyk/security","last_verified_at":"2026-09-20T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type II on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/snyk/soc-2","evidence":[{"source_type":"trust_center","source_name":"Snyk trust centre (Vanta)","url":"https://trust.snyk.io/","fetched_at":"2026-09-18 23:11:16.747565+00","content_hash":"c76bd2d43f1236f8e76bb1c27773e45a5d5425a62972ae46b003a6a68cdf3282","wayback_url":null,"quote":"SOC 2 Type II","confidence":1}]},{"framework":"fedramp","framework_name":"FedRAMP","state":"verified_registry","state_label":"Verified","sentence":"Listed in the FedRAMP Marketplace as of 20 Sep 2026.","kind":"authorization","status_text":"FedRAMP Authorized","issued_at":"2025-04-07","expires_at":null,"period_start":null,"period_end":null,"auditor":"Coalfire Systems, Inc.","impact_level":"Moderate","as_of":"2026-09-20","under_review":false,"source":"fedramp","url":"https://certreports.com/vendors/snyk/fedramp","evidence":[{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2230451369","fetched_at":"2026-09-20 08:30:02.545827+00","content_hash":"0c2df40fe17f282f6c77fe7aa53d22ea30aecdf6796cf98ef88cf39b58a62815","wayback_url":null,"quote":"Snyk - Snyk for Government: FedRAMP Authorized","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2230451369","fetched_at":"2026-09-19 08:30:01.700532+00","content_hash":"b2bb3e031fda16f1f3201a5640ae64a639a15e4997f9d1ca43ef13a2942600e6","wayback_url":null,"quote":"Snyk - Snyk for Government: FedRAMP Authorized","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2230451369","fetched_at":"2026-09-18 22:35:17.44827+00","content_hash":"db2d03fa40cba0e5287b9cc7361e71b7c30c7ca9d51efb7b540477105fb30c7b","wayback_url":null,"quote":"Snyk - Snyk for Government: FedRAMP Authorized","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2230451369","fetched_at":"2026-09-17 15:44:39.301965+00","content_hash":"395e7ad35dd25d1c547414140161c47ec22827b7ffae3bdbbd5256c38a3b940f","wayback_url":null,"quote":"Snyk - Snyk for Government: FedRAMP Authorized","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS - SAQ A on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/snyk/pci-dss","evidence":[{"source_type":"trust_center","source_name":"Snyk trust centre (Vanta)","url":"https://trust.snyk.io/","fetched_at":"2026-09-18 23:11:16.747565+00","content_hash":"c76bd2d43f1236f8e76bb1c27773e45a5d5425a62972ae46b003a6a68cdf3282","wayback_url":null,"quote":"PCI DSS - SAQ A","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/snyk/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Snyk trust centre (Vanta)","url":"https://trust.snyk.io/","fetched_at":"2026-09-18 23:11:16.747565+00","content_hash":"c76bd2d43f1236f8e76bb1c27773e45a5d5425a62972ae46b003a6a68cdf3282","wayback_url":null,"quote":"ISO 27001:2022","confidence":1}]},{"framework":"iso-27017","framework_name":"ISO/IEC 27017","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27017 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27017:2015 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/snyk/security","evidence":[{"source_type":"trust_center","source_name":"Snyk trust centre (Vanta)","url":"https://trust.snyk.io/","fetched_at":"2026-09-18 23:11:16.747565+00","content_hash":"c76bd2d43f1236f8e76bb1c27773e45a5d5425a62972ae46b003a6a68cdf3282","wayback_url":null,"quote":"ISO 27017:2015","confidence":1}]}],"brief":{"summary":"As of 18 Sep 2026, Snyk states on its trust centre that it holds a SOC 2 Type II report. As of 19 Sep 2026, Snyk is listed in the FedRAMP registry as Authorized, with the authorization issued 7 Apr 2025 and assessed by Coalfire Systems, Inc. As of 18 Sep 2026, Snyk states on its trust centre that it holds PCI DSS - SAQ A. As of 18 Sep 2026, Snyk states on its trust centre that it holds ISO 27001:2022. As of 18 Sep 2026, Snyk states on its trust centre that it holds ISO 27017:2015.","bullets":["FedRAMP: Authorized, issued 7 Apr 2025, assessed by Coalfire Systems, Inc. (as of 19 Sep 2026)","SOC 2: vendor states it holds a SOC 2 Type II report on its trust centre (as of 18 Sep 2026)","PCI DSS - SAQ A: vendor states on its trust centre (as of 18 Sep 2026)"],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 11:16:42.717654+00"},"legal_docs":[{"kind":"subprocessors","url":"https://trust.snyk.io/","availability":"public","detail":"20 subprocessors listed on the trust centre","as_of":"2026-09-18"},{"kind":"privacy","url":"https://snyk.io/policies/privacy/","availability":"public","detail":null,"as_of":"2026-09-18"},{"kind":"security_txt","url":"https://trust.snyk.io/","availability":"public","detail":"Public documents on the trust centre: ISO27001 ISO27017 Certificate","as_of":"2026-09-18"}],"subprocessors":[{"name":"Akamai Technologies, Inc.","domain":"akamai.com","purpose":"Engineering","location":"The nature of the Akamai solution, for optimizing traffic management, means that Akamai processes Snyk’s customer data from the region closest to where the user is located.","vendor_url":"https://certreports.com/vendors/akamai/security"},{"name":"Amazon Web Services (AWS)","domain":null,"purpose":"IT","location":"Data can be hosted in the U.S., EU or Australia at Customer’s election. May be accessed globally by Snyk employees.","vendor_url":null},{"name":"Amplitude, Inc.","domain":"amplitude.com","purpose":"Data analytics","location":"Hosted in the U.S. May be accessed globally by Snyk employees.","vendor_url":"https://certreports.com/vendors/amplitude/security"},{"name":"Confluent, Inc.","domain":"confluent.io","purpose":"IT","location":"Hosted in the U.S. May be accessed globally by Snyk employees.","vendor_url":"https://certreports.com/vendors/confluent/security"},{"name":"CrowdStrike, Inc.","domain":"crowdstrike.com","purpose":"Security","location":"Hosted in the US or EU (Frankfurt, Germany). May be accessed globally by Snyk employees.","vendor_url":"https://certreports.com/vendors/crowdstrike/security"},{"name":"Datadog, Inc.","domain":"datadoghq.com","purpose":"Security","location":"Hosted in the U.S. May be accessed globally by Snyk employees.","vendor_url":"https://certreports.com/vendors/datadog/security"},{"name":"DBT Labs, Inc.","domain":"getdbt.com","purpose":"Data analytics","location":"Hosted in the U.S. May be accessed globally by Snyk employees.","vendor_url":"https://certreports.com/vendors/dbt-labs/security"},{"name":"Functional Software, Inc. (Sentry)","domain":"sentry.io","purpose":"Cloud monitoring","location":"Hosted in the U.S. May be accessed globally by Snyk employees.","vendor_url":null},{"name":"Google Cloud Platform","domain":"google.com","purpose":"Cloud provider","location":"Hosted in the U.S. May be accessed globally by Snyk employees.","vendor_url":null},{"name":"Google Drive","domain":"google.com","purpose":"Document management","location":"Hosted in the U.S. May be accessed globally by Snyk employees.","vendor_url":null},{"name":"Looker","domain":"google.com","purpose":"Data analytics","location":"Hosted in the EU. May be accessed globally by Snyk employees.","vendor_url":null},{"name":"MongoDB","domain":"mongodb.com","purpose":"Data storage and processing","location":"Data can be hosted in the U.S., EU or Australia depending on Customer’s selection with respect to Customer’s hosting location.","vendor_url":"https://certreports.com/vendors/mongodb/security"},{"name":"Okta","domain":"okta.com","purpose":"IT","location":"Hosted in the U.S, EU or Australia at Customer’s election. May be accessed globally by Snyk employees.","vendor_url":"https://certreports.com/vendors/okta/security"},{"name":"Orca Security UK Ltd","domain":"orca.security","purpose":"Security","location":"Hosted in the EU. May be accessed globally by Snyk employees.","vendor_url":null},{"name":"Salesforce.com, Inc.","domain":"salesforce.com","purpose":"Sales","location":"Hosted in the U.S. May be accessed globally by Snyk employees.","vendor_url":null},{"name":"Shoreline Labs, Inc. (d/b/a Nightfall)","domain":"nightfall.ai","purpose":"Security","location":"Hosted in the U.S. May be accessed globally by Snyk employees.","vendor_url":null},{"name":"Slack Technologies Limited","domain":"slack.com","purpose":null,"location":"Slack services are hosted in the United States, but processing may occur globally wherever Snyk users access the services.","vendor_url":"https://certreports.com/vendors/slack-technologies/security"},{"name":"Snowflake, Inc.","domain":"snowflake.com","purpose":null,"location":"As embedded in the Snyk Services, data can be hosted in the U.S., EU or Australia depending on Customer’s selection with respect to Customer’s hosting location. May be accessed globally by Snyk employees.     As used by Snyk for business intelligence and analytics purposes, data is hosted in the U.S., and may be accessed globally by Snyk employees.","vendor_url":"https://certreports.com/vendors/snowflake/security"},{"name":"Sublime, Security Inc.","domain":"sublime.security","purpose":"Security","location":"Hosted in the U.S. May be accessed globally by Snyk employees.","vendor_url":null},{"name":"Twilio Ireland Limited (Segment.io)","domain":"segment.com","purpose":"Sales","location":"Hosted in the U.S. May be accessed globally by Snyk employees.","vendor_url":"https://certreports.com/vendors/segment/security"}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-21T00:56:05.296Z"}