Skip to main content
Auth0 logo

Auth0

ISO/IEC 27001 evidence

Secure users, AI agents, and more with Auth0, an easy-to-implement, scalable, and adaptable authentication and authorization

auth0.comIdentity and accessLast verified 21 Sep 2026
ISO/IEC 27001 mark, CertReports state Vendor-stated as of 21 Sep 2026Vendor-stated

Auth0 and ISO/IEC 27001

Auth0 states it holds an ISO/IEC 27001 certificate. CertReports captured this on 21 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.

Evidence

Vendor-statedVendor states ISO/IEC 27001:2022 on its trust centre
as of 21 Sep 2026 · confidence 80%
SourceCapturedQuoteLinks
Auth0 trust centre (Drata)
Vendor trust centre · HTTP 200
21 Sep 2026ISO/IEC 27001:2022
Live page Snapshotsha256 8981020655
Vendor-statedVendor states ISO/IEC 27017:2015 on its trust centre
as of 21 Sep 2026 · confidence 80%
SourceCapturedQuoteLinks
Auth0 trust centre (Drata)
Vendor trust centre · HTTP 200
21 Sep 2026ISO/IEC 27017:2015
Live page Snapshotsha256 8981020655
Vendor-statedVendor states ISO/IEC 27018:2019 on its trust centre
as of 21 Sep 2026 · confidence 80%
SourceCapturedQuoteLinks
Auth0 trust centre (Drata)
Vendor trust centre · HTTP 200
21 Sep 2026ISO/IEC 27018:2019
Live page Snapshotsha256 8981020655

What is not public

  • The certificate expiry and scope statement are not in a public source yet; the state will move to Verified when a certification body register or the IAF CertSearch API confirms them.
What ISO/IEC 27001 means, and what it does not

Certified by an accredited certification body on a three-year cycle with annual surveillance. Scope statements matter and expiry drives the state. Any certificate still citing ISO/IEC 27001:2013 is treated as lapsed because the IAF transition deadline of 31 October 2025 has passed.

Read the ISO/IEC 27001 guide and browse all vendors with evidence

Questions buyers ask

Is Auth0 ISO 27001 certified?

Auth0 states it holds an ISO/IEC 27001 certificate as of 21 Sep 2026. Scope statements matter; check the certificate scope covers the product you are buying.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 22 Sep 2026First indexed by CertReports16 evidence rows across 16 frameworks entered the index.

Alternatives with ISO 27001 evidence

Similar vendors (shared product tags or the Identity and access category) whose ISO 27001 row is verified or vendor-stated, ranked by similarity.

All articles