Auth0
Security and trust center evidence
Secure users, AI agents, and more with Auth0, an easy-to-implement, scalable, and adaptable authentication and authorization
Summary
Auth0 has 16 vendor-stated rows in the CertReports index, last verified 21 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 21 Sep 2026, CertReports holds 16 vendor-stated rows for Auth0, drawn from its trust centre (Drata). Auth0 states on its trust centre that it holds that it will sign a business associate agreement, a SOC 2 Type II report, a data processing agreement, a FedRAMP authorization, a PCI DSS attestation of compliance, an ISO/IEC 27001 certificate, a CSA STAR Level 1 self-assessment, a SOC 1 Type II report, a public SOC 3 report, an ISO/IEC 27017 certificate, an ISO/IEC 27018 certificate, an GovRAMP authorization, an TISAX assessment label, an BSI C5 attestation, an ENS certificate and an IRAP assessment, captured 21 Sep 2026; these are vendor statements, not independent confirmations.
- HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured), vendor-stated as of 21 Sep 2026
- SOC 2: Vendor states SOC 2 on its trust centre, vendor-stated as of 21 Sep 2026
Facts only, each dated; nothing here is inferred, scored or advised.
Among identity and access vendors
0verified rows
Category median 1, across 74 indexed identity and access vendors. Auth0 has no registry-verified row yet, like 41 percent of them; its evidence is vendor-stated or reported.
Compare with similar vendors
Pick your own comparisonCompliance grid
- HIPAAVendor-stated
Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)
as of 21 Sep 20261 source
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 21 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 21 Sep 20261 source - FedRAMPVendor-stated
Vendor states FedRAMP High on its trust centre
as of 21 Sep 20261 source
PCI DSSVendor-statedVendor states PCI DSS on its trust centre
as of 21 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001:2022 on its trust centre
as of 21 Sep 20261 source- CSA STARVendor-stated
Vendor states CSA STAR on its trust centre
as of 21 Sep 20261 source
SOC 1Vendor-statedVendor states SOC 1 on its trust centre
as of 21 Sep 20261 source
SOC 3Vendor-statedVendor states SOC 3 on its trust centre
as of 21 Sep 20261 source
ISO/IEC 27017Vendor-statedVendor states ISO/IEC 27017:2015 on its trust centre
as of 21 Sep 20261 source
ISO/IEC 27018Vendor-statedVendor states ISO/IEC 27018:2019 on its trust centre
as of 21 Sep 20261 source
GovRAMPVendor-statedVendor states GovRAMP on its trust centre
as of 21 Sep 20261 source
TISAXVendor-statedVendor states TISAX on its trust centre
as of 21 Sep 20261 source
BSI C5Vendor-statedVendor states C5 on its trust centre
as of 21 Sep 20261 source
ENSVendor-statedVendor states ENS on its trust centre
as of 21 Sep 20261 source
IRAPVendor-statedVendor states IRAP on its trust centre
as of 21 Sep 20261 source
No public evidence yet for Cyber Essentials, ISO 27701, ISO 42001. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Legal artefacts
Subprocessors
No subprocessor list captured yet.
Security profile
- Pen test cadence
- report available
Displayed as a security profile from public statements, not as attestations, as of 21 Sep 2026.
Change history
- 22 Sep 2026First indexed by CertReports16 evidence rows across 16 frameworks entered the index.
Similar vendors with evidence
Related by product tags and the Identity and access category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.
Delinea
Identity and access
Try Delinea's AI-driven identity security, authorization and PAM solutions to secure privileged access across your organization in real
Valimail
Identity and access
Protect your business from phishing and spoofing 4x faster with Valimail’s automated DMARC, DKIM, and SPF email authentication
empowerid
Identity and access
Govern every identity and control every consequential action across people, machines, and AI agents on the EmpowerID Identity
SecureW2
Identity and access
SecureW2 is a cybersecurity company specializing in passwordless, certificate-based authentication for networks and
Evidence against regulations
All regulations for Auth0How much of each regulation’s vendor requirements Auth0’s public evidence reaches.
Reviewing a vendor on public evidence
All articlesSOC 2 Type I vs Type II: what each one proves to a buyer
Solomon Amos · 14 Sep 2026 · 10 min read