Skip to main content
Auth0 logo

Auth0

SOC 2 evidence

Secure users, AI agents, and more with Auth0, an easy-to-implement, scalable, and adaptable authentication and authorization

auth0.comIdentity and accessLast verified 21 Sep 2026
SOC 2 mark, CertReports state Vendor-stated as of 21 Sep 2026Vendor-stated

Auth0 and SOC 2

Auth0 states it holds a SOC 2 Type II report. CertReports captured this on 21 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.

Evidence

Vendor-statedVendor states SOC 2 on its trust centre
as of 21 Sep 2026 · confidence 80%
SourceCapturedQuoteLinks
Auth0 trust centre (Drata)
Vendor trust centre · HTTP 200
21 Sep 2026SOC 2
Live page Snapshotsha256 8981020655
Vendor-statedVendor states CSA STAR on its trust centre
as of 21 Sep 2026 · confidence 80%
SourceCapturedQuoteLinks
Auth0 trust centre (Drata)
Vendor trust centre · HTTP 200
21 Sep 2026CSA STAR
Live page Snapshotsha256 8981020655
Vendor-statedVendor states SOC 1 on its trust centre
as of 21 Sep 2026 · confidence 80%
SourceCapturedQuoteLinks
Auth0 trust centre (Drata)
Vendor trust centre · HTTP 200
21 Sep 2026SOC 1
Live page Snapshotsha256 8981020655
Vendor-statedVendor states SOC 3 on its trust centre
as of 21 Sep 2026 · confidence 80%
SourceCapturedQuoteLinks
Auth0 trust centre (Drata)
Vendor trust centre · HTTP 200
21 Sep 2026SOC 3
Live page Snapshotsha256 8981020655

What is not public

  • The report period is not public, so CertReports cannot say whether the Auth0 SOC 2 report covers the last 12 months.
  • The audit firm is not stated in any public source CertReports has captured.
  • Trust services criteria in scope, carve-outs and bridge-letter status are only in the restricted-use report, which CertReports never hosts.
What SOC 2 means, and what it does not

SOC 2 reports are restricted-use and are never "certifications". A Type II report covers a period; freshness is the period end plus a bridge letter of at most three months. "SOC 2 ready" and "in progress" are not reports. No public SOC 2 registry exists; the strongest registry-grade signal is a CSA STAR Level 2 attestation, then a public SOC 3.

Read the SOC 2 guide and browse all vendors with evidence

Questions buyers ask

Is Auth0 SOC 2 certified?

No organisation is "SOC 2 certified": SOC 2 is an attestation report issued by a CPA firm, not a certification. Auth0 states it holds a SOC 2 Type II report as of 21 Sep 2026.

How do I get the Auth0 SOC 2 report?

SOC 2 reports are restricted-use documents shared under NDA. Request it through the Auth0 trust centre or security page; CertReports links to it and never hosts the report.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 22 Sep 2026First indexed by CertReports16 evidence rows across 16 frameworks entered the index.

Alternatives with SOC 2 evidence

Similar vendors (shared product tags or the Identity and access category) whose SOC 2 row is verified or vendor-stated, ranked by similarity.

All articles