
Culture Amp
Security and trust center evidence
Empower your teams and fuel positive change with performance, development, and employee engagement tools – all-in-one intuitive employee
Summary
Culture Amp has 7 vendor-stated rows in the CertReports index, last verified 19 Sep 2026. The strongest row is SOC 2: Vendor states SOC 2 on its trust centre. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
Culture Amp states it holds a SOC 2 Type II report. Culture Amp states it holds a data processing agreement. Culture Amp states it holds an ISO/IEC 27001 certificate. Culture Amp states it holds a CSA STAR Level 1 self-assessment.
- SOC 2: Vendor states SOC 2 on its trust centre (as of 19 Sep 2026)
- GDPR: Vendor states GDPR on its trust centre (as of 19 Sep 2026)
- ISO/IEC 27001: Vendor states ISO/IEC 27001 on its trust centre (as of 19 Sep 2026)
Facts only, each dated; nothing here is inferred, scored or advised.
Evidence count
0verified rows
Compliance grid
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 19 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 19 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001 on its trust centre
as of 19 Sep 20261 source- CSA STARVendor-stated
Vendor states CSA STAR on its trust centre
as of 19 Sep 20261 source
ISO/IEC 42001Vendor-statedVendor states ISO/IEC 42001:2023 on its trust centre
as of 19 Sep 20261 source- CCPA / CPRAVendor-stated
Vendor states CCPA on its trust centre
as of 19 Sep 20261 source
IRAPVendor-statedVendor states IRAP on its trust centre
as of 19 Sep 20261 source
No public evidence yet for HIPAA, FedRAMP, PCI DSS, Cyber Essentials, ISO 27701. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Legal artefacts
Subprocessors (2)
- EMEvent Management Virtual Private Cloud
- SISecurity Infrastructure Amazon Web Services