
Summary
OneLogin by One Identity has 7 vendor-stated rows, and 1 expired in the CertReports index, last verified 18 Sep 2026. The strongest row is SOC 2: Vendor states SOC 2 Type 2 on its trust centre. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 18 Sep 2026, CertReports holds 7 vendor-stated rows and 1 expired row for OneLogin by One Identity, drawn from its trust centre (Vanta) and the Data Privacy Framework list. OneLogin by One Identity states on its trust centre that it holds a SOC 2 Type II report, an ISO/IEC 27001 certificate, an ISO/IEC 27701 certificate, a SOC 1 Type II report, a public SOC 3 report, an ISO/IEC 27017 certificate and an ISO/IEC 27018 certificate, captured 18 Sep 2026; these are vendor statements, not independent confirmations. OneLogin by One Identity previously appeared with EU-US Data Privacy Framework evidence, but the listing is no longer active and CertReports found no renewal as of 17 Sep 2026. No public evidence was found for HIPAA, GDPR, PCI DSS and FedRAMP as of 18 Sep 2026; that is a gap in the public record, not a finding of non-coverage, and the vendor can supply it under NDA.
- SOC 2: Vendor states SOC 2 Type 2 on its trust centre, vendor-stated as of 18 Sep 2026
- ISO/IEC 27001: Vendor states ISO 27001:2022 on its trust centre, vendor-stated as of 18 Sep 2026
- EU-US Data Privacy Framework: Inactive, expired as of 17 Sep 2026
Facts only, each dated; nothing here is inferred, scored or advised.
Evidence count
0verified rows
Compliance grid
SOC 2Vendor-statedVendor states SOC 2 Type 2 on its trust centre
as of 18 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO 27001:2022 on its trust centre
as of 18 Sep 20261 source
ISO/IEC 27701Vendor-statedVendor states ISO 27701:2019 on its trust centre
as of 18 Sep 20261 source
SOC 1Vendor-statedVendor states SOC 1 Type 2 on its trust centre
as of 18 Sep 20261 source
SOC 3Vendor-statedVendor states SOC 3 on its trust centre
as of 18 Sep 20261 source
ISO/IEC 27017Vendor-statedVendor states ISO 27017:2022 on its trust centre
as of 18 Sep 20261 source
ISO/IEC 27018Vendor-statedVendor states ISO 27018:2019 on its trust centre
as of 18 Sep 20261 source
EU-US Data Privacy FrameworkExpiredInactive
as of 17 Sep 20261 source
Legal artefacts
Subprocessors (14)
- ADAccolite DigitalContract Staff · India
- AWAmazon Wed Services (AWS)Customer Support · US East
Cisco WebExCustomer Support · USA- DADeltaGen.AIAI Support for Technical Questions · Worldwide
Genesys Cloud CXCustomer Support · US West- LILiveHelpNowCustomer Support · USA
Microsoft AzureCustomer Support · Ireland, Netherlands, Hong Kong, Singapore, India, Australia, US East - Virginia, US West - Washington
MindtickleSales Enablement · US East
OpenAIAI within our products · US and Europe
PostmanCustomer Support · USA and EU- SASalesforceCustomer Support · USA
- SendGridCustomer Support · USA
VantaCompliance · San Francisco, California- VIVitallyCustomer Support · USA
Change history
- 18 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
- 18 Sep 2026ISO/IEC 27017 evidence addedA ISO/IEC 27017 row entered the index with state Vendor-stated.
- 18 Sep 2026ISO/IEC 27018 evidence addedA ISO/IEC 27018 row entered the index with state Vendor-stated.
- 18 Sep 2026ISO/IEC 27701 evidence addedA ISO/IEC 27701 row entered the index with state Vendor-stated.
- 18 Sep 2026SOC 1 evidence addedA SOC 1 row entered the index with state Vendor-stated.
- 18 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
- 18 Sep 2026SOC 3 evidence addedA SOC 3 row entered the index with state Vendor-stated.
- 18 Sep 2026Subprocessor added: Accolite DigitalAccolite Digital appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: Amazon Wed Services (AWS)Amazon Wed Services (AWS) appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: Cisco WebExCisco WebEx appeared on the subprocessor list.