
Splunk
Security and trust center evidence
Summary
Splunk has 2 registry-verified rows and 1 third-party reported row, and 1 expired in the CertReports index, last verified 17 Sep 2026. The strongest row is FedRAMP: FedRAMP Authorized. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, Splunk is listed in the FedRAMP registry as FedRAMP Authorized, with the authorization issued on 13 Sep 2024 and audited by Schellman Compliance, LLC. As of 17 Sep 2026, Splunk is listed in the CSA STAR registry with a STAR Level 2 certification, designated as a Trusted Cloud Provider, issued 21 Jun 2023. As of 17 Sep 2026, the CSA STAR registry entry indicates the STAR Level 2 certification is built on an underlying ISO/IEC 27001 certification issued 21 Jun 2023. As of 17 Sep 2026, Splunk's EU-US Data Privacy Framework status is listed as expired (Inactive), with no active dates provided. No public evidence found for SOC 2 or HIPAA as of 17 Sep 2026.
- FedRAMP: listed in fedramp registry as FedRAMP Authorized, issued 13 Sep 2024, audited by Schellman Compliance, LLC (as of 17 Sep 2026).
- CSA STAR / ISO 27001: listed in csa_star registry with STAR Level 2 certification (Trusted Cloud Provider), built on an ISO/IEC 27001 certification, issued 21 Jun 2023 (as of 17 Sep 2026).
- EU-US Data Privacy Framework: listed as expired/Inactive, no issued or expiry dates available (as of 17 Sep 2026).
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among devops and observability vendors
2verified rows
Category median 1, across 90 indexed devops and observability vendors. Splunk has more verified rows than 88 percent of them.
data analyticslog managementmonitoringobservability
Compare with similar vendors
Pick your own comparisonCompliance grid
- FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · Schellman Compliance, LLC
ISO/IEC 27001ReportedCSA STAR Level 2 certification on the registry, which is built on an ISO/IEC 27001 certification
as of 17 Sep 20261 source- CSA STARVerified
STAR Level 2 certification, Trusted Cloud Provider
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkExpiredInactive
as of 17 Sep 20261 source
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this.
Subprocessors
No subprocessor list captured yet.
Similar vendors with evidence
Related by product tags and the DevOps and observability category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.