Security, Privacy & Compliance
Working with Auth0 means working with a vetted, secure solution & partner who understands that you expect a return on your security investment.
Compliance
ISO27001
Auth0 is ISO27001 certified by a third party, managing information security risk in such a way as to comply with a robust design, implementation and continuous monitoring framework.Read MoreSOC 2 Type II
Auth0 has completed a full third-party SOC 2 Type II audit - an independent auditor has evaluated our product, infrastructure, and policies, and certifies that Auth0 complies with their stringent requirements.Read moreISO27018
Auth0 is ISO27018 certified by a third party, complying with security and privacy guidelines for managing PII as a cloud service provider.Read moreHIPAA BAA
Auth0 offers HIPAA BAA agreements to companies in the healthcare industry that must comply with HIPAA regulations for safeguarding patient privacy and sensitive health information.Read moreGold CSA STAR
Auth0 has achieved a Level 2 audit Gold CSA Star certification for its cloud service security capabilities.Read morePCI DSS Compliance
Auth0 is compliant with the Payment Card Industry (PCI) Data Security Standard (DSS) that requires strict security controls and processes for transacting customer payment card data.Read more
GDPR
As a company, Auth0 complies with the General Data Protection Regulation (GDPR). We take customer data privacy seriously, ensuring that:
All new vendors, assets and activities pertaining to processing personal data are subject to a review of privacy, security and compliance.
Personal data is properly collected, stored, and documented.
Relevant processes are followed for transfers of personal data outside the European Union / UK.
For more information, see our privacy policies here.
We also help our customers provide GDPR compliant solutions to their end-users and customers.
Data Sovereignty
Our customers can deploy on our public cloud or private cloud environments to control where data is stored. For more information, refer to our compliance and security certifications.
SEE CERTIFICATIONSDefense-in-depth
Product Security
Access Management
Security Monitoring
Endpoint protection
Incident Response
Vuln. Mgmt
Data encryption at-rest and in-transit
DDoS protection
"We hadn't expected to be able to find a partner like Auth0 who would be so focused on security, proper authentication, and yet create a platform that's incredibly well-documented, easy to test, and is HIPAA compliant.”
"AMD has seen a 50% time savings in identity-related development and has saved 200+ hours of annual operations time by using Auth0."
Contact Auth0's security team directly at:
security@auth0.com