Is this your company? Buyers are checking Asana here. Claim asana.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Asana
Sourced from public information. Not yet verified by the company.
Asana is SOC 2 Type II compliant, with its most recent report dated Jan 2026. Asana also holds SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, HIPAA, GDPR, CCPA, FedRAMP, and CSA STAR.
About
Work management and team collaboration platform.
Compliance & infrastructure
Compliance leadership
The person who leads Asana's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Asana's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
New Asana SOC Reports and ISO CertificatesMay 2026
We are pleased to announce that Asana has successfully completed a SOC 2 Type 1 audit for our Asana Gov platform — a significant milestone in our ongoing commitment to meeting the security and compliance requirements of government and public sector customers. In addition, we are pleased to share the following compliance updates for the Asana platform: The SOC 2 Type 2 report + HIPAA Assessment for the period February 1, 2025 to January 31, 2026 is now available for download via our Trust Center. The SOC 3 report for the same period is publicly available. Asana has also successfully completed its surveillance review against the ISO 27001:2022 standard. Current certifications for ISO 27001, ISO 27017, ISO 27018, and ISO 27701 are publicly available for download via the respective links.
New Asana SOC Reports and ISO certificatesApr 2025
Asana's SOC 2 Type 2 report + HIPAA Assessment for the period covering from February 2024 to January 2025 is now available to request for download from our Trust Center. Additionally, the Asana SOC 3 report for the same period is now publicly available. Asana successfully passed its recertification against the ISO 27001 standard, and was audited against the most recent version of the standard: ISO 27001:2022. Our up to date certifications for ISO 27001, ISO 27017, ISO 27018, and ISO 27701 are all available publicly for download by following the respective links.
New Security Assessment (Penetration Test) report published (August to November 2024)Nov 2024
Praetorian Security, Inc. just completed Asana's FY25 security assessment / penetration test. The scope of this test covers our web and mobile application, cloud infrastructure, Asana-owned integrations (subset selected by Asana Security), internal network, external network, and AI / Smart features. Please see the summary report on Asana's Trust Center: Penetration Testing
Asana Announces Commitment to Pursuing FedRAMP AuthorizationAug 2024
Asana has just publicly announced that we have committed to pursuing FedRAMP authorization - a commitment that will serve the complex needs of our customers in regulated industries. By pursuing FedRAMP, we expect numerous benefits to be extended to our customers, including: - Enhanced security and trust, especially among those in a regulatory environment - Expanded access for our customers working with or aspiring to do business with the U.S. Federal Government To learn more, check out our press release here and our blog post here.
New ISO 27001 SoA Published (February 2024)Feb 2024
As part of Asana’s annual security compliance audits, Asana was audited against the updated version of the ISO 27001 standard (ISO 27001:2022). As part of preparing for this audit, Asana updated its Statement of Applicability (SoA) in line with the new version, defining which ISO 27001:2022 controls were applied into the organization. Please find this updated SoA at Asana’s Trust Center here: ISO 27001 SoA.
New Disaster Recovery Summary Published (October 2023)Nov 2023
Asana just completed our annual Disaster Recovery Test in October 2023. The goal of this exercise is to model a worst case scenario where our infrastructure is completely lost and we are forced to bring up data from backup snapshots of our production environment, which we call snapshots. Please see the summary report on Asana's Trust Center: Disaster Recovery Summary
This listing is partial
7/11 details · 64%SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- SubprocessorsList your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.