SOC2C

Is this your company? Buyers are checking Chainguard Inc here. Claim chainguard.dev free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Chainguard Inc logo

Chainguard Inc

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Chainguard Inc is SOC 2 Type II compliant. Chainguard Inc also holds ISO 27001, GDPR, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Safe Source for Open Source™ We are committed to safeguarding our customers' data through industry standards, compliance certifications, and third-party audits. ###### Reporting Security Concerns Please review the [Inbound Vulnerability Disclosure Policy](https://www.chainguard.dev/legal/inbound-vulnerability-disclosure-policy) before sending a report. We do not participate in a bug bounty program. If you find an issue in our products or sites, report it to our team using the email below.

Compliance & infrastructure

Hosting
GCP
Data handled
Employee personally identifiable informationCredit card informationPersonal health information

Documents

3

Subprocessors

6
  • G
    Google Cloud Platform · Cloud service provider
    United States
  • C
    Cloudflare · Content delivery services
    United States
  • V
    Vercel · Data infrastructure and hosting services
    United States, United Kingdom, and Spain
  • Z
    Zendesk · Customer support platform
    United States
  • O
    Okta · Identity management services
    United States
  • F
    Feature-specific Subprocessors

Compliance leadership

The person who leads Chainguard Inc's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Chainguard Inc's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Added CAIQ v4.0.2Jun 2025

A completed copy of the CAIQ v4.0.2 was uploaded to the compliance section.

Added Higher Education Community Vendor Assessment Toolkit (HECVAT) DocumentJun 2025

Uploaded a completed Higher Education Community Vendor Assessment Toolkit (HECVAT) document for higher education customers.

Vulnerability Disclosure PoliciesMar 2025

Links to the _Inbound Vulnerability Disclosure Policy_ were added to: * The Trust Center header section * The Resources section * The FAQ section Links to the _Outbound Vulnerability Disclosure Policy_ were added to: * The Resources section * The FAQ section

WelcomeFeb 2025

Welcome to Chainguard's Trust Center. To receive notifications for future updates, find and click the "Subscribe to Updates" button in the page header above. It looks like a little bell (🔔).

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Chainguard Inc SOC 2 compliant?
Chainguard Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Chainguard Inc ISO 27001 certified?
According to Chainguard Inc's public trust center, Chainguard Inc is ISO 27001 certified. On SOC2C this listing is Listed.
Is Chainguard Inc GDPR compliant?
According to Chainguard Inc's public trust center, Chainguard Inc is GDPR compliant. On SOC2C this listing is Listed.
Is Chainguard Inc CCPA compliant?
According to Chainguard Inc's public trust center, Chainguard Inc is CCPA compliant. On SOC2C this listing is Listed.
Is Chainguard Inc SOC 2 Type I or Type II?
Chainguard Inc is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Business & Industrial peers that completed SOC 2