SOC2C

Is this your company? Buyers are checking Dashlane here. Claim dashlane.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Dashlane logo

Dashlane

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Dashlane is SOC 2 Type II compliant. Dashlane also holds ISO 27001, GDPR, CCPA, and HIPAA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Used by over 25,000 organizations and millions of people worldwide, Dashlane's user-first password management and digital identity management platform works seamlessly across web browsers, iOS and Android devices to make security simple. Our patented technology makes creating, managing, and using super-secure online credentials seamless. We empower organizations to protect company and employee data, while helping everyone easily log in to the accounts they need—anytime, anywhere.

Compliance & infrastructure

Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

2

Compliance leadership

The person who leads Dashlane's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Dashlane's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Dashlane SOC 2 compliant?
Dashlane is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Dashlane ISO 27001 certified?
According to Dashlane's public trust center, Dashlane is ISO 27001 certified. On SOC2C this listing is Listed.
Is Dashlane GDPR compliant?
According to Dashlane's public trust center, Dashlane is GDPR compliant. On SOC2C this listing is Listed.
Is Dashlane CCPA compliant?
According to Dashlane's public trust center, Dashlane is CCPA compliant. On SOC2C this listing is Listed.
Is Dashlane HIPAA compliant?
According to Dashlane's public trust center, Dashlane is HIPAA compliant. On SOC2C this listing is Listed.

Answers published by Dashlane

Reproduced from Dashlane's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do you encrypt data at rest?
Yes. Data stored on Dashlane is only ever decrypted locally, after a user has provided valid credentials on a verified device. All client data sent to Dashlane's servers (used to synchronize data among user devices) is encrypted at all times when in transit and at rest on our servers.
How do you protect passwords and other information stored on Dashlane?
By far the most important element of Dashlane's approach to protecting the data stored by users on our software (which is defined as "Secured Data in our consumer and business terms, but is often colloquially referred to as user "vaults") is our "Zero Knowledge" Architecture. What this means is that Dashlane (and our employees, subcontractors, etc.) cannot access information that users store on our software, even when that information is stored on our (AWS) servers. This is because each user's Secured Data is encrypted in transit and at rest with a unique key, which we do not have, that is derived either from their Master Password or SSO credentials. We do not have these encryption keys (or users' master passwords or SSO credentials), nor does our system include a "backdoor," master key, or any other technical means to expose user's vaults.
Do you support Single Sign-On (SSO)?
Yes, our Dashlane "Business" tier supports most major SSO providers. For SSO users, we automatically generate a random, 64 byte encryption key. To provide maximum security for user data, the key is split into two pieces, one of which is stored by Dashlane, and the other can either be stored in the Client environment or in a secure confidential computing enclave in AWS. In either case, any attacker hoping to gain access to the encryption key would have to hack multiple, fully isolated computing environments in order to obtain the complete encryption key.
Do you use third party subprocessors?
Yes, please see this page for complete information: https://www.dashlane.com/privacy/subprocessors
Where are your servers located?
Our servers are located in AWS' Dublin, Ireland region. We use multiple availability zones within the region in order to ensure maximum uptime and robust business continuity and disaster recovery protections.