SOC2C

Is this your company? Buyers are checking Datadome here. Claim datadome.co free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Datadome logo

Datadome

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Datadome is SOC 2 Type II compliant. Datadome also holds GDPR, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

DataDome’s AI-powered cyberfraud protection platform stops sophisticated bot and fraud attacks with unparalleled accuracy and zero compromise.

Compliance & infrastructure

Hosting
AWSGCP
Data handled
Customer personally identifiable information used to connect to the DataDome dashboardHTTP Traffic fingerprints from visitors on customers websites

Documents

6

Subprocessors

8
  • A
    Amazon Web Services · Cloud provider
    Worldwide
  • G
    Google · Cloud provider
    Worldwide
  • O
    OVH EUROPE · Cloud provider
    Europe
  • S
    SCALEWAY (Online) · Cloud provider
    Europe
  • A
    Auth0 · Identity provider
    Europe
  • D
    Datadog · Monitoring & Logging for Applications and Security
    Europe
  • E
    Elastic Cloud · Data storage
    Europe
  • I
    Imply.io · Data storage
    Europe

Compliance leadership

The person who leads Datadome's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Datadome's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

SOC 2 Type II Report Renewal (April 2025 – March 2026)Apr 2026

We are pleased to share that DataDome has successfully completed a new SOC 2 Type II report (April 2025 – March 2026). This independent assessment was conducted by Coalfire and covers the Security, Availability, and Confidentiality Trust Services Criteria across our entire Cyberfraud Protection Platform. The full SOC 2 Type II report is available in our Trust Center.

CISA Secure by Design PledgeDec 2025

DataDome has signed the CISA Secure by Design Pledge, reinforcing our commitment to embedding security throughout the product lifecycle. This initiative aligns with our long-standing approach to building secure, resilient products by design. Learn more: https://datadome.co/data-privacy/commitment-cisa-secure-by-design-pledge/ https://www.cisa.gov/securebydesign/pledge/progress-reports

DataDome's Response to React Server Component’s RCE Vulnerability (CVE-2025-55182)Dec 2025

A recently disclosed Remote Code Execution (RCE) vulnerability affecting React Server and Next.js, tracked as CVE-2025-55182, may allow attackers to execute arbitrary code by abusing specific server actions and request patterns. ### Impact on DataDome DataDome does not use React Server or Next.js in the delivery of its services. As a result, DataDome’s infrastructure and platform are not affected by this vulnerability. DataDome provides an optional integration module for customers using these frameworks. This module is not impacted by CVE-2025-55182. A demo application previously offered to test the integration has been updated to use patched versions of the affected components. ### Recommendations for Customers If your applications rely on React Server or Next.js, we recommend that you: - Update to the latest patched versions of the affected frameworks. - Review any server actions in your codebase that could be exposed to RCE conditions. - Ensure your CI/CD pipelines and dependency management systems pull the patched releases. DataDome’s integration module does not require any updates, but your application components must be kept up to date to remain secure. ### DataDome Protection and Monitoring DataDome monitors and protects against malicious traffic patterns associated with this vulnerability. Our detection engine inspects: - Requests containing `next-action` or…

Sha1-Hulud (2.0) NPM Supply Chain Attack - No impact to DataDomeNov 2025

DataDome is monitoring the newly reported “Shai-Hulud 2.0” npm supply-chain campaign. After a thorough review of our build pipelines and dependencies, we confirm that no DataDome systems, products, or customer environments are impacted. We continue to maintain strict isolation, code-integrity controls, and continuous monitoring across all build and deployment pipelines. Based on all available intelligence and our internal assessments, we have found no evidence of compromise, malicious packages, or suspicious activity within our environment. We will provide additional updates if new information becomes available.

Our 2025 Penetration Test Attestations are now available.Oct 2025

We are happy to share that our latest independent penetration test has been completed. The 2025 Penetration Test Attestations are now published and available for download directly from the DataDome Trust Center. Scope of the assessment The penetration test covered the full DataDome product suite: - DataDome Bot Protection - Account Protect - Page Protect - Ad Fraud Protect The assessment was performed by an independent third party using industry-standard methodologies ( OWASP Testing Guide).

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Datadome SOC 2 compliant?
Datadome is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Datadome GDPR compliant?
According to Datadome's public trust center, Datadome is GDPR compliant. On SOC2C this listing is Listed.
Is Datadome CCPA compliant?
According to Datadome's public trust center, Datadome is CCPA compliant. On SOC2C this listing is Listed.
Is Datadome SOC 2 Type I or Type II?
Datadome is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Datadome's SOC 2 for a vendor risk assessment?
Yes. Datadome's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.