SOC2C

Is this your company? Buyers are checking Teleport here. Claim goteleport.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Teleport logo

Teleport

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Teleport is SOC 2 Type II compliant. Teleport also holds ISO 27001, ISO 27701, CCPA, GDPR, HIPAA, and PCI DSS.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Our customers trust Teleport to protect their critical infrastructure and help them reduce the blast radius of attacks. We back this trust with the following [security commitments](https://goteleport.com/security/): * Proactive Detection - Publishing third-party security audits, conducting regular security vulnerability scanning, and running an active bug bounty program. * Disclosure - Notifying customers of critical vulnerabilities that could affect them. * Response - Triaging security issues rapidly and performing incident response as needed. * Privacy - Protecting our customers' and partner

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

2

Subprocessors

23
  • A
    Amazon Web Services (AWS) · Infrastructure Hosting
    United States
  • C
    Cloudflare · Content Delivery Network, DNS, DDoS Prevention
    United States
  • S
    Salesforce · CRM Software
    United States
  • 6
    6Sense · Account-based Marketing and Optimization
    United States
  • A
    Adobe · Marketing Automation and Tracking
    United States
  • C
    Clari · Video Conference Recording
    United States
  • C
    Clearbit · Lead Data Enrichment
    United States
  • C
    ClearFeed · Customer Support
    United States
  • G
    GitHub · Code Repository, Issue Tracking and Management
    United States
  • G
    Goldcast · Webinar Hosting
    United States
  • G
    Google Analytics · Analytics
    United States
  • G
    Google Workspace · Email, Collaboration, Data Storage
    United States
Show all 23 subprocessors
  • M
    Mailgun · Email Automation and Delivery
    United States
  • N
    NeverBounce · Email Validation
    United States
  • N
    Notion · Project Management and Customer Success
    United States
  • O
    Outreach · Email Automation
    United States
  • P
    PagerDuty · Incident Response
    United States
  • P
    Panther · Security Information and Event Management
    United States
  • Q
    Qualified · Sales Engagement and Communication Platform
    United States
  • S
    SendGrid · Transactional Emails
    United States
  • S
    Slack · Collaboration and Communication
    United States
  • Z
    Zendesk · Customer Support
    United States
  • Z
    Zoom · Video Conferencing
    United States

Compliance leadership

The person who leads Teleport's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Teleport's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Update on CVE-2026-31431 (Copy Fail)Apr 2026

Teleport has completed an investigation into the impact of the Linux kernel vulnerability CVE-2026-31431 (“Copy Fail”) on Teleport Cloud. We have found no exploitable attack surface in our production environment. We are hardening our infrastructure by disabling the `algif_aead` kernel module where appropriate. We will apply official patches when they are made available for the Linux distributions used in our cloud platform. We encourage Teleport users to review the impact of this Linux kernel vulnerability on their own infrastructure, as it can be used to escalate privileges on affected operating systems. Note that Teleport does not prevent such an exploit after an authorized SSH connection has been established. Teleport’s Session Recording feature can be used to audit SSH sessions for evidence of exploitation attempts. References: * https://copy.fail/ * https://goteleport.com/docs/reference/architecture/session-recording/

Update on LiteLLM and Trivy Supply Chain IncidentsMar 2026

Recent supply chain attacks have compromised the LiteLLM Python package (versions 1.82.7 and 1.82.8) and the Trivy package (version 0.69.4), embedding malicious code designed to steal credentials from affected systems. Teleport has investigated both incidents for impact on our systems and infrastructure, and has concluded that we have not been impacted. Teleport uses Socket to monitor our software supply chain on an ongoing basis, with a specific focus on supply chain attacks like these. We also use Project Discovery Cloud and Wiz for ongoing scanning and monitoring of our platform and web properties.

Update on Shai Hulud NPM Malware AttacksDec 2025

A wide range of NPM packages have been compromised in the past few months with malware attacks using similar, but varied techniques. This group of attacks is being referred to as "Shai Hulud". Teleport has investigated all currently known compromised packages for impact on our systems, and has concluded that we have not been impacted at this time. Teleport uses Socket to monitor our software supply chain on an ongoing basis, with a specific focus on malware attacks like Shai Hulud. We also use Project Discovery Cloud and Wiz for ongoing scanning and monitoring of our platform and web properties.

Update on CVE-2025-66564Dec 2025

CVE-2025-66564 is a high-severity issue in Sigstore's Timestamp Authority. Teleport has applied the patch to our master branch, but the patch version (2.0.3) includes a requirement to update to Go 1.25 which is not currently available in Teleport release branches. Go 1.25 will be available in Teleport releases after it passes our test plan in Q1 of calendar year 2026. As a result, this vulnerability will continue to be picked up by security scanning tools until Teleport is updated to Go 1.25. Teleport security engineers have completed an evaluation of this vulnerability and determined that Teleport is not affected. The vulnerable APIs are not used in Teleport (directly or indirectly). https://nvd.nist.gov/vuln/detail/CVE-2025-66564 https://github.com/sigstore/timestamp-authority/security/advisories/GHSA-4qg8-fj49-pxjh

Update on CVE-2025-55182 and CVE-2025-66478, critical vulnerabilities in React and Next.jsDec 2025

We have completed our investigation into CVE-2025-55182 and CVE-2025-66478, critical RCE vulnerabilities in React and Next.js. Teleport is not impacted.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Teleport SOC 2 compliant?
Teleport is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Teleport ISO 27001 certified?
According to Teleport's public trust center, Teleport is ISO 27001 certified. On SOC2C this listing is Listed.
Is Teleport ISO 27701 certified?
According to Teleport's public trust center, Teleport is ISO 27701 certified. On SOC2C this listing is Listed.
Is Teleport CCPA compliant?
According to Teleport's public trust center, Teleport is CCPA compliant. On SOC2C this listing is Listed.
Is Teleport GDPR compliant?
According to Teleport's public trust center, Teleport is GDPR compliant. On SOC2C this listing is Listed.