Is this your company? Buyers are checking Teleport here. Claim goteleport.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Teleport
Sourced from public information. Not yet verified by the company.
Teleport is SOC 2 Type II compliant. Teleport also holds ISO 27001, ISO 27701, CCPA, GDPR, HIPAA, and PCI DSS.
About
Our customers trust Teleport to protect their critical infrastructure and help them reduce the blast radius of attacks. We back this trust with the following [security commitments](https://goteleport.com/security/): * Proactive Detection - Publishing third-party security audits, conducting regular security vulnerability scanning, and running an active bug bounty program. * Disclosure - Notifying customers of critical vulnerabilities that could affect them. * Response - Triaging security issues rapidly and performing incident response as needed. * Privacy - Protecting our customers' and partner
Compliance & infrastructure
Documents
2Subprocessors
23- AAmazon Web Services (AWS) · Infrastructure HostingUnited States
- CCloudflare · Content Delivery Network, DNS, DDoS PreventionUnited States
- SSalesforce · CRM SoftwareUnited States
- 66Sense · Account-based Marketing and OptimizationUnited States
- AAdobe · Marketing Automation and TrackingUnited States
- CClari · Video Conference RecordingUnited States
- CClearbit · Lead Data EnrichmentUnited States
- CClearFeed · Customer SupportUnited States
- GGitHub · Code Repository, Issue Tracking and ManagementUnited States
- GGoldcast · Webinar HostingUnited States
- GGoogle Analytics · AnalyticsUnited States
- GGoogle Workspace · Email, Collaboration, Data StorageUnited States
Show all 23 subprocessorsShow fewer
- MMailgun · Email Automation and DeliveryUnited States
- NNeverBounce · Email ValidationUnited States
- NNotion · Project Management and Customer SuccessUnited States
- OOutreach · Email AutomationUnited States
- PPagerDuty · Incident ResponseUnited States
- PPanther · Security Information and Event ManagementUnited States
- QQualified · Sales Engagement and Communication PlatformUnited States
- SSendGrid · Transactional EmailsUnited States
- SSlack · Collaboration and CommunicationUnited States
- ZZendesk · Customer SupportUnited States
- ZZoom · Video ConferencingUnited States
Compliance leadership
The person who leads Teleport's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Teleport's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
Update on CVE-2026-31431 (Copy Fail)Apr 2026
Teleport has completed an investigation into the impact of the Linux kernel vulnerability CVE-2026-31431 (“Copy Fail”) on Teleport Cloud. We have found no exploitable attack surface in our production environment. We are hardening our infrastructure by disabling the `algif_aead` kernel module where appropriate. We will apply official patches when they are made available for the Linux distributions used in our cloud platform. We encourage Teleport users to review the impact of this Linux kernel vulnerability on their own infrastructure, as it can be used to escalate privileges on affected operating systems. Note that Teleport does not prevent such an exploit after an authorized SSH connection has been established. Teleport’s Session Recording feature can be used to audit SSH sessions for evidence of exploitation attempts. References: * https://copy.fail/ * https://goteleport.com/docs/reference/architecture/session-recording/
Update on LiteLLM and Trivy Supply Chain IncidentsMar 2026
Recent supply chain attacks have compromised the LiteLLM Python package (versions 1.82.7 and 1.82.8) and the Trivy package (version 0.69.4), embedding malicious code designed to steal credentials from affected systems. Teleport has investigated both incidents for impact on our systems and infrastructure, and has concluded that we have not been impacted. Teleport uses Socket to monitor our software supply chain on an ongoing basis, with a specific focus on supply chain attacks like these. We also use Project Discovery Cloud and Wiz for ongoing scanning and monitoring of our platform and web properties.
Update on Shai Hulud NPM Malware AttacksDec 2025
A wide range of NPM packages have been compromised in the past few months with malware attacks using similar, but varied techniques. This group of attacks is being referred to as "Shai Hulud". Teleport has investigated all currently known compromised packages for impact on our systems, and has concluded that we have not been impacted at this time. Teleport uses Socket to monitor our software supply chain on an ongoing basis, with a specific focus on malware attacks like Shai Hulud. We also use Project Discovery Cloud and Wiz for ongoing scanning and monitoring of our platform and web properties.
Update on CVE-2025-66564Dec 2025
CVE-2025-66564 is a high-severity issue in Sigstore's Timestamp Authority. Teleport has applied the patch to our master branch, but the patch version (2.0.3) includes a requirement to update to Go 1.25 which is not currently available in Teleport release branches. Go 1.25 will be available in Teleport releases after it passes our test plan in Q1 of calendar year 2026. As a result, this vulnerability will continue to be picked up by security scanning tools until Teleport is updated to Go 1.25. Teleport security engineers have completed an evaluation of this vulnerability and determined that Teleport is not affected. The vulnerable APIs are not used in Teleport (directly or indirectly). https://nvd.nist.gov/vuln/detail/CVE-2025-66564 https://github.com/sigstore/timestamp-authority/security/advisories/GHSA-4qg8-fj49-pxjh
Update on CVE-2025-55182 and CVE-2025-66478, critical vulnerabilities in React and Next.jsDec 2025
We have completed our investigation into CVE-2025-55182 and CVE-2025-66478, critical RCE vulnerabilities in React and Next.js. Teleport is not impacted.
This listing is partial
7/11 details · 64%SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Teleport SOC 2 compliant?
Is Teleport ISO 27001 certified?
Is Teleport ISO 27701 certified?
Is Teleport CCPA compliant?
Is Teleport GDPR compliant?
Is Teleport HIPAA compliant?
Is Teleport PCI DSS compliant?
Is Teleport SOC 2 Type I or Type II?
Can I use Teleport's SOC 2 for a vendor risk assessment?
Is Teleport penetration tested?
Is Teleport secure?
Does Teleport have a bug bounty or vulnerability disclosure program?
Who are Teleport's subprocessors?
Where does Teleport host or store data?
Where is Teleport's trust center or security page?
Technology peers that completed SOC 2

Action1

ELJUN LLC

equipifi
