SOC2C

Is this your company? Buyers are checking Hasura here. Claim hasura.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Hasura logo

Hasura

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Hasura is SOC 2 Type II compliant. Hasura also holds ISO 27001, GDPR, CCPA, and HIPAA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

API Platform, built for data delivery. The fastest and simplest way to build, operate, federate, govern, and evolve a robust API (GraphQL, REST, etc) on all your data – across one domain or many.

Compliance & infrastructure

Hosting
AWSGCPAzure
Data handled
Customer personally identifiable informationCredit card informationPersonal health information

Documents

5

Subprocessors

26
  • A
    Amazon Web Services · Cloud Hosting Provider
  • G
    Google Cloud Platform · Cloud Hosting Provider
  • C
    Cloudflare · Cloud Infrastructure and Security
  • Z
    Zendesk · Customer Support
  • M
    Microsoft Azure · Cloud Hosting Provider
  • A
    Anthropic · AI functionality to power PromptQL
  • O
    OpenAI · AI functionality to power PromptQL
  • S
    Salesforce · Customer Relationship Management
  • D
    Datadog · Log Storage/Analysis
  • S
    Slack · Instant Messaging and communication
  • H
    HoneyComb · Log Storage/Analysis
  • G
    Google Workspace · Identity Provider
Show all 26 subprocessors
  • S
    Stripe · Payment Processor
  • 6
    6sense · CRM & Sales
    USA
  • C
    Clari · CRM & Sales
  • C
    Clickhouse · Data and Analytics
  • F
    FiveTran · Data and Analytics
  • S
    Sentry · Operations and Monitoring
  • L
    Linear · Business Applications
  • M
    Maxio · Payments and Billing
  • M
    Marketo · CRM & Sales
  • N
    Netsuite · Payments and Billing
  • I
    Incident.io · Operations & Monitoring
  • S
    Segment · Data and Analytics
  • Z
    Zoom · Business Applications
  • Z
    ZoomInfo · CRM & Sales

Compliance leadership

The person who leads Hasura's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Hasura's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Hasura SOC 2 compliant?
Hasura is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Hasura ISO 27001 certified?
According to Hasura's public trust center, Hasura is ISO 27001 certified. On SOC2C this listing is Listed.
Is Hasura GDPR compliant?
According to Hasura's public trust center, Hasura is GDPR compliant. On SOC2C this listing is Listed.
Is Hasura CCPA compliant?
According to Hasura's public trust center, Hasura is CCPA compliant. On SOC2C this listing is Listed.
Is Hasura HIPAA compliant?
According to Hasura's public trust center, Hasura is HIPAA compliant. On SOC2C this listing is Listed.

Answers published by Hasura

Reproduced from Hasura's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What data do you collect?
Hasura values and prioritizes data privacy and security within our products. Our suite of applications contain self-hosted, cloud, and hybrid offerings. The data is collected as needed to provide the intended services, remains limited, and dependent on the selected offering. For reference, please review our Privacy policy here: https://hasura.io/legal/hasura-privacy-policy
Where are your servers located?
Hasura maintains servers in various countries around the world, currently in Singapore, Ireland, Belgium, France, India, UK, Germany, Australia, Canada, Japan and the United States.
How do you handle the data we collect?
The Personal Information that you provide, subject to disclosure in accordance with this Policy, shall be maintained in a safe and secure manner. Hasura databases and information are stored on secure servers with appropriate firewalls and physical and electronic safeguards. Hasura uses industry standard physical, technical and administrative security measures designed to safeguard all Personal Information and keep it confidential and secure. We conduct periodic reviews of our security measures pertaining to our Personal Information collection, storage, to guard against unauthorized access to systems. For additional information, reference our security documentation including the SOC 2 Type 2 report.
I found a security bug. Do you have an established bug bounty program?
Hasura has an internal bug bounty program. Please reference our Security Vulnerable Disclosure Protocol here for instructions: https://hasura.io/docs/latest/policies/security-disclosure/
Does Hasura have a Data Processing Addendum (DPA)?
Yes, and we can enter into a DPA with our enterprise customers as applicable. Our DPA is linked here: https://hasura.io/legal/hasura-data-processing-addendum