SOC2C

Is this your company? Buyers are checking LEAPWORK here. Claim leapwork.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
LEAPWORK logo

LEAPWORK

leapwork.com· 51–200 employees· Security contact
Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

LEAPWORK is SOC 2 Type II compliant. LEAPWORK also holds ISO 27001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Build, maintain and scale automation faster with our AI-powered visual test automation platform.

Compliance & infrastructure

Hosting
Azure

Subprocessors

4
  • O
    OpenAI, LLC · AI-powered data processing and automation
    United States
  • M
    Microsoft Azure · Cloud computing, storage, and data services
    United States
  • C
    Cloudmersive, LLC. · Data processing and API integration services.
    United States
  • R
    Retool Inc. · Data management and internal application development
    United States

Compliance leadership

The person who leads LEAPWORK's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. LEAPWORK's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is LEAPWORK SOC 2 compliant?
LEAPWORK is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is LEAPWORK ISO 27001 certified?
According to LEAPWORK's public trust center, LEAPWORK is ISO 27001 certified. On SOC2C this listing is Listed.
Is LEAPWORK SOC 2 Type I or Type II?
LEAPWORK is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use LEAPWORK's SOC 2 for a vendor risk assessment?
Yes. LEAPWORK's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is LEAPWORK penetration tested?
LEAPWORK hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by LEAPWORK

Reproduced from LEAPWORK's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What is Leapwork’s Trust Center FAQ?
Our Trust Center FAQ is a resource designed to address customer concerns about data privacy, security, and compliance. It reflects Leapwork’s commitment to transparency and provides detailed answers about how we handle and protect your data in line with global data protection regulations, including GDPR and CCPA.
Is Leapwork GDPR and CCPA compliant?
Yes, Leapwork is fully compliant with GDPR and CCPA. We process data in accordance with privacy laws, implement Privacy by Design principles, and maintain a Data Processing Addendum (DPA) to outline our obligations as a data processor/service provider. Learn more about GDPR and CCPA compliance in our Privacy Policy (https://www.leapwork.com/privacy-policy).
What certifications does Leapwork hold?
Leapwork is ISO 27001 certified, reflecting our adherence to stringent information security standards. Additionally, we hold a SOC 2 Type 2 attestation.​​
How do Leapwork On-Premises and Leapwork Cloud differ in terms of compliance needs?
Leapwork offers two primary products: - Leapwork On-Premises: This solution is installed and managed entirely within the customer’s environment. It provides full control over data storage and processing, making it ideal for customers with strict internal compliance or data residency requirements. Since all data stays within the customer’s infrastructure, compliance with regulations like GDPR depends entirely on the customer’s internal practices. - Leapwork Cloud: This is a cloud-hosted solution leveraging Microsoft Azure infrastructure. While Leapwork ensures the platform’s security and compliance with GDPR, CCPA, and ISO 27001, customers must ensure that their use of the platform aligns with applicable regulations. Features like Cloud Blocks and AI Blocks are managed through secure subprocessors, and Leapwork provides detailed documentation to help customers meet their compliance needs​​​. Both products emphasize privacy and security by design, but the choice depends on whether the customer prefers on-premise control or a scalable cloud-based solution with robust vendor-managed compliance measures.
How does Leapwork secure customer data?
We employ robust security measures, including: - Encryption: AES-256 encryption for data at rest and TLS 1.2/1.3 for data in transit. - Access Controls: Multi-factor authentication (MFA) and role-based access permissions. - Regular Audits: Security audits and vulnerability testing to proactively address risks​​.