Is this your company?Buyers are checking LEAPWORK here. Claim leapwork.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is LEAPWORK SOC 2 compliant?
LEAPWORK is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is LEAPWORK ISO 27001 certified?
According to LEAPWORK's public trust center, LEAPWORK is ISO 27001 certified. On SOC2C this listing is Listed.
Is LEAPWORK SOC 2 Type I or Type II?
LEAPWORK is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use LEAPWORK's SOC 2 for a vendor risk assessment?
Yes. LEAPWORK's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is LEAPWORK penetration tested?
LEAPWORK hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is LEAPWORK secure?
Security isn't a single yes/no, but LEAPWORK is SOC 2 Type II compliant and holds ISO 27001, SOC 2 Type II. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does LEAPWORK have a bug bounty or vulnerability disclosure program?
LEAPWORK hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@leapwork.com or via a /security page (LEAPWORK lists a security contact).
Who are LEAPWORK's subprocessors?
LEAPWORK lists 4 subprocessors on its trust center, including OpenAI, LLC, Microsoft Azure, Cloudmersive, LLC., Retool Inc.. Buyers use this for fourth-party risk review.
Where does LEAPWORK host or store data?
LEAPWORK hosts on Azure. Data residency details are on its trust center.
Where is LEAPWORK's trust center or security page?
LEAPWORK's trust center is at https://trust.leapwork.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
What is Leapwork’s Trust Center FAQ?
Our Trust Center FAQ is a resource designed to address customer concerns about data privacy, security, and compliance. It reflects Leapwork’s commitment to transparency and provides detailed answers about how we handle and protect your data in line with global data protection regulations, including GDPR and CCPA.
Is Leapwork GDPR and CCPA compliant?
Yes, Leapwork is fully compliant with GDPR and CCPA. We process data in accordance with privacy laws, implement Privacy by Design principles, and maintain a Data Processing Addendum (DPA) to outline our obligations as a data processor/service provider. Learn more about GDPR and CCPA compliance in our Privacy Policy (https://www.leapwork.com/privacy-policy).
What certifications does Leapwork hold?
Leapwork is ISO 27001 certified, reflecting our adherence to stringent information security standards. Additionally, we hold a SOC 2 Type 2 attestation.
How do Leapwork On-Premises and Leapwork Cloud differ in terms of compliance needs?
Leapwork offers two primary products: - Leapwork On-Premises: This solution is installed and managed entirely within the customer’s environment. It provides full control over data storage and processing, making it ideal for customers with strict internal compliance or data residency requirements. Since all data stays within the customer’s infrastructure, compliance with regulations like GDPR depends entirely on the customer’s internal practices. - Leapwork Cloud: This is a cloud-hosted solution leveraging Microsoft Azure infrastructure. While Leapwork ensures the platform’s security and compliance with GDPR, CCPA, and ISO 27001, customers must ensure that their use of the platform aligns with applicable regulations. Features like Cloud Blocks and AI Blocks are managed through secure subprocessors, and Leapwork provides detailed documentation to help customers meet their compliance needs. Both products emphasize privacy and security by design, but the choice depends on whether the customer prefers on-premise control or a scalable cloud-based solution with robust vendor-managed compliance measures.
How does Leapwork secure customer data?
We employ robust security measures, including: - Encryption: AES-256 encryption for data at rest and TLS 1.2/1.3 for data in transit. - Access Controls: Multi-factor authentication (MFA) and role-based access permissions. - Regular Audits: Security audits and vulnerability testing to proactively address risks.
What happens if a data breach occurs?
Leapwork has a comprehensive incident response plan. In the unlikely event of a breach, we notify affected customers and relevant authorities within 72 hours, as required by GDPR. We also perform a root cause analysis and implement corrective actions.
Where is Leapwork’s data stored?
All EU customer data is stored securely in Microsoft Azure data centers located in the North EU region, ensuring compliance with data residency requirements.
How does Leapwork support data subject rights?
Our platform includes features to help customers comply with GDPR rights, such as data access, rectification, and deletion. Customers can manage these rights directly through the Customer Portal.
Does Leapwork use customer data for training AI models?
No, Leapwork ensures that customer data processed through our AI Blocks is not used to train AI models. Our integration with OpenAI adheres to strict contractual terms ensuring data security and compliance.
How long does Leapwork retain customer data?
Leapwork retains customer data only as long as necessary for providing services or as required by law. Customers can request data deletion at any time through our support team as well as set various retention periods directly on the platform.
Does Leapwork share data with subprocessors?
Yes, Leapwork collaborates with vetted subprocessors, such as Microsoft Azure, OpenAI, and Cloudmersive. These providers meet stringent security and privacy standards. Customers are notified of new subprocessors with the option to object.
How are international data transfers handled?
Leapwork employs Standard Contractual Clauses (SCCs) and Transfer Impact Assessments (TIAs) to ensure secure and lawful international data transfers. When we use US-based subprocessors we strive to use vendors certified under the EU-US Data Privacy Framework.