SOC2C

Is this your company? Buyers are checking Maze here. Claim maze.co free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Maze logo

Maze

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Maze is SOC 2 Type II compliant. Maze also holds GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Maze is the leading product research platform that empowers agile teams to test, learn and act, rapidly. With Maze, product and marketing teams can easily test anything from prototypes to copy or round up user feedback all in one place - democratizing product research company-wide.

Compliance & infrastructure

Hosting
AWSGCP
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Subprocessors

33
  • A
    Amazon Web Services (AWS) · Infrastructure Hosting
    United States 🇺🇸
  • A
    AuraDB (Neo4j Inc.) · Database Hosting
    United States 🇺🇸
  • G
    Google Cloud Platform · AI Inference
    United States 🇺🇸
  • O
    OpenAI · AI Inference
    United States 🇺🇸
  • A
    Amplitude · Product Analytics
    United States 🇺🇸
  • C
    Chili Piper · Scheduling
    United States 🇺🇸
  • D
    Daily.co · Voice Infrastructure
    United States 🇺🇸
  • D
    Datadog · Monitoring
    United States 🇺🇸
  • D
    Deepgram · Transcription
    United States 🇺🇸
  • E
    Emailable · Email Verification
    United States 🇺🇸
  • F
    Fivetran · Data Integration
    United States 🇺🇸
  • G
    Google Workspace · Productivity Suite
    United States 🇺🇸
Show all 33 subprocessors
  • H
    Hightouch · Data Integration
    United States 🇺🇸
  • C
    Cronofy · Scheduling
    United States 🇺🇸
  • F
    Freeplay AI · LLM Experimentation
    United States 🇺🇸
  • H
    HubSpot · Marketing Automation
    United States 🇺🇸
  • G
    Gong · Sales Analytics
    United States 🇺🇸
  • G
    Google Analytics · Web Analytics
    United States 🇺🇸
  • Z
    Zoom · Video Infrastructure
    United States 🇺🇸
  • Z
    Zapier · Automation
    United States 🇺🇸
  • T
    TurboPuffer · Vector Search
    United States 🇺🇸
  • I
    Instantly · Outbound Email
    United States 🇺🇸
  • O
    OutboundSync · Data Integration
    United States 🇺🇸
  • S
    Stripe · Payment Processing
    United States 🇺🇸
  • I
    Iterable · Marketing Automation
    United States 🇺🇸
  • O
    Omni Analytics · Business Intelligence
    United States 🇺🇸
  • S
    Snowflake · Data Warehousing
    United States 🇺🇸
  • S
    Slack · Collaboration
    United States 🇺🇸
  • S
    SendGrid · Transactional Email
    United States 🇺🇸
  • S
    Segment · Customer Data Platform
    United States 🇺🇸
  • S
    Salesforce · CRM
    United States 🇺🇸
  • P
    Pylon · Customer Support
    United States 🇺🇸
  • T
    Temporal · Workflow Orchestration
    United States 🇺🇸

Compliance leadership

The person who leads Maze's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Maze's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Sub-processor updateFeb 2026

Maze is updating our list of authorized sub-processors to include: - Pylon A complete list of all sub-processors and their respective roles is available in our Data Processing Addendum. All sub-processors engaged by Maze undergo rigorous privacy, security, and compliance assessments as part of our Vendor Risk Management process, in accordance with Article 28(1) of the GDPR. If you have any questions or concerns regarding this update, please contact our Privacy Team at [privacy@maze.design](mailto:privacy@maze.design).

Sub-processor updateFeb 2026

Maze is updating our list of authorized sub-processors to include: - Google Cloud Platform - Instantly.ai - OutboundSync A complete list of all sub-processors and their respective roles is available in our Data Processing Addendum. All sub-processors engaged by Maze undergo rigorous privacy, security, and compliance assessments as part of our Vendor Risk Management process, in accordance with Article 28(1) of the GDPR. If you have any questions or concerns regarding this update, please contact our Privacy Team at [privacy@maze.design](mailto:privacy@maze.design).

Sub-processor updateFeb 2026

Maze is updating our list of authorized sub-processors to include: - Temporal – Distributed workflow orchestration and reliability infrastructure A complete list of all sub-processors and their respective roles is available in our Data Processing Addendum. All sub-processors engaged by Maze undergo rigorous privacy, security, and compliance assessments as part of our Vendor Risk Management process, in accordance with Article 28(1) of the GDPR. If you have any questions or concerns regarding this update, please contact our Privacy Team at privacy@maze.design.

Sub-processor UpdateJan 2026

Maze is updating our list of authorised sub-processors. - Omni Analytics - Deepgram - Turbopuffer Details on all our sub-processors and their respective roles are available on https://maze.co/data-processing-addendum/#sub-processors All sub-processors engaged by Maze undergo rigorous privacy, security, and compliance assessments as part of our Vendor Risk Management Process, in line with Article 28(1) of the GDPR. If you have any questions, please feel free to reach out to [privacy@maze.design]

Maze's latest SOC 2 Type II is now availableDec 2025

We are excited to share that we have successfully renewed our SOC2 Type II certification. You can view our latest SOC 2 report on https://compliance.maze.co.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Maze SOC 2 compliant?
Maze is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Maze GDPR compliant?
According to Maze's public trust center, Maze is GDPR compliant. On SOC2C this listing is Listed.
Is Maze SOC 2 Type I or Type II?
Maze is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Maze's SOC 2 for a vendor risk assessment?
Yes. Maze's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Maze penetration tested?
Maze hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.