Is this your company? Buyers are checking OpenSanctions.org here. Claim opensanctions.org free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
OpenSanctions.org
Sourced from public information. Not yet verified by the company.
OpenSanctions.org is SOC 2 compliant. OpenSanctions.org also holds ISO 27001, and GDPR.
About
Below we're sharing many of the documents our partners require in order to establish us as a vendor. For further questions and documentation, please [feel free to reach out](https://www.opensanctions.org/support/).
Compliance & infrastructure
Subprocessors
11- GGoogle Cloud Platform · Cloud providereurope-west3 (Frankfurt)
- HHubSpot Germany GmbH · MarketingEU data centres (per HubSpot's EU residency tier)
- SStripe, Inc. · Finance and paymentsEU + Stripe global infrastructure
- DDatev eG · Accounting according to German law (GoBD)Germany
- OOry Networks, Inc. · Single sign-on
- BBetter Stack, Inc. · MonitoringEU
- SSlack Technologies, LLC · Collaboration
- GGitHub, Inc. · Version controlUSA + global
- AAnthropic · EngineeringUSA
- VVanta · SecurityUSA
- GGoogle Analytics · AnalyticsUSA
Compliance leadership
The person who leads OpenSanctions.org's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. OpenSanctions.org's penetration test vendor isn't listed yet.
Claim this profile to add it.
This listing is partial
6/11 details · 55%SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is OpenSanctions.org SOC 2 compliant?
Is OpenSanctions.org ISO 27001 certified?
Is OpenSanctions.org GDPR compliant?
Can I use OpenSanctions.org's SOC 2 for a vendor risk assessment?
Is OpenSanctions.org penetration tested?
Is OpenSanctions.org secure?
Does OpenSanctions.org have a bug bounty or vulnerability disclosure program?
Who are OpenSanctions.org's subprocessors?
Where does OpenSanctions.org host or store data?
Where is OpenSanctions.org's trust center or security page?
Where are your servers located?
I found a security bug. Do you have an established bug bounty program?
What privacy/security settings are available?
Do you support Single Sign-On (SSO)?
Does OpenSanctions fulfill the EU’s DORA regulation requirements?
Technology peers that completed SOC 2

Action1

ELJUN LLC

equipifi
