SOC2C

Is this your company? Buyers are checking Ory GmbH here. Claim ory.sh free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Ory GmbH logo

Ory GmbH

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Ory GmbH is SOC 2 Type II compliant. Ory GmbH also holds ISO 27001, PCI DSS, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

The Ory Network is the commercial offering of Ory and is built on top of Ory Open Source software. The goal with Ory Network is to offer a planet-scale, low-latency, resilient, and secure service that's easy to use and set up. In short: Ory Network is the most convenient way to run Ory.

Compliance & infrastructure

Hosting
GCP

Subprocessors

12
  • G
    Google Cloud Platform · IaaS infrastructure: Network, GKE Clusters, Compute, Storage, Cache
    europe-west3, europe-west1, us-east4, us-west2, asia-northeast1
  • C
    Cloudflare · DDOs Protection, Managed WAF, Rate Limiting, DNS Management, TLS & Custom Hostna
    Global
  • C
    Cockroach Labs · Multi-region Database solution.
    europe-west3, us-east4, us-west2, asia-northeast1
  • M
    Mailgun · Mail Service
    europe-west1, europe-west3
  • S
    Slack · Dedicated Support Channel and Community Workspace
    US
  • H
    Hubspot · CRM Solution
    EU
  • S
    Stripe · Payment Handling for Ory Network
    US
  • G
    GitHub · Version control
    USA
  • P
    Posthog · Data analytics
    EU
  • G
    Google Workspace · Cloud provider
    USA
  • S
    Sentry (Functional Software, Inc.) · Cloud monitoring
    USA
  • Z
    Zendesk · Ticketing Support
    US

Compliance leadership

The person who leads Ory GmbH's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Ory GmbH's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Ory Completes PCI DSS v4.0.1 SAQ D for Service ProvidersJun 2026

Ory Corp has successfully completed its PCI DSS v4.0.1 SAQ D for Service Providers assessment, with an overall Compliant rating. The Qualified Security Assessor, BARR Advisory, performed the testing procedures. Ory is a service provider and does not store, process, or transmit account data. The scope covers Ory Network, and the assessment reflects the design and implementation of our controls against the applicable PCI DSS requirements as of the assessment date. The Attestation of Compliance (AOC) is available under Resources in the Trust Center.

Ory Corp Completes 2025-2026 SOC 2 Type 2 AuditMay 2026

Ory Corp has successfully completed its SOC 2 Type 2 audit for the period April 1, 2025 to March 31, 2026 with no exceptions noted. The audit was conducted by BARR Advisory, P.A., a licensed CPA firm. The report covers the Trust Services Criteria relevant to Security, Confidentiality, and Availability. SOC 2 Type 2 attests to the suitability of design and operating effectiveness of our controls throughout the full twelve-month audit period. The scope covers Ory Network. The updated report is available under Resources in the Trust Center.

Ory Corp Recertified to ISO/IEC 27001:2022Apr 2026

Ory Corp has successfully completed its ISO/IEC 27001:2022 recertification audit with no findings. The audit was conducted by BARR Certifications, an ANAB-accredited certification body. This recertification renews our ISO/IEC 27001 certification for a full three-year cycle, with annual surveillance audits scheduled to maintain continuous compliance. The scope covers the Information Security Management System supporting the Ory Identity Platform. The updated certificate is available under Resources in the Trust Center.

Security Assessment Update: Q4 2024Feb 2025

We are pleased to announce the completion of two comprehensive security assessments conducted by Cure53 in Q4 2024. These assessments covered both the Ory Network services and our infrastructure setup. Ory Network Services A thorough evaluation of the Ory Network and its components was performed across five work packages, covering Ory Network UI & CLI, Login & Authentication, Identity Management, Permissions & Access Control, and API Access with OAuth2/Machine-To-Machine capabilities. The assessment identified eight findings: two low-to-medium severity vulnerabilities and six general recommendations. Our team is actively working on implementing fixes and improvements to address these findings. Notably, no critical or high-severity issues were discovered, demonstrating our platform's robust security posture. Ory Network Infrastructure A separate review of our infrastructure configuration revealed only two low-risk findings. This exceptional result validates the effectiveness of our security measures and infrastructure implementation. Both assessments were conducted using white-box methodology, providing Cure53's security experts with full access to our source code and documentation. The complete absence of critical findings and the minimal number of vulnerabilities underscore our commitment to maintaining the highest security standards. We maintain our commitment to regular…

Ory Corp Achieves Data Privacy Framework (DPF) CertificationJun 2024

We are pleased to announce that Ory Corp has successfully self-certified in the Data Privacy Framework (DPF) as of May 30, 2024. The EU-U.S. DPF, UK Extension to the EU-U.S. DPF, and Swiss-U.S. DPF were developed by the U.S. Department of Commerce in collaboration with the European Commission, the UK Government, and the Swiss Federal Administration. These frameworks provide reliable mechanisms for personal data transfers to the United States from the European Union, United Kingdom, and Switzerland while ensuring data protection consistent with EU, UK, and Swiss law. This certification is a testament to our unwavering commitment to data privacy and our steadfast adherence to the highest standards of data protection.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Ory GmbH SOC 2 compliant?
Ory GmbH is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Ory GmbH ISO 27001 certified?
According to Ory GmbH's public trust center, Ory GmbH is ISO 27001 certified. On SOC2C this listing is Listed.
Is Ory GmbH PCI DSS compliant?
According to Ory GmbH's public trust center, Ory GmbH is PCI DSS compliant. On SOC2C this listing is Listed.
Is Ory GmbH GDPR compliant?
According to Ory GmbH's public trust center, Ory GmbH is GDPR compliant. On SOC2C this listing is Listed.
Is Ory GmbH SOC 2 Type I or Type II?
Ory GmbH is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.