SOC2C

Is this your company? Buyers are checking Snyk here. Claim snyk.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Snyk logo

Snyk

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Snyk is SOC 2 Type II compliant. Snyk also holds ISO 27001, ISO 27017, PCI DSS, and FedRAMP.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Trust is paramount at Snyk. Our Developer Security Platform uses AI-driven insights to secure your entire software supply chain and AI-generated code. We ensure transparency: customer code is never used for AI training. We uphold ISO 27001, SOC2 Type II, and GDPR compliance, protecting your data with encryption and regional residency. Explore our commitment to innovative, trustworthy security.

Compliance & infrastructure

Hosting
AWSGoogle Cloud

Documents

28

Subprocessors

20
  • A
    Amplitude, Inc. · Data analytics
    Hosted in the U.S. May be accessed globally by Snyk employees.
  • A
    Amazon Web Services (AWS) · IT
    Data can be hosted in the U.S., EU or Australia at Customer’s election. May be accessed globally by Snyk employees.
  • A
    Akamai Technologies, Inc. · Engineering
    The nature of the Akamai solution, for optimizing traffic management, means that Akamai processes Snyk’s customer data from the region closest to where the user is located.
  • O
    Okta · IT
    Hosted in the U.S, EU or Australia at Customer’s election. May be accessed globally by Snyk employees.
  • C
    Confluent, Inc. · IT
    Hosted in the U.S. May be accessed globally by Snyk employees.
  • C
    CrowdStrike, Inc. · Security
    Hosted in the US or EU (Frankfurt, Germany). May be accessed globally by Snyk employees.
  • D
    Datadog, Inc. · Security
    Hosted in the U.S. May be accessed globally by Snyk employees.
  • D
    DBT Labs, Inc. · Data analytics
    Hosted in the U.S. May be accessed globally by Snyk employees.
  • F
    Functional Software, Inc. (Sentry) · Cloud monitoring
    Hosted in the U.S. May be accessed globally by Snyk employees.
  • G
    Google Cloud Platform · Cloud provider
    Hosted in the U.S. May be accessed globally by Snyk employees.
  • G
    Google Drive · Document management
    Hosted in the U.S. May be accessed globally by Snyk employees.
  • L
    Looker · Data analytics
    Hosted in the EU. May be accessed globally by Snyk employees.
Show all 20 subprocessors
  • M
    MongoDB · Data storage and processing
    Data can be hosted in the U.S., EU or Australia depending on Customer’s selection with respect to Customer’s hosting location.
  • S
    Shoreline Labs, Inc. (d/b/a Nightfall) · Security
    Hosted in the U.S. May be accessed globally by Snyk employees.
  • O
    Orca Security UK Ltd · Security
    Hosted in the EU. May be accessed globally by Snyk employees.
  • S
    Salesforce.com, Inc. · Sales
    Hosted in the U.S. May be accessed globally by Snyk employees.
  • S
    Slack Technologies Limited · slack
    Slack services are hosted in the United States, but processing may occur globally wherever Snyk users access the services.
  • S
    Snowflake, Inc. · snowflake
    As embedded in the Snyk Services, data can be hosted in the U.S., EU or Australia depending on Customer’s selection with respect to Customer’s hosting location. May be accessed globally by Snyk employ
  • S
    Sublime, Security Inc. · Security
    Hosted in the U.S. May be accessed globally by Snyk employees.
  • T
    Twilio Ireland Limited (Segment.io) · Sales
    Hosted in the U.S. May be accessed globally by Snyk employees.

Compliance leadership

The person who leads Snyk's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Snyk's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Supply Chain Compromise Incident - Node-gyp - Update #1Jun 2026

We are investigating an active supply chain compromise affecting multiple npm packages. Current reporting indicates that malicious package versions were published to the npm registry on June 3-4 using a novel install-time execution path involving binding.gyp / node-gyp. Unlike more common npm supply chain compromises that rely on preinstall or postinstall lifecycle scripts, this activity uses binding.gyp to trigger execution during npm install. In the initial wave, 57 npm packages were affected, with multiple malicious versions across the affected package set. The affected package and version list will be updated if the campaign expands. The malicious behavior reportedly includes credential harvesting from developer and CI/CD environments, GitHub Actions workflow injection, package poisoning, and credential exfiltration. It gains persistence by injection into AI assistant configuration files. Initial Snyk advisories are being published, and the investigation remains ongoing. At this time, there is no confirmed Snyk customer impact. Snyk is not impacted. However, any environment that has installed affected package versions should be considered potentially compromised, and appropriate remediation actions should be taken, including removing compromised packages, rotating credentials from a trusted machine, and reviewing developer workstations and CI/CD systems for unauthorized…

Supply Chain Compromise Incident - Laravel-Lang Packagist - Update #1May 2026

We are investigating an active supply chain compromise affecting multiple widely used packages in the `laravel-lang` namespace in the PHP/Composer ecosystem, distributed via Packagist. Snyk services are not impacted by this incident. At least 700 historical package versions across four packages in the `laravel-lang/*` namespace are currently believed to have been compromised, and malicious versions were published to Packagist between May 22 and May 23, 2026. The affected packages are community-maintained Laravel localization libraries and are not part of the official Laravel framework. Initial analysis suggests the attacker bypassed the official repositories entirely by publishing malicious version tags that point to commits in an attacker-controlled fork. The coordinated republication of tags across multiple repositories in the same GitHub organization indicates the attacker likely obtained access to organization-level release credentials. Packagist has taken down the malicious versions and temporarily unlisted the affected packages while investigation and remediation efforts continue. Initial Snyk advisories have been published, and the investigation remains ongoing. At this time, there is no confirmed Snyk customer impact. However, any environment that has installed affected package versions should be considered potentially compromised, and appropriate remediation actions…

Supply Chain Compromise Incident - Antv npm Supply Chain Compromise - Update #3May 2026

We continue to monitor the AntV / Mini Shai-Hulud supply chain compromise and validate affected packages and versions. Since our last update, Snyk has identified additional related activity involving the PyPI package durabletask. The affected versions are 1.4.1, 1.4.2, and 1.4.3. This activity appears related to the broader Mini Shai-Hulud campaign, with limited propagation compared to the npm impact observed in the AntV ecosystem. Snyk has published an advisory for durabletask and is updating the Zero-Day report and dedicated security.snyk.io page accordingly. Customers can continue to assess potential impact in the Snyk app by visiting: Analytics → Reports → Zero-Day → Active Security Incident Assessment for Antv Supply Chain Compromise - May 2026 Snyk has confirmed there is no indication that Snyk systems, products, or infrastructure were compromised. For additional background and technical details, please refer to the Snyk Blog posts \[AntV , durabletask\]. We will continue to monitor the situation and provide updates as needed.

Supply Chain Compromise Incident - Antv npm Supply Chain Compromise - Update #2May 2026

We continue to investigate the active supply chain compromise affecting multiple packages in the AntV npm ecosystem. The “Active Security Incident Assessment for Antv Supply Chain Compromise - May 2026” report is now available in the Snyk app. Customers can use this report to assess potential impact by visiting: Analytics → Reports → Zero-Day → Active Security Incident Assessment for Antv Supply Chain Compromise - May 2026 Current findings indicate that approximately 323 unique npm packages may have been affected, with more than 639 malicious package versions published to the npm registry. The affected packages include packages within the @antv/\* namespace and related npm packages outside the AntV namespace. Any environment that has installed affected package versions should be considered potentially compromised, and appropriate remediation actions should be taken, including reviewing dependency trees and lockfiles, removing or pinning affected packages to known-good versions, rotating credentials from a trusted environment, and reviewing CI/CD systems for suspicious activity. You can use the dedicated security.snyk.io page to identify affected package versions and review recommended remediation actions. For additional background and technical details, please refer to the Snyk Blog post. The investigation remains ongoing, and the scope may change as additional information…

Supply Chain Compromise Incident - Antv npm Supply Chain Compromise - May 2026May 2026

We are investigating an active supply chain compromise affecting multiple widely used packages in the AntV npm ecosystem. Current reporting associates this activity with the ongoing “Mini Shai-Hulud” supply chain campaign, which is impacting additional npm packages outside the @antv/\* namespace. More than 323 unique npm packages are currently believed to have been affected, with more than 639 malicious package versions published to the npm registry. Initial analysis suggests the attacker compromised an npm maintainer account, enabling the publication of malicious packages across a broad set of packages. Initial Snyk Advisories are being prepared, and the investigation remains ongoing. At this time, we are continuing to assess the potential impact on Snyk customers. However, any environment that has installed affected package versions should be considered potentially compromised, and appropriate remediation actions should be taken, including credential rotation and environment review. We will continue to monitor the situation and update this page as more information becomes available.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Snyk SOC 2 compliant?
Snyk is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Snyk ISO 27001 certified?
According to Snyk's public trust center, Snyk is ISO 27001 certified. On SOC2C this listing is Listed.
Is Snyk ISO 27017 certified?
According to Snyk's public trust center, Snyk is ISO 27017 certified. On SOC2C this listing is Listed.
Is Snyk PCI DSS compliant?
According to Snyk's public trust center, Snyk is PCI DSS compliant. On SOC2C this listing is Listed.
Is Snyk FedRAMP compliant?
According to Snyk's public trust center, Snyk is FedRAMP compliant. On SOC2C this listing is Listed.