SOC2C

Is this your company? Buyers are checking CAOS AG here. Claim zitadel.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
CAOS AG logo

CAOS AG

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

CAOS AG is SOC 2 Type II compliant. CAOS AG also holds ISO 27001, GDPR, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to ZITADEL's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation. For security reports, please consult our [security.txt](https://zitadel.com/.well-known/security.txt) how to get in touch and report vulnerabilities. Useful resources: * [Data Processing Agreement](https://zitadel.com/docs/legal/data-processing-agreement) * [Legal Center](https://zitadel.com/legal) * [legal@zitadel.com](mailto:legal@zitadel.com) for legal and complian

Compliance & infrastructure

Hosting
GCP
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCustomer uploaded data

Subprocessors

3
  • G
    Google Cloud Platform · [Zitadel Cloud] Cloud provider
    Designated by customer
  • P
    Postmark (AC PM LLC) · [Zitadel Cloud] Transactional emails (Optional)
    USA
  • T
    Twillio Inc. · [Zitadel Cloud] Communication (Optional)
    USA

Compliance leadership

The person who leads CAOS AG's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. CAOS AG's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Updated Privacy Policy and Sub-ProcessorsOct 2025

Privacy Policy We've updated the Zitadel's Privacy Policy to align with the Data Privacy Framework (DPF) principles, a change approved by the U.S. Department of Commerce. This update ensures stronger privacy protections for data transfers from the EU/EEA, UK, and Switzerland to the U.S. and is now reflected in our policy. Zitadel has completed the necessary self-certification and is registered for an independent recourse mechanism (JAMS) to resolve complaints. Key changes: * Zitadel complies with the EU-U.S. DPF and the Swiss-U.S. DPF as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal data transferred from the European Union, European Economic Area, and Switzerland to the United States. The policy now details our commitment to effective recourse, enforcement, and liability under the DPF. We utilize JAMS (Judicial Arbitration and Mediation Services) as our independent recourse mechanism (IDR) and detail the conditions for binding arbitration as a means of dispute resolution. * Zitadel's HQ address has been updated. * We've removed explicit listings of analytics providers. The policy now links to our sub-processor list. Sub-Processors * Removed Posthog, Inc. * Added Mixpanel for Data Analytics

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is CAOS AG SOC 2 compliant?
CAOS AG is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is CAOS AG ISO 27001 certified?
According to CAOS AG's public trust center, CAOS AG is ISO 27001 certified. On SOC2C this listing is Listed.
Is CAOS AG GDPR compliant?
According to CAOS AG's public trust center, CAOS AG is GDPR compliant. On SOC2C this listing is Listed.
Is CAOS AG CCPA compliant?
According to CAOS AG's public trust center, CAOS AG is CCPA compliant. On SOC2C this listing is Listed.
Is CAOS AG SOC 2 Type I or Type II?
CAOS AG is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Answers published by CAOS AG

Reproduced from CAOS AG's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Want to report a potential security issue?
At ZITADEL we are extremely grateful for security aware people who disclose vulnerabilities to us and the open source community. All reports will be investigated by our team and we will work with you closely to validate and fix vulnerabilities reported to us. https://zitadel.com/docs/legal/policies/vulnerability-disclosure-policy We also follow RFC 9116 "A File Format to Aid in Security Vulnerability Disclosure" to find the security information for our websites and services.
Do you do regular penetration testing?
We conduct annual Penetration tests. At ZITADEL we believe that working transparently creates trust in our project and cloud service. With this mantra as one of the cornerstones of ZITADEL we actively and regularly engage with external security testers to test different scopes of our offerings. You can download the most recent reports under resources. We encourage security aware people to find and disclose vulnerabilities of our products. The process and scope can be reviewed in our vulnerability disclosure policy.
How can I get informed about security advisories?
We have set up an automated dependency management process to manage upstream dependencies of our products. The engineering team is automatically being privately notified when security issues are found. Depending on the criticality fixes are deployed in the regular release cycle, or shipped as hot-fix, published as security advisory on Github and clients are informed. Advisories are published on our Github repository: https://github.com/zitadel/zitadel/security/advisories
How can I get a bilaterally signed DPA?
Our DPA can be found in our legal section. The data processing agreement is part of our terms that you accept when you sign-up to our services. We don't provide a countersigned copy of the agreement by default. GDPR law requires a contract or legal act according to Art 28, 3.. We consider acceptance of our terms a sufficient legal act for this purpose.
Do you sign a HIPAA Business Associate Agreement (BAA)?
You can find all our certifications in our trust center. At this time, ZITADEL Cloud is not HIPAA compliant. If you want to enquire about the roadmap, please book a call to discuss your options. Since we are already compliant to some of the most strict compliance frameworks, we can provide a certification in a timely manner if a significant number of clients request HIPAA compliance.