Is this your company? Buyers are checking CAOS AG here. Claim zitadel.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
CAOS AG
Sourced from public information. Not yet verified by the company.
CAOS AG is SOC 2 Type II compliant. CAOS AG also holds ISO 27001, GDPR, and CCPA.
About
Welcome to ZITADEL's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation. For security reports, please consult our [security.txt](https://zitadel.com/.well-known/security.txt) how to get in touch and report vulnerabilities. Useful resources: * [Data Processing Agreement](https://zitadel.com/docs/legal/data-processing-agreement) * [Legal Center](https://zitadel.com/legal) * [legal@zitadel.com](mailto:legal@zitadel.com) for legal and complian
Compliance & infrastructure
Subprocessors
3- GGoogle Cloud Platform · [Zitadel Cloud] Cloud providerDesignated by customer
- PPostmark (AC PM LLC) · [Zitadel Cloud] Transactional emails (Optional)USA
- TTwillio Inc. · [Zitadel Cloud] Communication (Optional)USA
Compliance leadership
The person who leads CAOS AG's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. CAOS AG's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
Updated Privacy Policy and Sub-ProcessorsOct 2025
Privacy Policy We've updated the Zitadel's Privacy Policy to align with the Data Privacy Framework (DPF) principles, a change approved by the U.S. Department of Commerce. This update ensures stronger privacy protections for data transfers from the EU/EEA, UK, and Switzerland to the U.S. and is now reflected in our policy. Zitadel has completed the necessary self-certification and is registered for an independent recourse mechanism (JAMS) to resolve complaints. Key changes: * Zitadel complies with the EU-U.S. DPF and the Swiss-U.S. DPF as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal data transferred from the European Union, European Economic Area, and Switzerland to the United States. The policy now details our commitment to effective recourse, enforcement, and liability under the DPF. We utilize JAMS (Judicial Arbitration and Mediation Services) as our independent recourse mechanism (IDR) and detail the conditions for binding arbitration as a means of dispute resolution. * Zitadel's HQ address has been updated. * We've removed explicit listings of analytics providers. The policy now links to our sub-processor list. Sub-Processors * Removed Posthog, Inc. * Added Mixpanel for Data Analytics
This listing is partial
6/11 details · 55%SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is CAOS AG SOC 2 compliant?
Is CAOS AG ISO 27001 certified?
Is CAOS AG GDPR compliant?
Is CAOS AG CCPA compliant?
Is CAOS AG SOC 2 Type I or Type II?
Can I use CAOS AG's SOC 2 for a vendor risk assessment?
Is CAOS AG penetration tested?
Is CAOS AG secure?
Does CAOS AG have a bug bounty or vulnerability disclosure program?
Who are CAOS AG's subprocessors?
Where does CAOS AG host or store data?
Where is CAOS AG's trust center or security page?
Want to report a potential security issue?
Do you do regular penetration testing?
How can I get informed about security advisories?
How can I get a bilaterally signed DPA?
Do you sign a HIPAA Business Associate Agreement (BAA)?
Is there a compliance roadmap addressing upcoming regulations?
Do you provide the ISO27001 Certificate?
Is Zitadel compliant to BSI Cloud Computing Compliance Criteria Catalogue (C5)?
How do you protect against bot and DDoS attacks?
Do you encrypt all backups and store them in a secure location that is physically separated from the production environment?
What third party analytics tools are being used?
Technology peers that completed SOC 2

Action1

ELJUN LLC

equipifi
