BeyondTrust

Cybersecurity United States Website Reviewed Aug. 6, 2026

Privileged access management vendor - Password Safe, Endpoint Privilege Management, Remote Support, Privileged Remote Access and Entitle.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 Accredited certification body BeyondTrust corporate and cloud Information Security Management System (ISMS), comprising 26 policies and standards. Aug. 21, 2026 Current
ISO/IEC 27701:2019 Accredited certification body Privacy Information Management System (PIMS) as an extension to the ISO/IEC 27001 certification. Aug. 21, 2026 Current
SOC 2 Type 2 (AWS-hosted services) Independent third-party CPA firm AWS-hosted products only: Entitle, Identity Security Insights, Endpoint Privilege Management for Linux, and Secure Remote Access (Remote Support and Privileged Remote Access). Current
SOC 2 Type 2 (Azure-hosted services) Independent third-party CPA firm Azure-hosted products only: Endpoint Privilege Management Cloud and Password Safe Cloud. Current
EU-US Data Privacy Framework US Department of Commerce (self-certification) Transfers of EU/EEA personal data to BeyondTrust in the USA. Trust centre publishes an expiration date of 24 March 2026 - RE-VERIFY, this date has passed as at the review date. March 24, 2026 Expired
Swiss-US Data Privacy Framework US Department of Commerce (self-certification) Transfers of Swiss personal data to the USA. Published expiration 24 March 2026 - RE-VERIFY on the official DPF list. March 24, 2026 Expired
UK Extension to the EU-US Data Privacy Framework US Department of Commerce (self-certification) Transfers of UK and Gibraltar personal data to the USA. Published expiration 24 March 2026 - RE-VERIFY on the official DPF list. March 24, 2026 Expired
FIPS 140-2 NIST/CSE Cryptographic Module Validation Program BeyondTrust Remote Support ONLY. Certification date April 2021. FIPS 140-2 has been superseded by FIPS 140-3; validations move to the CMVP historical list over time. April 1, 2021 Current
PCI DSS Level 4 (Merchant) Approved Scanning Vendor / self-assessment BeyondTrust as a Level 4 MERCHANT (fewer than 20,000 e-commerce card transactions per year). This is NOT a PCI DSS service-provider attestation and does not certify BeyondTrust products for storing, processing or transmitting cardholder data. Jan. 27, 2027 Current
Common Criteria (ISO/IEC 15408) Common Criteria certification scheme Protection Profile for Enterprise Security Management. Certificate date June 2018 - dated; confirm which product version and Protection Profile remain in force. June 1, 2018 Current
FedRAMP Moderate FedRAMP PMO Secure Remote Access solutions ONLY (Remote Support and Privileged Remote Access). Authorised 17 April 2024. Does not extend to Password Safe, Endpoint Privilege Management, Identity Security Insights or Entitle. April 17, 2024 Current
TX-RAMP Level 2 - Secure Remote Access Texas Department of Information Resources Privileged Remote Access and Remote Support, certified under the Secure Remote Access service offering. Certificate ID TX1230552. Current
TX-RAMP Level 2 - Password Safe Texas Department of Information Resources BeyondTrust Password Safe. Certificate ID TX1152790. Current
TX-RAMP Level 2 - Endpoint Privilege Management Texas Department of Information Resources BeyondTrust Endpoint Privilege Management. Certificate ID TX1152816. Current
CISA Secure by Design Pledge US Cybersecurity and Infrastructure Security Agency Voluntary pledge signatory covering enterprise software products and services. A commitment, not an audited certification. Current
VPAT / Accessibility Conformance Report (ACR) Self-assessment against Section 508 / WCAG Product accessibility conformance documentation published per product. Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
ISMS certified to ISO/IEC 27001:2022. Certificate on the trust centre shows an expiration date of 21 August 2026 - confirm the renewal certificate.
SOC 2 Type 2
Full
Two separate SOC 2 Type 2 reports split by hosting platform (AWS-hosted and Azure-hosted products). Check that the report you receive covers the specific product you are buying.
ISO 22301:2019
Partial
BC/DR plans are stated to be ALIGNED to ISO 22301 but certified and audited under ISO 27001 and SOC 2 Type II rather than separately certified to ISO 22301. Tested annually and approved by the Executive Leadership Team.
GDPR 2016/679
Full
Customer DPA incorporates EU SCCs (2021/914/EU), the ICO IDTA for UK data and FDPIC-amended SCCs for Swiss data. ISO/IEC 27701 PIMS certified. DPF certification published but its expiry date has passed - re-verify.
PCI DSS v4.0
Partial
PCI DSS Level 4 MERCHANT compliance only, expiring 27 January 2027. There is no PCI DSS service-provider Attestation of Compliance; do not treat BeyondTrust products as in-scope PCI certified components without your own assessment.
NIST Cybersecurity Framework
Partial
NIST 800-53 / CSF alignment is inherited from the FedRAMP Moderate authorisation, which covers only the Secure Remote Access products. No standalone NIST CSF attestation is published.
ISO 27002
Partial
ISO 27002 control alignment inherited from the ISO/IEC 27001:2022 and ISO/IEC 27701 certifications rather than separately attested.

Penetration Testing

Scope Conducted By Date Frequency Report
Penetration testing and vulnerability scanning are embedded in the secure SDLC alongside secure code review, peer review, SAST/DAST, regression, acceptance and performance testing. All development and testing is in-house; no live data in non-production. BeyondTrust also self-discovers vulnerabilities and publishes numbered advisories (e.g. BT26-03, July 2026, four internally found RS/PRA issues up to CVSS 9.2). No public third-party report or cadence. (date = profile capture date) BeyondTrust internal Application Security team (in-house SDLC testing); no named independent penetration testing firm published Aug. 6, 2026 Ad-hoc Not Available

Data Handling

Data Residency Regions
Customer-selectable hosting region per product. Published locations include USA, Canada, Europe, UK, Japan, India, South America and Australia. AWS hosts Secure Remote Access, Identity Security Insights, Privilege Management for Linux and Entitle; Azure hosts Endpoint Privilege Management (Win/Mac) Cloud and Password Safe Cloud. Availability differs per product - check the Technical Documentation. Locations are geographically dispersed with replication, mirroring and geo-redundant storage.
Encryption at Rest
Yes — BeyondTrust states customer data is encrypted at rest for storage purposes and that products are configurable to meet data-at-rest requirements. Specific algorithms and key management are not published publicly - request the Trust Portal documentation and Schedule 2 of the DPA (Technical and Organisational Measures).
Encryption in Transit
Yes — Secure communications using HTTPS/SSL/TLS for web-based communication and data collection; customer data encrypted during transmission. Corporate access uses SSO with mandatory FIDO2 multi-factor authentication.
Backup Frequency
Not published. DR uses replication, mirroring and geo-redundant storage; DR testing on a scheduled basis and BC/DR plans tested annually. Uptime SLA 99.9% on AWS and Azure. RTO and RPO explicitly stated to vary by incident and are not published.
Retention Policy
Data Deletion
No specific retention periods are published. The Privacy FAQ states data is kept only as long as necessary for the purposes collected, considering volume, nature and sensitivity, risk of harm, processing purpose and legal requirements. Deletion and access rights are exercised via [email protected] with a one-month response commitment. GAP: obtain concrete retention and deletion periods per product in writing during assessment.

Sub-processors

Sub-processor Purpose Data Location Trust Portal
Amazon Web Services (AWS) Cloud hosting provider for Secure Remote Access, Identity Security Insights, Privilege Management for Linux and Entitle Customer selection View ↗
Microsoft Cloud hosting provider for Endpoint Privilege Management (Windows/Mac) Cloud and Password Safe Cloud Customer selection View ↗
Salesforce Customer Relationship Management system USA View ↗
ServiceNow Support services ticketing system USA View ↗
Gainsight Customer success tool - product experience and engagement USA
Datadog Login system for Entitle USA
GitHub CI/CD and code management platform for Entitle USA
Slack Communication tool for Entitle USA
LogRocket UI monitoring for Entitle USA
Databricks Data analytics platform for Identity Security Insights USA

Incident & Breach History

Date Summary Impact Resolution Report
Dec. 5, 2024 Remote Support SaaS security incident. A zero-day in a third-party application was used to reach an online asset in a BeyondTrust AWS account, from which the attacker obtained a BeyondTrust infrastructure API key. That key was used against a separate AWS account running Remote Support infrastructure, allowing access to certain Remote Support SaaS instances by resetting local application passwords. Two product zero-days were then found: CVE-2024-12356 (CVSS 9.8) and CVE-2024-12686 (CVSS 6.6). 17 Remote Support SaaS customers involved. No BeyondTrust products outside Remote Support SaaS were affected, no FedRAMP instances were affected, no other BeyondTrust systems were compromised and ransomware was not involved. Federal law enforcement attributed the activity to a group of individuals associated with China. This incident was widely reported as the vector for intrusions at US federal agencies. Confirmed 5 Dec 2024; incident response initiated same day, compromised API key revoked, affected instances suspended and quarantined, infrastructure quarantined for analysis, third-party forensics firm engaged. Public advisory 8 Dec; federal law enforcement notified 10 Dec; SaaS environments patched 14-15 Dec; CVE-2024-12356 and CVE-2024-12686 disclosed with patches 16 and 19 Dec. Forensic investigation completed 17 Jan 2025 finding no unauthorised access since early December. IoCs published. Report ↗

Security Policies

Policy Availability Link
ISMS Policies & Standards (26 documents) On Request View ↗
Responsible Disclosure Policy Public View ↗
Secure Software Development Lifecycle / Engineering Procedures Public View ↗
Software Bill of Materials (SBOM) commitment On Request View ↗
Business Continuity & Disaster Recovery Plan On Request View ↗
Cloud Security Guide On Request View ↗
Incident Response Plan On Request View ↗
Data Processing Addendum (incl. Schedule 2 Technical & Organisational Measures) Public View ↗
Privacy Notice Public View ↗
Cookie Notice Public View ↗
AI Policy Public View ↗
Government & Law Enforcement Access Request Policy Public View ↗

Contact & Responsible Disclosure

Trust Portal & Audit Evidence

**Trust Centre:** https://www.beyondtrust.com/trust-center
**Gated trust portal (for security reviews):** https://trustportal.beyondtrust.com
**Privacy Centre:** https://www.beyondtrust.com/privacy-center

**Publicly available without NDA**
- Industry certifications page with named scopes AND expiry dates: https://www.beyondtrust.com/trust-center/industry-certifications
- Corporate security programme and the full list of ISMS policy topics: https://www.beyondtrust.com/trust-center/security
- Cloud security, BC/DR approach, uptime SLA: https://www.beyondtrust.com/trust-center/cloud-security
- Application security, responsible disclosure, SDLC and SBOM commitment: https://www.beyondtrust.com/trust-center/application-security
- Numbered security advisories with CVEs, CVSS scores and public dates: https://www.beyondtrust.com/trust-center/security-advisories
- Sub-processor and affiliate list with corporate addresses and DPO contacts: https://www.beyondtrust.com/privacy-center/sub-processors-list
- DPA, GDPR statement, privacy FAQs, AI policy, government access request policy
- ISO 27001, ISO 27701, DPF, FIPS 140-2, Common Criteria and TX-RAMP certificates are linked directly from the certifications page

**Gated / NDA required**
- SOC 2 Type 2 reports (both AWS-hosted and Azure-hosted variants)
- ISMS policies and standards, incident response plan, BC/DR plan and test results
- Cloud Security Guide, SBOMs, penetration test evidence

**The 26 ISMS policy and standard topics published by BeyondTrust**
Access Management; Asset Management; Audit Management; Change Management; Communications Management; Configuration Management; Use of Cryptography; Data Protection; Device & Media Control; Disaster Recovery & Business Continuity Management; Endpoint Use & Endpoint Security; Exception and Approval Process; Human Resources Security Management; Incident Management; Information Lifecycle Management; Information Security Management; Logging & Monitoring Management; Network Security Management; Password & Authentication Management; Patch Management; Personal Information Management; Physical & Environmental Security Management; Risk Analysis & Management; Software Development; Third-Party Risk Management; Vulnerability Management.

**Corporate control measures published**
Pre-employment background checks globally (identity, right to work, criminal record, credit, education, drug screening); mandatory security awareness training pre-employment and annually with phishing simulations; SSO with FIDO2 MFA and least privilege; full disk encryption, EDR, web content filtering and centralised configuration management on endpoints; next-generation internet-edge firewalls; dedicated Security Operations Centre with centralised SIEM ingestion; documented incident response covering identification, containment, eradication, recovery and lessons learned.

**Gaps noted at review**
- No public master agreement or terms of service page could be located; contractual terms appear to be negotiated per customer. Only product-specific EULAs (e.g. the Discovery Tool EULA) and the customer support guide are public.
- The sub-processor page "Summary of Changes" log shows only one entry, 23 April 2024 (page publication). Either the list has not changed in over two years or changes are not being logged - ask BeyondTrust to confirm.
- No backup frequency, RTO or RPO figures published, and no published data retention periods.

Risk Assessment Notes

**Inherent risk drivers**
- BeyondTrust is a privileged access management vendor. Its products hold and broker credentials for the most privileged accounts in the estate and, in the case of Remote Support and Privileged Remote Access, provide interactive remote control of endpoints and servers. Compromise of the vendor or the product is a direct path to domain-level compromise. Treat inherent risk as **critical**.
- Remote Support / Privileged Remote Access are internet-facing by design and have a sustained record of critical vulnerabilities: CVE-2024-12356 (9.8), CVE-2025-5309 (8.6), CVE-2026-1731 (9.9) and four further high/critical issues in BT26-03 (up to 9.2) in July 2026.
- The December 2024 incident is the clearest demonstrated risk: a compromised BeyondTrust infrastructure API key allowed a China-nexus actor into 17 customers’ Remote Support SaaS instances by resetting local application passwords. This was a genuine supply-chain compromise of the PAM layer, not a theoretical one.
- Cloud products are split across AWS and Azure by product, so assurance and residency answers differ depending on which BeyondTrust product you buy.

**Mitigating factors**
- ISO/IEC 27001:2022 plus ISO/IEC 27701 PIMS certification, and two SOC 2 Type 2 reports covering the AWS- and Azure-hosted product sets.
- FedRAMP Moderate for Secure Remote Access and TX-RAMP Level 2 for three product lines - meaningful government-grade scrutiny of the highest-risk products.
- Genuinely good vulnerability transparency: numbered advisories with CVEs, CVSS scores and dates, and self-disclosure of internally discovered issues rather than waiting for researchers.
- Strong, specific incident handling in December 2024: key revoked and instances quarantined the same day the anomaly was confirmed, public advisory within three days, third-party forensics firm already on retainer, law enforcement engaged, IoCs published and a dated closure statement.
- Well-documented corporate controls: FIDO2 MFA on SSO, EDR and full disk encryption, dedicated SOC with SIEM, global background checks, annual awareness training with phishing simulation.
- Sub-processor list is unusually detailed - corporate addresses, hosting location and a named DPO contact for each - with a 30-day objection window.

**Concerns to track**
- **ISO 27001 and ISO 27701 certificates show an expiration date of 21 August 2026, roughly two weeks after this review.** Obtain the renewal certificates before relying on them.
- **All three Data Privacy Framework certifications show a published expiration of 24 March 2026, which has already passed.** Verify BeyondTrust’s current status on the official DPF list; if lapsed, the SCC route in the DPA is the operative transfer mechanism.
- **PCI DSS is Level 4 MERCHANT compliance only.** It says nothing about the products’ suitability for cardholder data environments. Do not let this appear as "PCI DSS certified" in a risk register without that qualifier.
- FIPS 140-2 covers **Remote Support only** and dates from April 2021; FIPS 140-2 is superseded by 140-3. Common Criteria dates from June 2018. Both are stale.
- FedRAMP Moderate and each TX-RAMP certificate are product-specific. Do not credit them across the portfolio.
- No named third-party penetration testing firm, no published external testing cadence and no pen test report - testing is described as part of the in-house SDLC. This is weaker than every other vendor currently in this library.
- No published backup frequency, RTO, RPO or data retention periods. The 99.9% uptime SLA is stated but RTO/RPO explicitly "may vary".
- No bug bounty and no researcher rewards, which may reduce external vulnerability discovery relative to peers.
- Sub-processor change log has not been updated since the page was published in April 2024.
- Entitle (acquired) introduces a distinct sub-processor set (Datadog, GitHub, Slack, LogRocket) and an Israeli affiliate, Entitle Inc.

**Residual customer responsibilities**
- Patch self-hosted appliances promptly and enable "Apply Critical Updates Automatically" in the /appliance interface. The December 2024 guidance makes clear self-hosted customers own their own patching.
- Prefer external SAML authentication over local application accounts, and delete unused accounts - local password reset was the exact mechanism abused in the 2024 incident.
- Integrate session data and configuration/authentication events into your own SIEM via syslog or middleware and review them; do not rely on vendor-side detection.
- Apply least privilege to user roles, capabilities and endpoint access; use the Session Policy simulator to validate policies.
- Periodically review all active accounts, especially admins, deactivate unused ones and rotate passwords.
- Enable network restrictions and outbound event notifications where possible.
- Confirm your hosting region per product and obtain the SOC 2 report matching your hosting platform.
- Execute the DPA and confirm the current transfer mechanism given the DPF expiry.

**Suggested review cadence:** semi-annual reassessment rather than annual, given the criticality of the PAM layer and the frequency of critical CVEs. Subscribe to the advisories page and treat any critical Remote Support or Privileged Remote Access advisory as an immediate out-of-cycle trigger. Re-check the ISO and DPF certificate status before the next assessment closes.

Assess BeyondTrust in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.