BeyondTrust
Privileged access management vendor - Password Safe, Endpoint Privilege Management, Remote Support, Privileged Remote Access and Entitle.
Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| ISO/IEC 27001:2022 | Accredited certification body | BeyondTrust corporate and cloud Information Security Management System (ISMS), comprising 26 policies and standards. | — | Aug. 21, 2026 | Current |
| ISO/IEC 27701:2019 | Accredited certification body | Privacy Information Management System (PIMS) as an extension to the ISO/IEC 27001 certification. | — | Aug. 21, 2026 | Current |
| SOC 2 Type 2 (AWS-hosted services) | Independent third-party CPA firm | AWS-hosted products only: Entitle, Identity Security Insights, Endpoint Privilege Management for Linux, and Secure Remote Access (Remote Support and Privileged Remote Access). | — | — | Current |
| SOC 2 Type 2 (Azure-hosted services) | Independent third-party CPA firm | Azure-hosted products only: Endpoint Privilege Management Cloud and Password Safe Cloud. | — | — | Current |
| EU-US Data Privacy Framework | US Department of Commerce (self-certification) | Transfers of EU/EEA personal data to BeyondTrust in the USA. Trust centre publishes an expiration date of 24 March 2026 - RE-VERIFY, this date has passed as at the review date. | — | March 24, 2026 | Expired |
| Swiss-US Data Privacy Framework | US Department of Commerce (self-certification) | Transfers of Swiss personal data to the USA. Published expiration 24 March 2026 - RE-VERIFY on the official DPF list. | — | March 24, 2026 | Expired |
| UK Extension to the EU-US Data Privacy Framework | US Department of Commerce (self-certification) | Transfers of UK and Gibraltar personal data to the USA. Published expiration 24 March 2026 - RE-VERIFY on the official DPF list. | — | March 24, 2026 | Expired |
| FIPS 140-2 | NIST/CSE Cryptographic Module Validation Program | BeyondTrust Remote Support ONLY. Certification date April 2021. FIPS 140-2 has been superseded by FIPS 140-3; validations move to the CMVP historical list over time. | April 1, 2021 | — | Current |
| PCI DSS Level 4 (Merchant) | Approved Scanning Vendor / self-assessment | BeyondTrust as a Level 4 MERCHANT (fewer than 20,000 e-commerce card transactions per year). This is NOT a PCI DSS service-provider attestation and does not certify BeyondTrust products for storing, processing or transmitting cardholder data. | — | Jan. 27, 2027 | Current |
| Common Criteria (ISO/IEC 15408) | Common Criteria certification scheme | Protection Profile for Enterprise Security Management. Certificate date June 2018 - dated; confirm which product version and Protection Profile remain in force. | June 1, 2018 | — | Current |
| FedRAMP Moderate | FedRAMP PMO | Secure Remote Access solutions ONLY (Remote Support and Privileged Remote Access). Authorised 17 April 2024. Does not extend to Password Safe, Endpoint Privilege Management, Identity Security Insights or Entitle. | April 17, 2024 | — | Current |
| TX-RAMP Level 2 - Secure Remote Access | Texas Department of Information Resources | Privileged Remote Access and Remote Support, certified under the Secure Remote Access service offering. Certificate ID TX1230552. | — | — | Current |
| TX-RAMP Level 2 - Password Safe | Texas Department of Information Resources | BeyondTrust Password Safe. Certificate ID TX1152790. | — | — | Current |
| TX-RAMP Level 2 - Endpoint Privilege Management | Texas Department of Information Resources | BeyondTrust Endpoint Privilege Management. Certificate ID TX1152816. | — | — | Current |
| CISA Secure by Design Pledge | US Cybersecurity and Infrastructure Security Agency | Voluntary pledge signatory covering enterprise software products and services. A commitment, not an audited certification. | — | — | Current |
| VPAT / Accessibility Conformance Report (ACR) | Self-assessment against Section 508 / WCAG | Product accessibility conformance documentation published per product. | — | — | Current |
Compliance Frameworks
Penetration Testing
| Scope | Conducted By | Date | Frequency | Report |
|---|---|---|---|---|
| Penetration testing and vulnerability scanning are embedded in the secure SDLC alongside secure code review, peer review, SAST/DAST, regression, acceptance and performance testing. All development and testing is in-house; no live data in non-production. BeyondTrust also self-discovers vulnerabilities and publishes numbered advisories (e.g. BT26-03, July 2026, four internally found RS/PRA issues up to CVSS 9.2). No public third-party report or cadence. (date = profile capture date) | BeyondTrust internal Application Security team (in-house SDLC testing); no named independent penetration testing firm published | Aug. 6, 2026 | Ad-hoc | Not Available |
Data Handling
Sub-processors
| Sub-processor | Purpose | Data Location | Trust Portal |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting provider for Secure Remote Access, Identity Security Insights, Privilege Management for Linux and Entitle | Customer selection | View ↗ |
| Microsoft | Cloud hosting provider for Endpoint Privilege Management (Windows/Mac) Cloud and Password Safe Cloud | Customer selection | View ↗ |
| Salesforce | Customer Relationship Management system | USA | View ↗ |
| ServiceNow | Support services ticketing system | USA | View ↗ |
| Gainsight | Customer success tool - product experience and engagement | USA | — |
| Datadog | Login system for Entitle | USA | — |
| GitHub | CI/CD and code management platform for Entitle | USA | — |
| Slack | Communication tool for Entitle | USA | — |
| LogRocket | UI monitoring for Entitle | USA | — |
| Databricks | Data analytics platform for Identity Security Insights | USA | — |
Incident & Breach History
| Date | Summary | Impact | Resolution | Report |
|---|---|---|---|---|
| Dec. 5, 2024 | Remote Support SaaS security incident. A zero-day in a third-party application was used to reach an online asset in a BeyondTrust AWS account, from which the attacker obtained a BeyondTrust infrastructure API key. That key was used against a separate AWS account running Remote Support infrastructure, allowing access to certain Remote Support SaaS instances by resetting local application passwords. Two product zero-days were then found: CVE-2024-12356 (CVSS 9.8) and CVE-2024-12686 (CVSS 6.6). | 17 Remote Support SaaS customers involved. No BeyondTrust products outside Remote Support SaaS were affected, no FedRAMP instances were affected, no other BeyondTrust systems were compromised and ransomware was not involved. Federal law enforcement attributed the activity to a group of individuals associated with China. This incident was widely reported as the vector for intrusions at US federal agencies. | Confirmed 5 Dec 2024; incident response initiated same day, compromised API key revoked, affected instances suspended and quarantined, infrastructure quarantined for analysis, third-party forensics firm engaged. Public advisory 8 Dec; federal law enforcement notified 10 Dec; SaaS environments patched 14-15 Dec; CVE-2024-12356 and CVE-2024-12686 disclosed with patches 16 and 19 Dec. Forensic investigation completed 17 Jan 2025 finding no unauthorised access since early December. IoCs published. | Report ↗ |
Security Policies
| Policy | Availability | Link |
|---|---|---|
| ISMS Policies & Standards (26 documents) | On Request | View ↗ |
| Responsible Disclosure Policy | Public | View ↗ |
| Secure Software Development Lifecycle / Engineering Procedures | Public | View ↗ |
| Software Bill of Materials (SBOM) commitment | On Request | View ↗ |
| Business Continuity & Disaster Recovery Plan | On Request | View ↗ |
| Cloud Security Guide | On Request | View ↗ |
| Incident Response Plan | On Request | View ↗ |
| Data Processing Addendum (incl. Schedule 2 Technical & Organisational Measures) | Public | View ↗ |
| Privacy Notice | Public | View ↗ |
| Cookie Notice | Public | View ↗ |
| AI Policy | Public | View ↗ |
| Government & Law Enforcement Access Request Policy | Public | View ↗ |
Legal & Privacy
- Privacy Policy View ↗
- DPA Template View ↗
- GDPR Representative Data Protection Officer, BeyondTrust: [email protected]. HQ: BeyondTrust Corporation, 11695 Johns Creek Parkway, Suite 200, Johns Creek, GA 30097, USA. EU/UK affiliates include Avecto Ltd (UK) and Bomgar Germany GmbH.
- Lawful Basis BeyondTrust acts as processor under its customer DPA. EU transfers rely on the EU SCCs (2021/914/EU); UK transfers on the EU SCCs as integrated by the ICO International Data Transfer Addendum under s.119A DPA 2018; Swiss transfers on the EU SCCs as amended per FDPIC guidance. SCCs also cover onward transfers to sub-processors and affiliates, supported by Schedules 2 and 4 of the DPA. DPF certification is claimed but the published expiry has passed - re-verify.
Contact & Responsible Disclosure
- Security Contact [email protected]
- Responsible Disclosure View policy ↗
- Bug Bounty Platform None. BeyondTrust explicitly states it does NOT provide compensation or rewards for vulnerability discoveries. Reports go to [email protected] (PGP key provided); researchers are credited unless they request anonymity.
Trust Portal & Audit Evidence
**Trust Centre:** https://www.beyondtrust.com/trust-center
**Gated trust portal (for security reviews):** https://trustportal.beyondtrust.com
**Privacy Centre:** https://www.beyondtrust.com/privacy-center
**Publicly available without NDA**
- Industry certifications page with named scopes AND expiry dates: https://www.beyondtrust.com/trust-center/industry-certifications
- Corporate security programme and the full list of ISMS policy topics: https://www.beyondtrust.com/trust-center/security
- Cloud security, BC/DR approach, uptime SLA: https://www.beyondtrust.com/trust-center/cloud-security
- Application security, responsible disclosure, SDLC and SBOM commitment: https://www.beyondtrust.com/trust-center/application-security
- Numbered security advisories with CVEs, CVSS scores and public dates: https://www.beyondtrust.com/trust-center/security-advisories
- Sub-processor and affiliate list with corporate addresses and DPO contacts: https://www.beyondtrust.com/privacy-center/sub-processors-list
- DPA, GDPR statement, privacy FAQs, AI policy, government access request policy
- ISO 27001, ISO 27701, DPF, FIPS 140-2, Common Criteria and TX-RAMP certificates are linked directly from the certifications page
**Gated / NDA required**
- SOC 2 Type 2 reports (both AWS-hosted and Azure-hosted variants)
- ISMS policies and standards, incident response plan, BC/DR plan and test results
- Cloud Security Guide, SBOMs, penetration test evidence
**The 26 ISMS policy and standard topics published by BeyondTrust**
Access Management; Asset Management; Audit Management; Change Management; Communications Management; Configuration Management; Use of Cryptography; Data Protection; Device & Media Control; Disaster Recovery & Business Continuity Management; Endpoint Use & Endpoint Security; Exception and Approval Process; Human Resources Security Management; Incident Management; Information Lifecycle Management; Information Security Management; Logging & Monitoring Management; Network Security Management; Password & Authentication Management; Patch Management; Personal Information Management; Physical & Environmental Security Management; Risk Analysis & Management; Software Development; Third-Party Risk Management; Vulnerability Management.
**Corporate control measures published**
Pre-employment background checks globally (identity, right to work, criminal record, credit, education, drug screening); mandatory security awareness training pre-employment and annually with phishing simulations; SSO with FIDO2 MFA and least privilege; full disk encryption, EDR, web content filtering and centralised configuration management on endpoints; next-generation internet-edge firewalls; dedicated Security Operations Centre with centralised SIEM ingestion; documented incident response covering identification, containment, eradication, recovery and lessons learned.
**Gaps noted at review**
- No public master agreement or terms of service page could be located; contractual terms appear to be negotiated per customer. Only product-specific EULAs (e.g. the Discovery Tool EULA) and the customer support guide are public.
- The sub-processor page "Summary of Changes" log shows only one entry, 23 April 2024 (page publication). Either the list has not changed in over two years or changes are not being logged - ask BeyondTrust to confirm.
- No backup frequency, RTO or RPO figures published, and no published data retention periods.
Risk Assessment Notes
**Inherent risk drivers**
- BeyondTrust is a privileged access management vendor. Its products hold and broker credentials for the most privileged accounts in the estate and, in the case of Remote Support and Privileged Remote Access, provide interactive remote control of endpoints and servers. Compromise of the vendor or the product is a direct path to domain-level compromise. Treat inherent risk as **critical**.
- Remote Support / Privileged Remote Access are internet-facing by design and have a sustained record of critical vulnerabilities: CVE-2024-12356 (9.8), CVE-2025-5309 (8.6), CVE-2026-1731 (9.9) and four further high/critical issues in BT26-03 (up to 9.2) in July 2026.
- The December 2024 incident is the clearest demonstrated risk: a compromised BeyondTrust infrastructure API key allowed a China-nexus actor into 17 customers’ Remote Support SaaS instances by resetting local application passwords. This was a genuine supply-chain compromise of the PAM layer, not a theoretical one.
- Cloud products are split across AWS and Azure by product, so assurance and residency answers differ depending on which BeyondTrust product you buy.
**Mitigating factors**
- ISO/IEC 27001:2022 plus ISO/IEC 27701 PIMS certification, and two SOC 2 Type 2 reports covering the AWS- and Azure-hosted product sets.
- FedRAMP Moderate for Secure Remote Access and TX-RAMP Level 2 for three product lines - meaningful government-grade scrutiny of the highest-risk products.
- Genuinely good vulnerability transparency: numbered advisories with CVEs, CVSS scores and dates, and self-disclosure of internally discovered issues rather than waiting for researchers.
- Strong, specific incident handling in December 2024: key revoked and instances quarantined the same day the anomaly was confirmed, public advisory within three days, third-party forensics firm already on retainer, law enforcement engaged, IoCs published and a dated closure statement.
- Well-documented corporate controls: FIDO2 MFA on SSO, EDR and full disk encryption, dedicated SOC with SIEM, global background checks, annual awareness training with phishing simulation.
- Sub-processor list is unusually detailed - corporate addresses, hosting location and a named DPO contact for each - with a 30-day objection window.
**Concerns to track**
- **ISO 27001 and ISO 27701 certificates show an expiration date of 21 August 2026, roughly two weeks after this review.** Obtain the renewal certificates before relying on them.
- **All three Data Privacy Framework certifications show a published expiration of 24 March 2026, which has already passed.** Verify BeyondTrust’s current status on the official DPF list; if lapsed, the SCC route in the DPA is the operative transfer mechanism.
- **PCI DSS is Level 4 MERCHANT compliance only.** It says nothing about the products’ suitability for cardholder data environments. Do not let this appear as "PCI DSS certified" in a risk register without that qualifier.
- FIPS 140-2 covers **Remote Support only** and dates from April 2021; FIPS 140-2 is superseded by 140-3. Common Criteria dates from June 2018. Both are stale.
- FedRAMP Moderate and each TX-RAMP certificate are product-specific. Do not credit them across the portfolio.
- No named third-party penetration testing firm, no published external testing cadence and no pen test report - testing is described as part of the in-house SDLC. This is weaker than every other vendor currently in this library.
- No published backup frequency, RTO, RPO or data retention periods. The 99.9% uptime SLA is stated but RTO/RPO explicitly "may vary".
- No bug bounty and no researcher rewards, which may reduce external vulnerability discovery relative to peers.
- Sub-processor change log has not been updated since the page was published in April 2024.
- Entitle (acquired) introduces a distinct sub-processor set (Datadog, GitHub, Slack, LogRocket) and an Israeli affiliate, Entitle Inc.
**Residual customer responsibilities**
- Patch self-hosted appliances promptly and enable "Apply Critical Updates Automatically" in the /appliance interface. The December 2024 guidance makes clear self-hosted customers own their own patching.
- Prefer external SAML authentication over local application accounts, and delete unused accounts - local password reset was the exact mechanism abused in the 2024 incident.
- Integrate session data and configuration/authentication events into your own SIEM via syslog or middleware and review them; do not rely on vendor-side detection.
- Apply least privilege to user roles, capabilities and endpoint access; use the Session Policy simulator to validate policies.
- Periodically review all active accounts, especially admins, deactivate unused ones and rotate passwords.
- Enable network restrictions and outbound event notifications where possible.
- Confirm your hosting region per product and obtain the SOC 2 report matching your hosting platform.
- Execute the DPA and confirm the current transfer mechanism given the DPF expiry.
**Suggested review cadence:** semi-annual reassessment rather than annual, given the criticality of the PAM layer and the frequency of critical CVEs. Subscribe to the advisories page and treat any critical Remote Support or Privileged Remote Access advisory as an immediate out-of-cycle trigger. Re-check the ISO and DPF certificate status before the next assessment closes.
Copyright © 2026 SnapGRC