Okta
Independent identity provider (Okta Workforce Identity Cloud and Auth0 Customer Identity) for SSO, MFA, IGA and PAM.
Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| SOC 1 Type 2 | Independent third-party auditor | Okta Workforce Identity Cloud, Customer Identity and Auth0 platforms. Report available under NDA via the Okta Security Trust Center. | — | — | Current |
| SOC 2 Type 2 | Independent third-party auditor | Okta Workforce Identity Cloud, Customer Identity Solution and Auth0 platforms. Covers security, availability and confidentiality. Report under NDA. | — | — | Current |
| SOC 3 | Independent third-party auditor | Public-facing summary report for the Okta and Auth0 platforms. | — | — | Current |
| ISO/IEC 27001:2022 | Accredited certification body | Okta information security management system covering the Okta and Auth0 services. | — | — | Current |
| ISO/IEC 27017:2015 | Accredited certification body | Cloud-specific information security controls for the Okta services. | — | — | Current |
| ISO/IEC 27018:2019 | Accredited certification body | Protection of personally identifiable information in public cloud acting as a PII processor. | — | — | Current |
| CSA STAR Level 1 (CAIQ Self-Assessment) | Cloud Security Alliance | Self-assessment published to the CSA STAR registry; CAIQ also available from the trust centre. | — | — | Current |
| CSA STAR Level 2 (Certification) | Cloud Security Alliance / accredited auditor | Third-party audited CSA STAR Level 2 certification for the Okta cloud services. | — | — | Current |
| CSA Trusted Cloud Provider | Cloud Security Alliance | Trust mark recognising CSA membership and demonstrated cloud security practice. | — | — | Current |
| FedRAMP High | FedRAMP PMO / JAB | Okta for Government High and Okta US Military subscriptions only. Not the commercial Okta cell. | — | — | Current |
| FedRAMP Moderate | FedRAMP PMO | Okta for Government Moderate subscriptions only. | — | — | Current |
| DoD Impact Level 5 (IL5) | US Department of Defense / DISA | Okta US Military offering. Not applicable to commercial subscriptions. | — | — | Current |
| GovRAMP (formerly StateRAMP) | GovRAMP | US state and local government offering. | — | — | Current |
| IRAP Assessment (PROTECTED) | ASD-endorsed IRAP assessor | Australian Government IRAP assessment; IRAP Protected documentation available via the trust centre. | — | — | Current |
| BSI C5 | Independent third-party auditor | German Cloud Computing Compliance Criteria Catalogue attestation for the Okta cloud services. | — | — | Current |
| PCI DSS v4.0.0 | Qualified Security Assessor (QSA) | Okta as a service provider; Attestation of Compliance available under NDA. | — | — | Current |
| FIPS 140-2 | NIST/CSE Cryptographic Module Validation Program | Validated cryptographic modules used within the Okta service. | — | — | Current |
| TISAX | ENX Association / accredited audit provider | Automotive industry information security assessment exchange label. | — | — | Current |
| EU Cloud Code of Conduct | SCOPE Europe (monitoring body) | GDPR Article 40 code of conduct adherence; public report of adherence published by Okta. | — | — | Current |
| ST4S (Safer Technologies 4 Schools) | Education Services Australia | Australian schools sector safety, privacy and security assessment badge. | — | — | Current |
Compliance Frameworks
Penetration Testing
| Scope | Conducted By | Date | Frequency | Report |
|---|---|---|---|---|
| Annual third-party penetration testing of the Okta and Auth0 production services, plus continuous internal penetration testing of source code and production security controls including OWASP-specific flaws. Customers may also run their own penetration tests against their tenant with prior approval. (date shown is the profile capture date) | Independent third-party testing firms plus Okta internal penetration testing team | Aug. 6, 2026 | Annual | On NDA |
Data Handling
Sub-processors
| Sub-processor | Purpose | Data Location | Trust Portal |
|---|---|---|---|
| Amazon Web Services (AWS) | Primary hosting and cloud infrastructure for Workforce/Customer Identity, Auth0, Identity Security Posture Management and Okta for Government | USA, Canada, India, Germany, Ireland, Australia, Japan (plus extensive Auth0 private-cloud regions) | View ↗ |
| Google, Inc. | Cyber defence (threat detection, investigation and response); hosting for Access Governance and Okta Privileged Access; non-training generative AI for Log Investigator | USA, Canada, India, Germany, Belgium, Australia, Japan, EMEA | View ↗ |
| Microsoft | Hosting and cloud infrastructure - Azure regional failover for Auth0 public cloud (Canada, Japan, Australia) and Auth0 private cloud regions | USA, Canada, Brazil, Ireland, Netherlands, France, Switzerland, Norway, Germany, Sweden, South Africa, UAE, UK, India, South Korea, Australia, Japan | View ↗ |
| Splunk, Inc. | Business analytics and log analysis | USA, Germany, Ireland, United Kingdom | — |
| Salesforce, Inc. (salesforce.com, inc.) | Support and maintenance ticketing process (Okta Help Center) | USA | View ↗ |
| Twilio, Inc. | SMS authenticator delivery | USA | — |
| SendGrid, Inc. | Email notifications and email access request inbox | USA | — |
| TeleSign Corporation | SMS authenticator delivery | USA, Netherlands | — |
| Snowflake Computing, Inc. / Snowflake Computing Netherlands B.V. | Data warehouse services | USA, Canada, India, Germany, Australia, Japan | — |
| MongoDB, Inc. | Managed database services for Access Governance, Okta Privileged Access, ISPM and Auth0 | USA, Canada, India, Germany, Belgium, Netherlands, Australia, Japan | — |
| Datadog, Inc. | Business analytics for Access Governance, Advanced Server Access, Okta Privileged Access and Auth0 | USA, Germany | — |
| Cloudflare, Inc. | Content delivery network and DDoS prevention for the Auth0 platform (may process data in any country by design) | Global | View ↗ |
| Aiven Ltd | Managed database services for Auth0 | Corresponds to the customer-selected AWS or Azure region | — |
| S.C. Computer Generated Solutions Romania S.R.L. (subsidiary of Computer Generated Solutions, Inc., USA) | 24x7 outsourced customer support team; may access AWS and Salesforce data centres Okta uses while providing support | No data centres; support team located in Romania (USA for Government Moderate) | — |
| Sentry | Security event analysis and incident response for Identity Security Posture Management | USA, Germany | — |
| Slack Technologies, LLC | Messaging and collaboration for Identity Security Posture Management | USA | — |
Incident & Breach History
| Date | Summary | Impact | Resolution | Report |
|---|---|---|---|---|
| Oct. 20, 2023 | Unauthorised access to the Okta Help Center (support case management system). A threat actor used stolen credentials to access the support case management system and viewed HTTP Archive (HAR) files uploaded by customers during troubleshooting, which could contain session tokens. | Okta stated its production identity service was not impacted. A subset of support customers were affected and received a customised impact report; indicators of compromise were published and regulators and law enforcement were notified. | RCA published 3 Nov 2023; recommended actions 29 Nov 2023. Independent forensic firm Stroz Friedberg confirmed no malicious activity beyond Okta’s own findings; investigation closed 8 Feb 2024. Okta hardened the Help Center, changed admin access provisioning and that system’s retention policy, and shipped Zero Standing Privileges for admins, MFA for protected admin actions, anonymiser blocking, IP binding and API network zone allowlisting. | Report ↗ |
Security Policies
| Policy | Availability | Link |
|---|---|---|
| Information Security Policy | On Request | View ↗ |
| Access Control Policy | On Request | View ↗ |
| Acceptable Use Policy | On Request | View ↗ |
| AI Governance | Public | View ↗ |
| Business Continuity Plan + DR Attestation | On Request | View ↗ |
| Cyber Security Incident Response Plan | On Request | View ↗ |
| Data Classification and Handling Standard | On Request | View ↗ |
| Endpoint Security Standard | On Request | View ↗ |
| Engineering Release Management Procedure | On Request | View ↗ |
| Okta Control Library | On Request | View ↗ |
| Physical Security Policy | On Request | View ↗ |
| Risk Assessment / Management Policy | On Request | View ↗ |
| Vulnerability Reporting Policy | Public | View ↗ |
Legal & Privacy
- Privacy Policy View ↗
- DPA Template View ↗
- Terms of Service View ↗
- GDPR Representative Okta, Inc., 100 First Street, Sixth Floor, San Francisco, CA 94105 USA (Attn: Legal Department). EU/UK affiliates include Okta Identity Ireland Ltd and Okta UK Ltd. Confirm the named Art. 27 representative in the current privacy policy.
- Lawful Basis Okta acts as processor for customer Personal Data under its global DPA, incorporating the June 2021 EU SCCs (controller-to-processor and processor-to-processor modules) with Annexes I and II. Further transfer mechanisms: EU-US DPF, Swiss-US DPF, UK Extension, EU Cloud Code of Conduct (monitored by SCOPE Europe) and Global PRP/APEC certifications. A BAA is available for HIPAA. Okta publishes a Government Request Transparency Report and Government Authority Data Request Policy.
Contact & Responsible Disclosure
- Security Contact [email protected]
- Responsible Disclosure View policy ↗
- Bug Bounty Platform Bugcrowd - public programmes at https://bugcrowd.com/okta and https://bugcrowd.com/auth0-okta, plus private bug bounty programmes and a customer bug reporting programme.
Trust Portal & Audit Evidence
**Primary trust portal:** https://security.okta.com (SafeBase) - reached from https://trust.okta.com. Public status and availability: https://status.okta.com (trust page reports 12-month availability of 99.99%, averaged across incidents affecting at least 10% of customers).
**Publicly available without NDA**
- Full compliance badge list, control descriptions and policy summaries on the trust centre landing page
- SOC 3 report (public summary)
- Sub-processor list: https://www.okta.com/en-gb/legal/trustandcompliance/subprocessors/
- Data Processing Addendum, SCCs, Information Security Addendum, Business Associate Agreement, Government Request Transparency Report, Modern Slavery statement, EU Cloud Code of Conduct public report of adherence and AI Model Cards: https://www.okta.com/trustandcompliance/
- Vulnerability Reporting Policy and Bugcrowd programmes
- Security advisories and RSS: https://trust.okta.com/security-advisories/
- Security blog: https://sec.okta.com
**Gated behind trust-centre access request / NDA**
- SOC 1 and SOC 2 Type 2 reports
- ISO 27001 / 27017 / 27018 certificates
- CSA STAR Level 2 certification, CAIQ, HECVAT, MVSP
- IRAP Protected documentation, ENS (Royal Decree 311/2022) report, PCI DSS AoC
- Penetration test reports and the Okta FastPass Assessor’s Report
- Information Security Policy, Okta Control Library, BCP/DR attestation, incident response plan, endpoint security standard, release management procedure
**Additional trust-centre claims recorded here but not held as separate certificates:** CISA Secure-by-Design Pledge signatory, NIST 800-53 Rev. 5 (via FedRAMP), EU-US / Swiss-US DPF and UK Extension, GDPR, HIPAA, DORA, ENS, APEC/Global CBPR and PRP, ProcessUnity and TruSight questionnaire participation, VPAT accessibility conformance.
**Other notes**
- Okta runs a "Pooled Security Audits" programme allowing customers to share audit effort - see https://sec.okta.com/articles/pooledauditretro/
- Customers should set a Primary Security Contact and CIO/CISO contact in the Okta Help Center so Okta can alert them to organisation-specific threats.
- Sub-processor change notifications are opt-in by emailing [email protected] with an executed DPA; customers have 10 business days to object.
Risk Assessment Notes
**Inherent risk drivers**
- Okta is an identity provider and therefore a single point of authentication for every downstream application it fronts. Compromise of the Okta tenant is effectively compromise of the whole estate, so inherent risk should be treated as **critical** regardless of the data volume held.
- Holds authentication credentials, MFA factors, session tokens, directory attributes and detailed sign-in telemetry.
- Highly attractive target: Okta has been the subject of two widely reported supply-chain style incidents (the January 2022 Lapsus$/Sitel third-party support compromise and the October 2023 Help Center incident recorded above).
- Long fourth-party chain. Okta depends on AWS, Google and Microsoft Azure for hosting, plus Twilio, TeleSign and SendGrid for out-of-band authentication delivery - meaning MFA availability depends on third-party telecom providers.
- Outsourced 24x7 support in Romania (CGS) with potential access to production support data. This was the risk pattern behind the 2022 incident.
**Mitigating factors**
- Very broad and independently audited assurance set: SOC 1/2/3, ISO 27001/27017/27018, CSA STAR Level 2, BSI C5, PCI DSS v4.0.0, IRAP, FedRAMP High and Moderate, DoD IL5, GovRAMP, TISAX, EU Cloud Code of Conduct and FIPS 140-2 validated crypto.
- Per-tenant encryption keys at rest and TLS with PFS and HSTS in transit.
- Public, dated and product-segmented sub-processor list with an opt-in notification and objection process - materially better transparency than most vendors in this library.
- Annual third-party penetration testing plus a continuous internal penetration testing team and two public Bugcrowd programmes.
- Quarterly DR testing with regional and geographic DR capacity; BCP/DR and incident response attested within SOC 2 Type II.
- Demonstrated incident transparency: root cause analysis, recommended actions, independent forensic review by Stroz Friedberg and published closure.
- Concrete product hardening delivered after 2023 (Zero Standing Privileges for admins, MFA for protected admin actions, IP binding, API network zone allowlisting, anonymiser blocking) and the ongoing Okta Secure Identity Commitment.
**Concerns to track**
- Verify which cell your tenant is in. Data residency, and which sub-processors apply, differ per cell and per SKU - EU cell data can still flow to US-hosted Splunk, Datadog or Google depending on the service.
- FedRAMP High, FedRAMP Moderate, DoD IL5 and GovRAMP apply **only** to Okta for Government / US Military subscriptions. Do not credit these to a commercial tenant.
- Retention periods are in separate Okta and Auth0 Data Retention Policy documents and vary by product and log type; confirm actual figures rather than assuming.
- CDN processing for Auth0 via Cloudflare is explicitly global and cannot be pinned to a region.
- MFA delivered by SMS depends on Twilio/TeleSign; prefer phishing-resistant factors (Okta FastPass, WebAuthn) to reduce both security and third-party availability risk.
- Most substantive evidence (SOC 2, ISO certificates, pen test reports, ISMS policies) requires an NDA and a trust-centre access request - budget time for this in the assessment.
**Residual customer responsibilities**
- Configure and enforce phishing-resistant MFA, admin role scoping, Zero Standing Privileges, session and IP binding, Dynamic Zones and API network zone allowlisting. Okta ships these controls but does not enable them for you.
- Restrict who can upload HAR files or other troubleshooting artefacts to Okta support, and sanitise them first.
- Set the Primary Security Contact and CIO/CISO contact in the Help Center.
- Subscribe to sub-processor change notifications and to the security advisory RSS feed.
- Execute a DPA (and a BAA where PHI is in scope) and confirm the applicable SCC module.
- Monitor and retain Okta System Log events in your own SIEM - do not rely on Okta-side log retention.
**Suggested review cadence:** annual full reassessment, with quarterly review of security advisories, sub-processor changes and tenant configuration drift. Given the criticality of the identity layer, treat any Okta security advisory as an out-of-cycle trigger for review.
Copyright © 2026 SnapGRC