



Security & compliance at a glance
Clerk has been SOC 2 Type 2 and HIPAA certified since May 2022, complies with GDPR through the EU-U.S. Data Privacy Framework, and publishes its CCPA notice, CVE history, and outage postmortems. Each item below links to a source you can check.
Compliance at a glance
The status of each framework, including the ones Clerk does not hold. Each row links to the relevant legal, pricing, or trust center document.
| Requirement | Exact status | Detail | Access & evidence |
|---|---|---|---|
| SOC 2 Type 2 | Held | Since May 6, 2022 | Report on the Business plan and above, via support@clerk.comAnnouncementPricingTrust portal |
| HIPAA | Held | Since May 6, 2022 | Business Associate Agreement (BAA) on the Enterprise planAnnouncementPricing |
| GDPR / Data Privacy Framework | Held | Self-certified under the EU-U.S. DPF, its UK Extension, and the Swiss-U.S. DPF, effective Feb 22, 2024 | Public DPF Notice and DPADPF NoticeDPAGDPR notice |
| CCPA | Held | Supplemental notice published | PublicCCPA notice |
| ISO 27001 | Not held | Infrastructure providers (Google Cloud, Cloudflare) hold it; Clerk does not | N/ATrust portal |
| PCI DSS | Not applicable | Clerk never stores cardholder data | N/ATrust portal |
| Regional data residency | Not offered | US-hosted; EU/UK/Swiss data transferred under the DPF | N/ASubprocessor listDPF Notice |
How to obtain reports and agreements
SOC 2 report
Available on the Business plan and above. Request it through support@clerk.com.
HIPAA BAA
The Business Associate Agreement is signed on the Enterprise plan.
Public notices
The DPA, DPF Notice, and CCPA notice are public.
Trust portal
trust.clerk.com hosts the attestations.
Clerk's audited platform controls are the same on every plan. Plans gate access to the reports and agreements, not the controls themselves.
Security practices
Secure by default
60-second session tokens with server-side verification, refreshed in the background.
Breached-password detection
Passwords are checked against HaveIBeenPwned's 10B+ compromised credentials, aligned with NIST SP 800-63B.
Abuse protection built in
Bot protection (Cloudflare Turnstile), account lockout, rate limiting, and user-enumeration protection.
MFA enforcement
Enforce multi-factor authentication application-wide with a single Dashboard toggle.
Independent audits
Third-party penetration testing and external code audits of the SDKs.
Coordinated disclosure
A published Vulnerability Disclosure Policy with safe harbor, a public status page, and full outage postmortems.
To report a vulnerability, email security@clerk.dev. The Vulnerability Disclosure Policy covers coordinated disclosure, response targets, and safe harbor for good-faith researchers.
Compliance questions and answers




Start now, no strings attached
Integrate complete user management in minutes. Free for your first 50,000 monthly retained users and 100 monthly retained orgs. No credit card required.