Skip to main content

Security & compliance at a glance

Clerk has been SOC 2 Type 2 and HIPAA certified since May 2022, complies with GDPR through the EU-U.S. Data Privacy Framework, and publishes its CCPA notice, CVE history, and outage postmortems. Each item below links to a source you can check.

Compliance at a glance

The status of each framework, including the ones Clerk does not hold. Each row links to the relevant legal, pricing, or trust center document.

Clerk compliance status by framework
RequirementExact statusDetailAccess & evidence
SOC 2 Type 2HeldSince May 6, 2022Report on the Business plan and above, via support@clerk.comAnnouncementPricingTrust portal
HIPAAHeldSince May 6, 2022Business Associate Agreement (BAA) on the Enterprise planAnnouncementPricing
GDPR / Data Privacy FrameworkHeldSelf-certified under the EU-U.S. DPF, its UK Extension, and the Swiss-U.S. DPF, effective Feb 22, 2024Public DPF Notice and DPADPF NoticeDPAGDPR notice
CCPAHeldSupplemental notice publishedPublicCCPA notice
ISO 27001Not heldInfrastructure providers (Google Cloud, Cloudflare) hold it; Clerk does notN/ATrust portal
PCI DSSNot applicableClerk never stores cardholder dataN/ATrust portal
Regional data residencyNot offeredUS-hosted; EU/UK/Swiss data transferred under the DPFN/ASubprocessor listDPF Notice

How to obtain reports and agreements

Clerk's audited platform controls are the same on every plan. Plans gate access to the reports and agreements, not the controls themselves.

Security practices

  • Secure by default

    60-second session tokens with server-side verification, refreshed in the background.

  • Breached-password detection

    Passwords are checked against HaveIBeenPwned's 10B+ compromised credentials, aligned with NIST SP 800-63B.

  • Abuse protection built in

    Bot protection (Cloudflare Turnstile), account lockout, rate limiting, and user-enumeration protection.

  • MFA enforcement

    Enforce multi-factor authentication application-wide with a single Dashboard toggle.

  • Independent audits

    Third-party penetration testing and external code audits of the SDKs.

  • Coordinated disclosure

    A published Vulnerability Disclosure Policy with safe harbor, a public status page, and full outage postmortems.

To report a vulnerability, email security@clerk.dev. The Vulnerability Disclosure Policy covers coordinated disclosure, response targets, and safe harbor for good-faith researchers.

Compliance questions and answers

Start now, no strings attached

Integrate complete user management in minutes. Free for your first 50,000 monthly retained users and 100 monthly retained orgs. No credit card required.