# Clerk Security and Compliance at a Glance

> Clerk has been SOC 2 Type 2 and HIPAA certified since May 6, 2022, complies with GDPR through the EU-U.S. Data Privacy Framework, and publishes its CCPA notice, CVE history, and outage postmortems. Each item below links to a source you can check.

Last reviewed: 2026-08-17

[Trust portal](https://trust.clerk.com) | [Security article](https://clerk.com/articles/clerk-security-how-we-protect-your-users)

## Compliance at a glance

| Requirement | Exact status | Detail | Access & evidence |
|---|---|---|---|
| SOC 2 Type 2 | Held | Since May 6, 2022 | Report on the Business plan and above, via support@clerk.com ([Announcement](https://clerk.com/changelog/2022-05-06), [Pricing](https://clerk.com/pricing), [Trust portal](https://trust.clerk.com)) |
| HIPAA | Held | Since May 6, 2022 | Business Associate Agreement (BAA) on the Enterprise plan ([Announcement](https://clerk.com/changelog/2022-05-06), [Pricing](https://clerk.com/pricing)) |
| GDPR / Data Privacy Framework | Held | Self-certified under the EU-U.S. DPF, its UK Extension, and the Swiss-U.S. DPF, effective Feb 22, 2024 | Public DPF Notice and DPA ([DPF Notice](https://clerk.com/legal/dpf), [DPA](https://clerk.com/legal/dpa), [GDPR notice](https://clerk.com/legal/gdpr)) |
| CCPA | Held | Supplemental notice published | Public ([CCPA notice](https://clerk.com/legal/ccpa)) |
| ISO 27001 | Not held | Infrastructure providers (Google Cloud, Cloudflare) hold it; Clerk does not | N/A ([Trust portal](https://trust.clerk.com)) |
| PCI DSS | Not applicable | Clerk never stores cardholder data | N/A ([Trust portal](https://trust.clerk.com)) |
| Regional data residency | Not offered | US-hosted; EU/UK/Swiss data transferred under the DPF | N/A ([Subprocessor list](https://trust.clerk.com), [DPF Notice](https://clerk.com/legal/dpf)) |

## How to obtain reports and agreements

- SOC 2 report: available on the Business plan and above. Request it through support@clerk.com
- HIPAA Business Associate Agreement (BAA): available on the Enterprise plan ([Pricing](https://clerk.com/pricing))
- DPA, DPF Notice, and CCPA notice: public ([Legal resources](https://clerk.com/legal))
- Trust portal (Drata): [trust.clerk.com](https://trust.clerk.com)

Clerk's audited platform controls are the same on every plan. Plans gate access to the reports and agreements, not the controls themselves.

## Security practices summary

- Secure by default: 60-second session tokens with server-side verification, refreshed in the background
- Breached-password detection against HaveIBeenPwned's 10B+ compromised credentials, aligned with NIST SP 800-63B
- Bot protection (Cloudflare Turnstile), account lockout, rate limiting, and user-enumeration protection built in
- Application-wide MFA enforcement with a single Dashboard toggle
- Independent third-party penetration testing and external code audits of the SDKs
- A published Vulnerability Disclosure Policy with safe harbor ([VDP](https://clerk.com/docs/guides/how-clerk-works/security/vulnerability-disclosure-policy)), a public status page ([status.clerk.com](https://status.clerk.com)), and full outage postmortems

CVEs, advisories, and outage postmortems are covered in [Clerk Security: How We Protect Your Users](https://clerk.com/articles/clerk-security-how-we-protect-your-users.md).

To report a vulnerability, email security@clerk.dev. The [Vulnerability Disclosure Policy](https://clerk.com/docs/guides/how-clerk-works/security/vulnerability-disclosure-policy) covers coordinated disclosure, response targets, and safe harbor for good-faith researchers.

## FAQ

### Is Clerk SOC 2 compliant, and how do I get the report?

Yes. Clerk has been SOC 2 Type 2 certified since May 6, 2022. The report is available on the Business plan and above. Request it through [support@clerk.com](mailto:support@clerk.com). Clerk's audited platform controls are the same on every plan; only access to the report is plan-gated.

### Does Clerk sign a HIPAA Business Associate Agreement (BAA)?

Yes. Clerk has been HIPAA certified since May 6, 2022, and the BAA is available on the Enterprise plan ([Pricing](https://clerk.com/pricing)).

### Is Clerk ISO 27001 certified?

No. Clerk is not ISO 27001 certified. Its infrastructure providers, Google Cloud and Cloudflare, hold the certification, but Clerk itself does not.

### Is Clerk PCI DSS compliant?

Not applicable. Clerk never stores cardholder data, so it makes no PCI DSS claim. Payments go through your payment provider, which carries the PCI obligations.

### Does Clerk offer regional data residency?

No. Clerk does not offer regional data residency or region selection. Data is hosted on US infrastructure (Google Cloud and Cloudflare, with all subprocessors in the USA), and EU, UK, and Swiss personal data is transferred to the US under the Data Privacy Framework, which is Clerk's GDPR-compliance mechanism (subprocessor list at [trust.clerk.com](https://trust.clerk.com); [DPF Notice](https://clerk.com/legal/dpf)).

### How do I report a security vulnerability to Clerk?

Report it to [security@clerk.dev](mailto:security@clerk.dev). Clerk publishes a [Vulnerability Disclosure Policy](https://clerk.com/docs/guides/how-clerk-works/security/vulnerability-disclosure-policy) with a 90-day coordinated disclosure window, a 3-business-day initial response target, safe-harbor language for good-faith researchers, and defined in-scope hosts. Clerk does not run a paid bug-bounty program.

### Has Clerk ever had a data breach?

No breach of Clerk's own systems or customer data has been publicly reported. The security issues on record are vulnerabilities in Clerk's open-source SDKs, each patched within days and published with a CVE and a GitHub Security Advisory. See [Clerk Security: How We Protect Your Users](https://clerk.com/articles/clerk-security-how-we-protect-your-users.md) for incident details and primary-source links.

## More

- [Homepage](https://clerk.com/)
- [Pricing](https://clerk.com/pricing)
- [Legal resources](https://clerk.com/legal)
- [Trust portal](https://trust.clerk.com)
- [Clerk Security: How We Protect Your Users](https://clerk.com/articles/clerk-security-how-we-protect-your-users)
- [Site index for LLMs (llms.txt)](https://clerk.com/llms.txt)
