1Password SOC 2 Type 2, FedRAMP & DPA Review
- FedRAMP Status
- 1Password is not listed on the FedRAMP Marketplace as of March 2026.
- SOC 2 Status
- 1Password has a SOC 2 claim detected on their trust page. Claim is vendor-attested — no public registry exists for independent verification.
- Sanctions Screening
- 1Password returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
- Risk Tier
- ThirdProof assigned 1Password a Moderate Risk tier with 82% confidence across 24 intelligence sources.
ThirdProof investigated 1Password (1password.com) across 24 intelligence sources including sanctions databases, cyber risk scores, business registries, and more.
Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
1Password is not listed on the FedRAMP Marketplace. 1Password maintains SOC 2 Type II certification.
Investigation Preview — 23 Sources Queried
Full investigation report with evidence chain, compliance assessment, and recommended actions.
Investigate 1Password — First Investigation Free →Executive Summary Preview
1Password is an established, well-recognized password management SaaS vendor with a 22-year domain history, a clean threat intelligence profile across 93 security engines, and no active malware, phishing, or sanctions findings. The vendor's overall security posture is strong relative to its category, with no evidence of active compromise or regulatory enforcement.
This is an excerpt from the full ThirdProof investigation report. Get the complete report →
Key Findings for 1Password
| Severity | Finding | Source |
|---|---|---|
| medium | Aging adverse media in historical archives | Historical Media Search |
| info | Clean domain reputation | Threat Intelligence |
| low | 10 open ports detected | Infrastructure Exposure |
| low | 2 certifications claimed but not independently verified | Trust & Compliance Page Scan |
| low | Threat intelligence pulses detected | Threat Intelligence (OTX) |
5 total findings in the full report. View all findings →
Recommended Actions
- Request 1Password's current SOC 2 Type II audit report to independently verify the vendor-attested certification claim. Contact their security team directly at security@1password.com or visit https://trust.1password.com — many enterprise SaaS vendors provide these under NDA upon request. Retain the report with your TPSP documentation file for QSA review.
- Execute a formal written Third-Party Service Provider (TPSP) agreement with 1Password that satisfies PCI-DSS 4.0 Requirement 12.8.2. This agreement must document 1Password's acknowledgment of their role in protecting cardholder data environments and must specify which PCI DSS controls are managed by 1Password versus your organization. Ask your 1Password account manager for their standard enterprise security agreement.
- Obtain 1Password's CCPA Data Processing Addendum (DPA) and GDPR Data Processing Agreement if your retail organization processes EU consumer data. Confirm the DPA designates 1Password as a 'service provider' under CCPA with explicit contractual prohibition on selling or sharing credential data. These documents are often available via https://1password.com/legal or upon request.
Full recommendations available in the complete report.
“We manage nearly 100 vendors touching customer payment data. ThirdProof gives me audit-ready evidence in the time it used to take just to send the questionnaire.”
— April, Co-owner, The Perky Lady
What you'll see in 1Password's report
Every ThirdProof report includes these sections
Deterministic score based on evidence — not AI opinion
Understand how complete the picture is — higher confidence means more data sources returned results
Each finding linked to its source with severity rating
Know exactly what to do next — plain-language guidance for your compliance team
Independently verified, vendor attested, or not found
Audit-ready report with methodology disclosure
ThirdProof uses a deterministic rules engine to assign risk tiers. AI writes the narrative — rules drive the decision.
Intelligence Sources Queried for 1Password
Get 1Password's complete risk report — risk tier, confidence score, individual findings, and AI synthesis — in under 2 minutes.
Get 1Password's Risk Report Free →No credit card required
What a ThirdProof investigation covers
Sanctions Screening
Is 1Password on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
Cyber Risk Assessment
What is 1Password's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Business Registration
Is 1Password a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Adverse Media Analysis
Has 1Password appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Domain & Infrastructure
Is 1Password's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
Company Intelligence
What are 1Password's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Trust & Compliance Verification
Does 1Password claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Supply Chain & Subprocessor Discovery
Who does 1Password depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Regulatory & Financial Filings
Has 1Password appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
1Password Security and Compliance Status
1Password is a password management platform claiming SOC 2 and CCPA compliance. 1Password is not listed on the FedRAMP Marketplace and has not pursued FedRAMP authorization. For organizations managing credential vaults across teams, 1Password's zero-knowledge architecture means the vendor cannot access stored credentials — but organizations should verify this claim through 1Password's SOC 2 report and assess the security implications of 10 open ports identified during ThirdProof's infrastructure scan.
1Password Security Posture
ThirdProof investigated 1Password across 24 intelligence sources and assigned a Moderate Risk (Tier 3) rating with 82% confidence. Sanctions screening returned clear with no matches. Domain reputation is clean across 93 security engines with a 22-year domain history. The SSL/TLS grade is B and the HTTP security grade is C- (45/100) — these infrastructure findings should be weighed against 1Password's application-layer security model and zero-knowledge architecture.
Compliance Resources
Frequently asked about 1Password
Does 1Password have SOC 2 Type 2?+
Is 1Password FedRAMP authorized?+
Does 1Password offer a DPA?+
Is 1Password safe to use as a vendor?+
Does 1Password have SOC 2 certification?+
Is 1Password FedRAMP authorized?+
Has 1Password had any data breaches?+
Is 1Password on any sanctions lists?+
How do I assess 1Password for vendor risk?+
Also investigated by ThirdProof
Get the full report on 1Password
Your first vendor investigation is completely free. Results in under 2 minutes.
Get 1Password's Risk Report Free →No credit card required
After your free investigation, plans start at $399/mo for up to 25 investigations.
Want a walkthrough of ThirdProof for your team?
▶Request a Personalized Demo