Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with 1Password, your compliance team needs documented proof they can be trusted. ThirdProof investigated 1Password across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
25 sources queried. 100% confidence. Every 1Password investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get 1Password's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 33% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
1Password has achieved ISO 27001, 27017, 27018, and 27701 certifications.
Q41
Not found in FedRAMP marketplace
Q40
1Password does not sign Business Associate Agreements because AgileBits cannot access or decrypt customer data, so it is not defined as a Business Associate under HIPAA.
Q42
1Password offers a Data Protection Addendum (DPA) that outlines terms for processing personal data in compliance with GDPR and other data protection regulations.
+ 4 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get 1Password's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
1Password is not listed on the FedRAMP Marketplace. 1Password maintains SOC 2 Type II certification.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
25
Sources Queried
25
Sources With Data
April 6, 2026
Last Assessed
AI-generated analysis for 1Password
1Password (1password.com) is a well-established password management and secrets platform assessed at Risk Tier 3 (Moderate Risk) with a confidence score of 100%. Given its critical data access level — storing and managing credentials, secrets, and access controls for enterprise environments — this vendor warrants elevated scrutiny and active oversight. Positive signals are substantial across several domains:
Independence Statement
All evidence in this assessment was independently sourced from external data providers, public registries, and open-source intelligence without vendor participation or notification.
4 findings identified for 1Password
Article from onerep.com: "1Password Breach: 2023–2025 Incidents And How To Stay Safe"
1password.com received a mediocre grade (C-). Some security headers are configured but improvements are needed. Note: This scan was performed on the marketing site (1password.com). The application endpoint (app.1password.com) may have different security headers. Verify the application domain separately.
1password.com has certificates from 25 different Certificate Authorities. This may indicate inconsistent certificate management practices.
An AI-specific data usage policy was not discoverable for 1password.com through automated scanning of common policy paths and web search. The vendor may publish relevant data handling commitments in enterprise agreement documents (DPAs, product terms, licensing portals) that are not indexed at standard public URLs. Request the vendor's Data Protection Addendum or AI-specific terms directly.
23 positive signals verified
Not Found as FDIC-Insured Institution
FDIC Institution Check →No LEI Registry Match (Expected for Most Companies)
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Domain Infrastructure Healthy
Domain Analysis →Valid SSL Certificate
Domain Analysis →11 Open Ports Detected
Infrastructure Exposure →Established Domain (22+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Tech Community Discussion: security
Tech Community Sentiment →Large Certificate Footprint (64 subdomains)
Certificate Transparency →Established Web Presence (24+ years)
Web Archive History →Domain in 18 Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Subprocessor Page Found, No Entries Parsed
Supply Chain & Subprocessor Discovery →No SEC Enforcement Filings Found
SEC Filing Search →News Coverage Found (No Risk Signals)
Historical Media Search →HITRUST Directory Match — Manual Verification Required
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Steps to address findings for 1Password
**[PRIORITY 1 — Within 30 days]** Request 1Password's SOC 2 Type II report and a current bridge letter. Start at their trust portal ([trust.1password.com](https://trust.1password.com)) or contact their enterprise security team. Retain the report with a reviewer signature as SOC 2 CC9.2 audit evidence.
**[PRIORITY 2 — Within 30 days]** Inquire directly about the 2023–2025 security incidents described in the [adverse media coverage](https://onerep.com/blog/1password-breach-what-happened-and-how-to-stay-safe). Ask 1Password's security team for an incident summary, root cause analysis, and documentation of remediation steps taken. This is particularly important given the critical data access level.
**[PRIORITY 3 — Within 45 days]** Obtain 1Password's Data Protection Addendum (DPA) and any AI-specific product terms. Specifically confirm: (a) no customer credential data is used for AI model training, (b) named third-party AI processors if any, and (c) applicable data retention policies for AI-processed inputs.
**[PRIORITY 4 — Within 45 days]** Manually review the subprocessor page at [trust.1password.com/subprocessors](https://trust.1password.com/subprocessors) in a browser. Document each subprocessor's name, location, and function. Cross-check any non-EU/US subprocessors against your data transfer framework (SCCs, adequacy decisions).
**[PRIORITY 5 — If using the CLI or DevOps integrations]** Review the [1Password CLI vulnerability disclosure](https://news.ycombinator.com/item?id=45478553) and confirm whether your deployment is affected. Check 1Password's changelog and security advisories for the patch status, and ensure automated workflows using the CLI are pinned to a patched version.
**[PRIORITY 6 — Within 30 days]** Confirm with 1Password that automated TLS certificate renewal is active. If your account team cannot confirm this, flag it for re-check after May 31, 2026. Consider setting a calendar reminder at the 30-day mark (May 1, 2026).
**[PRIORITY 7 — Before next SOC 2 audit cycle]** If 1Password is within your SOC 2 audit boundary, document the complementary user entity controls (CUECs) your organization must implement — including access provisioning/deprovisioning, MFA enforcement on the 1Password account, and audit log review procedures. Retain this assessment report with a reviewer signature as CC9.2 evidence.
25 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you 1Password? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is 1Password on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is 1Password's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is 1Password a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has 1Password appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is 1Password's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are 1Password's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does 1Password claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does 1Password depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has 1Password appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
1Password is a password management platform claiming SOC 2 and CCPA compliance. 1Password is not listed on the FedRAMP Marketplace and has not pursued FedRAMP authorization. For organizations managing credential vaults across teams, 1Password's zero-knowledge architecture means the vendor cannot access stored credentials — but organizations should verify this claim through 1Password's SOC 2 report and assess the security implications of 10 open ports identified during ThirdProof's infrastructure scan.
ThirdProof investigated 1Password across 27 intelligence sources and assigned a Moderate Risk (Tier 3) rating with 82% confidence. Sanctions screening returned clear with no matches. Domain reputation is clean across 93 security engines with a 22-year domain history. The SSL/TLS grade is B and the HTTP security grade is C- (45/100) — these infrastructure findings should be weighed against 1Password's application-layer security model and zero-knowledge architecture.
Seeing this in an audit? ThirdProof lets you investigate 1Password and every other vendor in your stack — average report time: 7 minutes. Get 1Password's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates 1Password across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.