Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Airtable, your compliance team needs documented proof they can be trusted. ThirdProof investigated Airtable across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
25 sources queried. 96% confidence. Every Airtable investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Airtable's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 39% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
Airtable holds ISO/IEC 27001:2022 certification with official certificate of registration covering the ISMS supporting the Airtable platform
Q41
Not found in FedRAMP marketplace
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
+ 6 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Airtable's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
Airtable is not listed on the FedRAMP Marketplace.
Low Risk
Vendor Risk Assessment
Based on data availability and source coverage
25
Sources Queried
24
Sources With Data
April 5, 2026
Last Assessed
AI-generated analysis for Airtable
Airtable (airtable.com) is a well-established SaaS platform rated Tier 4 (Low Risk) by ThirdProof's rule engine, reflecting a strong overall security posture with no material risk signals identified across the full scope of this investigation. Positive signals are substantial and consistent across multiple domains:
Independence Statement
All evidence in this report was independently sourced by ThirdProof's automated data collection infrastructure without vendor participation, notification, or review.
1 finding identified for Airtable
airtable.com received a mediocre grade (C). Some security headers are configured but improvements are needed. Note: This scan was performed on the marketing site (airtable.com). The application endpoint (app.airtable.com) may have different security headers. Verify the application domain separately.
30 positive signals verified
No Adverse Media Found
Adverse Media Scan →Legal Entity Actively Registered
Business Registration →[Filtered] Recently Registered Entity
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Domain Infrastructure Healthy
Domain Analysis →Valid SSL Certificate
Domain Analysis →Security Headers Present
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Established Domain (22+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Minimal Tech Community Discussion
Tech Community Sentiment →Certificate Data from TLS Handshake
Certificate Transparency →Established Web Presence (25+ years)
Web Archive History →Domain in 18 Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: HIPAA
Trust & Compliance Page Scan →Certification Claimed: GDPR
Trust & Compliance Page Scan →Certification Claimed: CCPA
Trust & Compliance Page Scan →25 Subprocessors Identified
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →No Historical Adverse Media Found
Historical Media Search →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Vendor Commits to Not Training on Customer Data
AI Data Usage Policy →AI Data Retention Policy Not Specified
AI Data Usage Policy →Steps to address findings for Airtable
Request Airtable's current SOC 2 Type II report and bridge letter — contact your Airtable account manager or email security@airtable.com. Ask specifically for the most recent audit period and confirm the report covers the systems and services your organization uses. Many enterprise customers receive this under a mutual NDA.
If your organization processes or stores protected health information (PHI) in Airtable, execute a signed HIPAA Business Associate Agreement (BAA) before go-live — Airtable's security page indicates BAA availability for qualifying plans. Request this through your account team.
Clarify AI data retention in writing: ask Airtable's account team how long Input and Output data submitted to Airtable AI features is retained by Airtable and by third-party AI providers (including OpenAI, LLC), and request confirmation that deletion occurs within a defined period. Document the response in your vendor risk file.
Verify the production application security header configuration by running a free HTTP security scanner scan on app.airtable.com at https://observatory.mozilla.org/analyze/app.airtable.com — this will give your security team a more accurate picture of the application's header posture than the marketing site scan.
Review Airtable's published subprocessor list at https://airtable.com/subprocessors on a quarterly basis and subscribe to change notifications if available. Pay particular attention to any additions of AI or data processing subprocessors given Airtable's active AI feature development roadmap.
25 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Airtable? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Airtable on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Airtable's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Airtable a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Airtable appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Airtable's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Airtable's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Airtable claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Airtable depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Airtable appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Airtable received a Tier 4 (Low Risk) rating at 84% confidence. LEI-verified business registration (Formagrid Inc.), clean sanctions, clean threat intelligence, and attested SOC 2 and HIPAA compliance. Primary diligence items: obtain SOC 2 Type II report, execute HIPAA BAA if PHI is involved, and review base-level permissions for workflows that may contain regulated data.
Seeing this in an audit? ThirdProof lets you investigate Airtable and every other vendor in your stack — average report time: 7 minutes. Get Airtable's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Airtable across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.