Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with ClickUp, your compliance team needs documented proof they can be trusted. ThirdProof investigated ClickUp across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
24 sources queried. 89% confidence. Every ClickUp investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get ClickUp's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 35% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
ISO 27001 claim found on trust page (Vendor attested)
Q41
Not found in FedRAMP marketplace
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
+ 4 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get ClickUp's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
ClickUp is not listed on the FedRAMP Marketplace.
High Risk
Vendor Risk Assessment
Based on data availability and source coverage
24
Sources Queried
23
Sources With Data
March 25, 2026
Last Assessed
AI-generated analysis for Clickup
ClickUp (clickup.com) is an established project management and productivity SaaS platform that has been assessed at Risk Tier 2 (High Risk), driven primarily by unverified compliance certifications, an indefinite AI data retention concern, and infrastructure CVE exposure attributable to its CDN provider. The investigation identified several meaningful positive signals:
Independence Statement
All evidence underlying this report was independently sourced from external data providers, public registries, and open-source intelligence without vendor participation or notification.
4 findings identified for Clickup
Infrastructure scanner has identified 39 known CVE(s) associated with services running on clickup.com (3.170.3.96). Note: This IP resolves to Cloudflare edge infrastructure. These CVEs may relate to CDN software, not clickup.com's own application.
A critical data source was unavailable during this investigation. Manual verification is recommended.
clickup.com has certificates from 33 different Certificate Authorities. This may indicate inconsistent certificate management practices.
clickup.com may retain customer data indefinitely for AI processing.
34 positive signals verified
No LEI Registry Match (Expected for Most Companies)
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →Firmographic Data Available
Company Intelligence →Domain Infrastructure Healthy
Domain Analysis →Valid SSL Certificate
Domain Analysis →Security Headers Present
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Established Domain (24+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Notable Tech Community Presence
Tech Community Sentiment →Minimal Tech Community Discussion
Tech Community Sentiment →HTTP Security Grade: B-
HTTP Security Scan →Large Certificate Footprint (378 subdomains)
Certificate Transparency →Established Web Presence (25+ years)
Web Archive History →No Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: ISO 27001
Trust & Compliance Page Scan →Certification Claimed: ISO 27017
Trust & Compliance Page Scan →Certification Claimed: ISO 27018
Trust & Compliance Page Scan →Certification Claimed: HIPAA
Trust & Compliance Page Scan →Certification Claimed: GDPR
Trust & Compliance Page Scan →Certification Claimed: CCPA
Trust & Compliance Page Scan →Certification Claimed: SOC 1
Trust & Compliance Page Scan →Certification Claimed: PCI DSS
Trust & Compliance Page Scan →Subprocessor Page Found, No Entries Parsed
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →No Historical Adverse Media Found
Historical Media Search →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Vendor Commits to Not Training on Customer Data
AI Data Usage Policy →AI Governance Standards Referenced
AI Data Usage Policy →Steps to address findings for Clickup
Request ClickUp's SOC 2 Type 2 report and a bridge letter — visit their Drata trust portal at security.clickup.com to request access, or contact sales@clickup.com. The bridge letter should be dated within the last 6 months to confirm continuous coverage. Target receipt within 15 business days.
Request ISO 27001:2022 certificate documentation directly from ClickUp's security team, including the issuing certification body, certificate number, and expiry date. You can attempt independent verification at iafcertsearch.org by searching for 'ClickUp' once you have the certificate number.
Manually review the subprocessor list at trust.clickup.com/subprocessors. Identify any subprocessors processing personal data and confirm each has appropriate data transfer mechanisms (SCCs, adequacy decisions) in place. Document this review within 30 days.
Request ClickUp's Data Processing Addendum (DPA) and ask their legal or security team to clarify the specific retention period for AI-processed data, including first-party retention by ClickUp — not only third-party partner retention. Ensure the no-training commitment is contractually incorporated into the DPA.
If ISO 27001 certificate details are obtained from ClickUp, independently verify the certificate number at iafcertsearch.org to confirm the certification body, scope, and expiry date are consistent with ClickUp's claims.
24 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you ClickUp? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is ClickUp on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is ClickUp's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is ClickUp a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has ClickUp appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is ClickUp's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are ClickUp's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does ClickUp claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does ClickUp depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has ClickUp appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Seeing this in an audit? ThirdProof lets you investigate ClickUp and every other vendor in your stack — average report time: 7 minutes. Get ClickUp's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates ClickUp across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.