Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Databricks, your compliance team needs documented proof they can be trusted. ThirdProof investigated Databricks across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
24 sources queried. 96% confidence. Every Databricks investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Databricks's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 33% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
Databricks is ISO 27001 certified, with ISO certifications available in their due diligence package.
Q41
FedRAMP authorized: Product: Databricks; Provider: Databricks, Inc.; Status: Compliant; Impact Level: Moderate; Authorization Date: 2022-06-30T04:00:00.000Z
Q40
Databricks provides a Business Associate Agreement (BAA) and HIPAA compliance support when enabled through the compliance security profile.
Q42
Databricks provides a Data Processing Addendum (DPA) for customers requiring GDPR compliance and data protection regulations.
+ 5 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Databricks's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
Databricks is not listed on the FedRAMP Marketplace.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
24
Sources Queried
22
Sources With Data
March 25, 2026
Last Assessed
AI-generated analysis for Databricks
Databricks (databricks.com) is a well-established Data and AI platform company assessed at Risk Tier 3 (Moderate Risk) with a 96% confidence score. This tier reflects a strong overall security and compliance posture across most evaluated dimensions, tempered by specific gaps in AI data usage policy clarity and minor website security header configuration. Databricks presents a number of meaningful positive signals that distinguish it from typical Tier 3 vendors:
Independence Statement
All evidence in this report was independently sourced from public registries, external scanning infrastructure, threat intelligence feeds, and third-party data providers without vendor participation or disclosure.
2 findings identified for Databricks
databricks.com is missing 3 recommended security headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options.
databricks.com has an AI-related policy page but does not clearly state whether customer data is used for AI model training.
27 positive signals verified
No SEC Enforcement Filings Found
SEC Filing Search →No Historical Adverse Media Found
Historical Media Search →Legal Entity Actively Registered
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Established Domain (14+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Notable Tech Community Presence
Tech Community Sentiment →HTTP Security Grade: B
HTTP Security Scan →Certificate Data from TLS Handshake
Certificate Transparency →Web Archive History Unavailable
Web Archive History →No Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →10 Subprocessors Identified
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →HITRUST Directory Match — Manual Verification Required
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Third-Party AI Providers Disclosed
AI Data Usage Policy →Zero Data Retention for AI Processing
AI Data Usage Policy →Steps to address findings for Databricks
Request written AI training policy clarification: Contact the Databricks account team and ask for explicit written confirmation (email or addendum) that customer data — including inputs, outputs, and workload telemetry — is not used to train AI or machine learning models. Reference their AI trust page (https://docs.databricks.com/aws/en/databricks-ai/databricks-ai-trust) as a starting point and ask for any supplemental language available for inclusion in your DPA.
Request the SOC 2 Type II report and bridge letter: Ask your Databricks account team for their current SOC 2 Type II report — many enterprise vendors share this under NDA. Also request a bridge letter covering any gap period between the report end date and today. Review Section 4 (complementary user entity controls) carefully to confirm your organization's responsibilities.
Confirm HITRUST CSF certification status: For healthcare or HIPAA-regulated buyers, request the current HITRUST CSF certificate from the Databricks security team, or contact the HITRUST Alliance directly at hitrustalliance.net to confirm Azure Databricks certification remains active and current.
Verify ISO 27001 certification status: ISO 27001 was not found in the public IAF registry during this assessment. Request the current ISO 27001 certificate (including certificate number, issuing body, and expiry date) from the vendor's security team. If certified, ask them to confirm their accreditation body so you can cross-reference at iafcertsearch.org.
Review FedRAMP authorization for government or regulated workloads: Databricks holds independently verified FedRAMP Moderate authorization (since June 2022). Buyers operating in federal or regulated environments should confirm which specific Databricks products and cloud regions fall within the FedRAMP authorization boundary by reviewing the full authorization package at https://marketplace.fedramp.gov/products/FR1834740315.
Document HTTP security header gap for your risk register: The Databricks marketing domain is missing Strict-Transport-Security, Content-Security-Policy, and X-Frame-Options headers (HTTP security scanner grade: B, 75/100). While the application platform (app.databricks.com) may have different header configurations, document this gap and request confirmation from the vendor that the application platform meets your organization's header security standards.
Confirm the legal entity for contracting: The Legal Entity Registry registry returned a sole proprietor entity registered in Denmark with a 90/100 match confidence. Confirm with the Databricks legal team that contracts and data processing agreements are executed with Databricks, Inc. (the US-incorporated parent entity) and not a subsidiary, and request the relevant entity's EIN or incorporation documentation.
24 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Databricks? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Databricks on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Databricks's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Databricks a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Databricks appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Databricks's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Databricks's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Databricks claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Databricks depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Databricks appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Seeing this in an audit? ThirdProof lets you investigate Databricks and every other vendor in your stack — average report time: 7 minutes. Get Databricks's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Databricks across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.