Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Freshworks, your compliance team needs documented proof they can be trusted. ThirdProof investigated Freshworks across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
27 sources queried. 100% confidence. Every Freshworks investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Freshworks's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 77% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
Freshworks holds ISO/IEC 27001:2022 certification and is audited under SOC 2 Type II framework for security, confidentiality, and availability.
Q41
Not found in FedRAMP marketplace
Q40
Freshworks supports HIPAA compliance and offers Business Associate Agreement (BAA) execution for customers who are HIPAA-covered entities or business associates.
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
+ 10 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Freshworks's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
Freshworks is not listed on the FedRAMP Marketplace.
Low Risk
Vendor Risk Assessment
Based on data availability and source coverage
27
Sources Queried
26
Sources With Data
April 17, 2026
Last Assessed
AI-generated analysis for Freshworks
Freshworks (freshworks.com) is a publicly listed enterprise SaaS vendor offering IT service management and customer service solutions, assessed here at a Tier 4 (Low Risk) rating with 100% confidence across all data sources. The assessment surfaces a strong overall security posture supported by multiple independent signals:
Independence Statement
All evidence in this assessment was independently sourced from external registries, threat intelligence feeds, DNS/TLS infrastructure scans, and public media archives without vendor participation or notification.
2 findings identified for Freshworks
freshworks.com is missing 3 recommended security headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options.
freshworks.com has certificates from 36 different Certificate Authorities. This may indicate inconsistent certificate management practices.
29 positive signals verified
Legal Entity Actively Registered
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Adverse Media Found
Adverse Media Scan →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →1 Open Port Detected
Infrastructure Exposure →Established Domain (28+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Minimal Tech Community Discussion
Tech Community Sentiment →HTTP Security Grade: B
HTTP Security Scan →Large Certificate Footprint (195 subdomains)
Certificate Transparency →Established Web Presence (4+ years)
Web Archive History →Domain in 2 Threat Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: GDPR
Trust & Compliance Page Scan →Certification Claimed: CCPA
Trust & Compliance Page Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: SOC 1
Trust & Compliance Page Scan →Certification Claimed: CSA STAR
Trust & Compliance Page Scan →Certification Claimed: Cyber Essentials
Trust & Compliance Page Scan →2 Subprocessors Identified
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →No Historical Adverse Media Found
Historical Media Search →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Deep Document Crawler Results
Deep Document Analysis →Steps to address findings for Freshworks
Request the SOC 2 Type II report and current bridge letter from Freshworks' security team — visit [trust.freshworks.com](https://trust.freshworks.com), log in or request access under NDA, and look for the SOC 2 Type II document under the 'Compliance' section. Ask specifically for a bridge letter if the report period ended more than 6 months ago.
Request the ISO/IEC 27001:2022 certificate directly from Freshworks — ask for the certificate number, issuing certification body, and expiry date, then independently verify it via [IAF CertSearch](https://www.iafcertsearch.org) by searching for 'Freshworks' under the issuing body.
Clarify AI data usage practices before processing sensitive or regulated data through any Freshworks AI-powered feature (e.g., Freddy AI) — contact the Freshworks security team and ask: (a) Is customer data used to train AI models? (b) Which third-party AI providers receive customer data? (c) What is the data retention period for AI-processed inputs? Reference their [published privacy policy](https://www.freshworks.com/privacy/) as a starting point.
Request the full GDPR Article 28 subprocessor list from Freshworks — the published page at [trust.freshworks.com/subprocessors](https://trust.freshworks.com/subprocessors) currently lists only 2 technology-layer subprocessors; ask the vendor for the complete operational subprocessor disclosure and review for any entities in high-risk jurisdictions.
Confirm HIPAA BAA execution if your organization qualifies as a HIPAA-covered entity or business associate — contact Freshworks' legal or compliance team to initiate the BAA process before transmitting any protected health information through Freshworks products.
27 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Freshworks? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Freshworks on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Freshworks's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Freshworks a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Freshworks appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Freshworks's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Freshworks's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Freshworks claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Freshworks depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Freshworks appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Seeing this in an audit? ThirdProof lets you investigate Freshworks and every other vendor in your stack — average report time: 7 minutes. Get Freshworks's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Freshworks across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.