Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Gusto, your compliance team needs documented proof they can be trusted. ThirdProof investigated Gusto across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
24 sources queried. 100% confidence. Every Gusto investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Gusto's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 32% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
Gusto offers integration with Secureframe to streamline ISO 27001 compliance, but no direct certification claim found at gusto.com.
Q41
Not found in FedRAMP marketplace
Q42
Gusto provides an Employer Data Processing Addendum (DPA) for compliance with applicable data protection laws including GDPR.
Q23
Gusto explicitly states 'All data at rest is encrypted using AES-256' in AWS.
+ 2 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Gusto's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
Gusto is not listed on the FedRAMP Marketplace.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
24
Sources Queried
24
Sources With Data
March 25, 2026
Last Assessed
AI-generated analysis for Gusto
Gusto (gusto.com) is an established HR, payroll, and benefits SaaS platform assessed at Tier 3 (Moderate Risk), reflecting a mature and largely well-configured vendor with a small number of supply chain transparency and AI data governance gaps that warrant attention before full approval. Gusto demonstrates a number of meaningful positive signals across security, domain health, and operational maturity:
Independence Statement
All evidence in this report was independently sourced by ThirdProof from external data sources without vendor participation or input.
2 findings identified for Gusto
gusto.com has certificates from 31 different Certificate Authorities. This may indicate inconsistent certificate management practices.
gusto.com may use customer data for AI training unless customers opt out. Review the opt-out process.
26 positive signals verified
Legal Entity Actively Registered
Business Registration →Low-Confidence Sanctions Matches Only
Sanctions & Watchlist Screening →Firmographic Data Available
Company Intelligence →Domain Infrastructure Healthy
Domain Analysis →Valid SSL Certificate
Domain Analysis →13 Open Ports Detected
Infrastructure Exposure →Established Domain (30+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Notable Tech Community Presence
Tech Community Sentiment →Minimal Tech Community Discussion
Tech Community Sentiment →HTTP Security Grade: B
HTTP Security Scan →Large Certificate Footprint (113 subdomains)
Certificate Transparency →Established Web Presence (28+ years)
Web Archive History →Domain in 2 Threat Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Trust Page Found, No Certifications Detected
Trust & Compliance Page Scan →Subprocessor Page Found (Placeholder)
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →No Historical Adverse Media Found
Historical Media Search →HITRUST Directory Match — Manual Verification Required
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Third-Party AI Providers Disclosed
AI Data Usage Policy →AI Data Retention Policy Not Specified
AI Data Usage Policy →Steps to address findings for Gusto
Request Gusto's current SOC 2 Type II report and a bridge letter covering the period to today — contact their security team directly or check https://trust.gusto.com, where many vendors make reports available under NDA. Ask whether the report covers the payroll and HR processing environment specifically.
Obtain a complete subprocessor list from Gusto by contacting their privacy team. The published page at https://trust.gusto.com/subprocessors was not populated at time of assessment — request a current list directly and incorporate it into your vendor risk register.
Clarify the scope and mechanism of Gusto's AI model training opt-out by reviewing your Data Processing Agreement (DPA) with Gusto. If processing sensitive employee data through AI features, require written confirmation that opt-out is in effect and document it. Review https://docs.gusto.com/app-integrations/docs/mcp for the current policy.
Confirm TLS certificate auto-renewal is operational for gusto.com by asking Gusto's security team to confirm their certificate management process during your next vendor review cycle. This is low urgency at 72 days but should be documented.
Independently verify HITRUST certification status by searching the HITRUST Alliance directory directly at https://directory.hitrustalliance.net/search?q=Gusto and confirming the listed entity matches Gusto (the payroll/HR company). If confirmed, this is a significant positive compliance signal worth documenting.
24 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Gusto? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Gusto on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Gusto's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Gusto a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Gusto appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Gusto's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Gusto's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Gusto claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Gusto depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Gusto appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Seeing this in an audit? ThirdProof lets you investigate Gusto and every other vendor in your stack — average report time: 7 minutes. Get Gusto's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Gusto across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.