Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with LastPass, your compliance team needs documented proof they can be trusted. ThirdProof investigated LastPass across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
25 sources queried. 100% confidence. Every LastPass investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get LastPass's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 35% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
ISO 27001 claim found on trust page (Vendor attested)
Q41
Not found in FedRAMP marketplace
Q40
LastPass blog discusses HIPAA compliance and BAA requirements for associates handling PHI, but third-party sources indicate LastPass does not directly store patient PHI and BAA details are not prominently published.
Q42
LastPass support documentation confirms the product is compliant with GDPR, and LastPass provides a Data Processing Addendum governing processing of personal data as a service provider.
+ 4 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get LastPass's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
LastPass is not listed on the FedRAMP Marketplace.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
25
Sources Queried
25
Sources With Data
April 6, 2026
Last Assessed
AI-generated analysis for LastPass
LastPass (lastpass.com) is a critical-data-access SaaS password management and identity platform assessed at Tier 3 (Moderate Risk), reflecting a combination of strong baseline infrastructure controls, vendor-attested compliance certifications, and a material unresolved incident history stemming from the 2022 breach. On the positive side, LastPass presents a number of meaningful security indicators:
However, several concerns require buyer attention before this vendor is approved for use in environments with critical data access. The 2022 breach — in which encrypted password vaults were exfiltrated — continues to generate downstream harm: ongoing cryptocurrency theft campaigns have been traced to that event, and a $24.5M class action settlement is in progress. The UK Information Commissioner's Office issued a regulatory fine in December 2025 related to the same breach. Both SOC 2 and ISO 27001 certifications are vendor-attested only — no independent registry confirmation was found — and the full audit reports should be obtained. The subprocessor page at trust.lastpass.com/subprocessors could not be parsed by automated means, preventing supply chain visibility. No public AI data usage policy was discoverable. Overall, LastPass is conditionally approvable for continued or new use, provided the buying organization obtains current third-party audit reports, reviews post-breach remediation evidence, and satisfies the requirements listed in this report. The long-term impact of the 2022 breach and the absence of independently verified certifications are the primary factors warranting conditional rather than standard approval.
Independence Statement
All evidence in this assessment was independently sourced from external data providers, public registries, and open-source intelligence without vendor participation, input, or notification.
11 findings identified for LastPass
Article from Cyber Risk Assessment provider.com: "What Did the LastPass Breach Reveal About Password Manager Security?"
Article from medium.com: "I Spent a Week Researching What the LastPass Breach Actually Did to People. The Answer Is Still Getting Worse. | by Ed O. | TechEd Shield | TechEd Publishers | Mar, 2026 | Medium"
Article from www.techradar.com: "Historic LastPass breach enabling cryptocurrency theft, investigation reveals | TechRadar"
Article from www.bleepingcomputer.com: "Cryptocurrency theft attacks traced to 2022 LastPass breach"
Article from vinciworks.com: "The LastPass breach: how convenience became a compliance failure - VinciWorks"
7 article(s) reference significant concerns for "LastPass": "Experts Trace $35m in Stolen Crypto to LastPass Breach" (Infosecurity Magazine) https://news.google.com/rss/articles/CBMigAFBVV95cUxQa0lzOFdwRVhJc3ZxS1Q1Ymktb1cwb0xaY1pqR2lnR1o0M2E5STczRXVvNWhpSm1ZUmQzT2pjaHI3MjNNUF9QNlhLWmxSa1NXYXY0anpNWFNwLUtuVXYwbW1lQWZySWEwX183THg2T2ROa2hVS3VtLURLcEozV2dPYw?oc=5; "Cryptocurrency theft attacks traced to 2022 LastPass breach" (BleepingComputer) https://news.google.com/rss/articles/CBMiqwFBVV95cUxOZG1SRXdCanRFNGM4cDJHQWtvTWhwQXlRM3JfMjNYT1FwczQ4cU9MTEF2ZVlRbVh4dFg1aWZKTFJBWFJEZWRMWHd1TDRKSkthS3hFTmE2dTZmYWktMnVJSU1pMkQ5czU1Umt5VDZMdWcxajZhVFYyeEJDNnJMcUU3cG56bmpjQzlOSUVIWi1SeUZzODRDeEdVUnFpUFczSFJwN2J5c1hwTmptR03SAbABQVVfeXFMTy1YbV93dWJ4VG04YmhOQUJmNXNQZUdHMmhnaHBOaVg4TENPQnNjZHl2a2NRN09rVEJSSzJ0MkRrdVJoNEJ5M0dQM3l6cFFhdGRrN0VLcFU0LTN6M1lrckROX3MyNWRHOWR1dVdWNTVfdWpOT1Fpd3g2aHNWZUdkRnp4aDJjREZyaDZMbXR3eU9WSFhsYloxWlMza0ZLcndKLUs1MTIyZzZhajU2MUtNRDY?oc=5; "Crypto theft still powered by 2022 LastPass breach | brief | SC Media" (SC Media) https://news.google.com/rss/articles/CBMihwFBVV95cUxNbmlDZllzOEY5YXo5Qm5WazhnN0p2RWtaenN1V08wbHl3bTRVRnFaZTBDOFhjM3FyV2hKM0VOUTlCdUt4amFJMVpLQVhiTS1QS040bDNzR2FQQnZNdGdiVHg0OXFzTHhWbHUyX290S3FMOWFqU1dVMFNGblpYaVQ2LVBsSVZkckE?oc=5
The LEI registration for LASTPASS US LP has status "LAPSED". This may indicate the entity no longer maintains its regulatory filings.
Article from www.pcworld.com: "The LastPass breach settlement is real. Here’s what you should know | PCWorld"
Article from www.pcmag.com: "Affected by This LastPass Breach? How to Get a Cut of the $24.5M Settlement | PCMag"
lastpass.com has certificates from 46 different Certificate Authorities. This may indicate inconsistent certificate management practices.
An AI-specific data usage policy was not discoverable for lastpass.com through automated scanning of common policy paths and web search. The vendor may publish relevant data handling commitments in enterprise agreement documents (DPAs, product terms, licensing portals) that are not indexed at standard public URLs. Request the vendor's Data Protection Addendum or AI-specific terms directly.
24 positive signals verified
Legal Entity Actively Registered
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Recent News Coverage
Adverse Media Scan (Fallback)
Firmographic Data Available
Company Intelligence →Domain Infrastructure Healthy
Domain Analysis →Valid SSL Certificate
Domain Analysis →Security Headers Present
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Established Domain (21+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Tech Community Discussion: regulatory
Tech Community Sentiment →HTTP Security Grade: B
HTTP Security Scan →Large Certificate Footprint (139 subdomains)
Certificate Transparency →Established Web Presence (3+ years)
Web Archive History →Domain in 2 Threat Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: ISO 27001
Trust & Compliance Page Scan →Subprocessor Page Found, No Entries Parsed
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Steps to address findings for LastPass
Obtain the current SOC 2 Type II report (post-January 2023 period) and bridge letter: contact LastPass's security team via their [Trust Center](https://trust.lastpass.com) or request directly from your account representative. Confirm the audit covers the post-breach remediated control environment. Complete within 30 days.
Verify ISO 27001 certification independently: request the certificate number and issuing body from LastPass, then cross-check against the [IAF CertSearch registry](https://www.iafcertsearch.org). Complete within 30 days.
Review the subprocessor list manually at [trust.lastpass.com/subprocessors](https://trust.lastpass.com/subprocessors): document all named subprocessors, check data residency, and verify that any subprocessors with access to vault or credential data hold their own SOC 2 or equivalent certifications. Retain as GDPR Article 28 evidence. Complete within 30 days.
Request written AI data handling commitments from LastPass covering: training data use, third-party AI providers, retention periods, and opt-out availability. If commitments cannot be obtained in writing, restrict use of AI-enhanced features until resolved. Complete within 45 days.
Request and review LastPass's post-breach remediation documentation: specifically architectural changes to vault storage, key management improvements, and any third-party forensic review findings. Cross-reference against the [compliance unavailability analysis](https://vinciworks.com/blog/the-lastpass-breach-how-convenience-became-a-compliance-unavailability/) published in March 2026 to ensure identified gaps have been addressed. Complete within 45 days.
Document complementary user entity controls (CUECs) for your organization if LastPass is in-scope for your SOC 2 boundary: at minimum, enforce MFA for all LastPass admin accounts, maintain a current inventory of users with admin access, and establish a procedure for emergency credential rotation in the event of a future compromise notification.
25 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you LastPass? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is LastPass on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is LastPass's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is LastPass a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has LastPass appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is LastPass's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are LastPass's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does LastPass claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does LastPass depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has LastPass appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Seeing this in an audit? ThirdProof lets you investigate LastPass and every other vendor in your stack — average report time: 7 minutes. Get LastPass's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates LastPass across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.