Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Okta, your compliance team needs documented proof they can be trusted. ThirdProof investigated Okta across 27 intelligence sources — here's what we found.
✓ FedRAMP Status: Authorized (Moderate) — verified against marketplace.fedramp.gov
27 sources queried. 100% confidence. Every Okta investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Okta's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 41% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
ISO 27001 claim found on trust page (Vendor attested)
Q41
FedRAMP authorized: Product: Okta IDaaS Government High Cloud (GHC); Provider: Okta; Status: Compliant; Impact Level: High; Authorization Date: 2023-09-19T04:00:00.000Z
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
+ 6 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Okta's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Verified against the official FedRAMP Marketplace API as of March 2026.
Okta identity platform authorized at Moderate impact level.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
27
Sources Queried
25
Sources With Data
April 17, 2026
Last Assessed
AI-generated analysis for Okta
Automated narrative synthesis unavailable. 6 finding(s) identified by the rule engine for Okta. Risk tier determined deterministically. Manual review recommended.
6 findings identified for Okta
Article from cybernews.com: "Okta breach chain hits Hims & Hers in wider ShinyHunters attack spree"
okta.com received a failing grade (F) from Mozilla HTTP Observatory. This indicates serious HTTP security configuration issues. Note: This scan was performed on the marketing site (okta.com). The application endpoint (app.okta.com) may have different security headers. Verify the application domain separately.
1 article(s) reference security or regulatory concerns for "Okta": "Okta breach chain hits Hims & Hers in wider ShinyHunters attack spree" (Cybernews) https://news.google.com/rss/articles/CBMidEFVX3lxTE1yR1Zrb3RYMFBMTUJhSUE0eXd2bGRienBLZTBNczNUYy01MDRLdGp0MWFkaVhjcWxHVGlKOUJhUVFPRFRmNTB2ZXFWVG9od0pkd1VOVThLME4tSUZwSmZFUloyTnZNLUlfNktGbENEd080MEVJ?oc=5
The LEI registration for OKTA has status "LAPSED". This may indicate the entity no longer maintains its regulatory filings.
okta.com is missing 3 recommended security headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options.
An AI-specific data usage policy was not discoverable for okta.com through automated scanning of common policy paths and web search. The vendor may publish relevant data handling commitments in enterprise agreement documents (DPAs, product terms, licensing portals) that are not indexed at standard public URLs. Request the vendor's Data Protection Addendum or AI-specific terms directly.
30 positive signals verified
Legal Entity Actively Registered
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Established Domain (21+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Tech Community Discussion: security
Tech Community Sentiment →Certificate Data from TLS Handshake
Certificate Transparency →Established Web Presence (22+ years)
Web Archive History →Domain in 50 Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →Certification Claimed: GDPR
Trust & Compliance Page Scan →Certification Claimed: CCPA
Trust & Compliance Page Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: SOC 1
Trust & Compliance Page Scan →Certification Claimed: ISO 27001
Trust & Compliance Page Scan →Certification Claimed: PCI DSS
Trust & Compliance Page Scan →Certification Claimed: HIPAA
Trust & Compliance Page Scan →Certification Claimed: CSA STAR
Trust & Compliance Page Scan →Certification Claimed: NIST
Trust & Compliance Page Scan →Subprocessor Page Found (Placeholder)
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Steps to address findings for Okta
Review rule engine findings manually
Re-run assessment when AI synthesis is available
27 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Okta? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Okta on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Okta's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Okta a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Okta appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Okta's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Okta's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Okta claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Okta depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Okta appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Okta claims SOC 2 Type II, ISO 27001, FedRAMP, HIPAA, and CSA STAR certifications. Okta for Government holds FedRAMP Moderate authorization independently verifiable on marketplace.fedramp.gov. ThirdProof's assessment cross-references these claims with public registries and flags certifications that cannot be independently verified. As an identity provider, Okta is a Tier 1 critical vendor for most organizations — request the full SOC 2 Type II report and any bridge letters before finalizing vendor approval.
ThirdProof investigated Okta across 27 intelligence sources and assigned a Moderate Risk (Tier 3) rating with 86% confidence. Historical media search identified the 2022 LAPSUS$ breach and the 2023 support case/HAR file compromise. Okta's current threat intelligence profile is clean — no active sanctions, no current adverse media, no malware indicators. The Moderate Risk rating is driven by incident history, not current controls, and should be weighed alongside Okta's post-incident remediation disclosures.
Seeing this in an audit? ThirdProof lets you investigate Okta and every other vendor in your stack — average report time: 7 minutes. Get Okta's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Okta across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.