Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with PagerDuty, your compliance team needs documented proof they can be trusted. ThirdProof investigated PagerDuty across 27 intelligence sources — here's what we found.
✓ FedRAMP Status: Authorized (Moderate) — verified against marketplace.fedramp.gov
25 sources queried. 99% confidence. Every PagerDuty investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get PagerDuty's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 36% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
ISO 27001 claim found on trust page (Vendor attested)
Q41
Not found in FedRAMP marketplace
Q42
PagerDuty includes Standard Contractual Clauses in its Data Processing Addendum and requires subprocessors to enter into DPAs for GDPR compliance.
Q39
PCI DSS compliance claim found on trust page (Vendor attested)
+ 4 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get PagerDuty's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Verified against the official FedRAMP Marketplace API as of March 2026.
PagerDuty authorized at Moderate impact level.
Low Risk
Vendor Risk Assessment
Based on data availability and source coverage
25
Sources Queried
24
Sources With Data
April 4, 2026
Last Assessed
AI-generated analysis for PagerDuty
PagerDuty, Inc. (NYSE: PD) is an established operations management platform incorporated in Delaware and active as a legal entity (LEI: 549300U1SB749EDAGH21). ThirdProof's assessment assigns a Tier 4 (Low Risk) rating with 99% confidence, reflecting a strong overall security posture with only minor areas requiring attention. PagerDuty presents a compelling set of positive signals across all major risk dimensions:
Independence Statement
All evidence underpinning this report was sourced independently by ThirdProof from external databases, public registries, and open-source intelligence — without vendor participation or disclosure.
2 findings identified for PagerDuty
pagerduty.com is missing 2 recommended security headers: Content-Security-Policy, X-Frame-Options.
pagerduty.com received a mediocre grade (C). Some security headers are configured but improvements are needed. Note: This scan was performed on the marketing site (pagerduty.com). The application endpoint (app.pagerduty.com) may have different security headers. Verify the application domain separately.
25 positive signals verified
Valid SSL Certificate
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Legal Entity Actively Registered
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Adverse Media Found
Adverse Media Scan →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Established Domain (17+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Minimal Tech Community Discussion
Tech Community Sentiment →Certificate Data from TLS Handshake
Certificate Transparency →Established Web Presence (16+ years)
Web Archive History →No Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: ISO 27001 (Inherited)
Trust & Compliance Page Scan →Certification Claimed: PCI DSS (Inherited)
Trust & Compliance Page Scan →Certification Claimed: FedRAMP
Trust & Compliance Page Scan →40 Subprocessors Identified
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →No Historical Adverse Media Found
Historical Media Search →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Steps to address findings for PagerDuty
Verify FedRAMP Low Authorization independently by searching 'PagerDuty' directly on the FedRAMP Marketplace at https://marketplace.fedramp.gov — this takes less than 5 minutes and will confirm or clarify the vendor's claim. Complete within 15 days.
Request PagerDuty's current SOC 2 Type II report and a bridge letter confirming continuity of controls through the present date — contact their security team directly or check https://trust.pagerduty.com. Complete within 30 days of onboarding.
Run an independent HTTP security scanner scan of the application endpoint at https://observatory.mozilla.org/analyze/app.pagerduty.com to assess security header configuration at the layer where your data will be processed. Document the result in your vendor risk register within 60 days.
Clarify PagerDuty's AI data handling practices if your organization processes sensitive data through their platform — specifically ask whether customer incident data is used to train AI/ML models, which third-party AI providers have access to your data, and what the data retention period is for AI-processed content. Request their AI governance policy or data processing addendum.
Schedule an annual vendor risk review for PagerDuty to re-assess certifications (SOC 2 Type II renewal, FedRAMP status), domain reputation, and subprocessor list updates — set a calendar reminder for 12 months from today.
25 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you PagerDuty? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is PagerDuty on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is PagerDuty's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is PagerDuty a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has PagerDuty appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is PagerDuty's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are PagerDuty's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does PagerDuty claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does PagerDuty depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has PagerDuty appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Seeing this in an audit? ThirdProof lets you investigate PagerDuty and every other vendor in your stack — average report time: 7 minutes. Get PagerDuty's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates PagerDuty across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.