Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with PandaDoc, your compliance team needs documented proof they can be trusted. ThirdProof investigated PandaDoc across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
27 sources queried. 100% confidence. Every PandaDoc investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get PandaDoc's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 77% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
ISO 27001 claim found on trust page (Vendor attested)
Q41
Not found in FedRAMP marketplace
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
+ 9 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get PandaDoc's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
PandaDoc is not listed on the FedRAMP Marketplace.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
27
Sources Queried
26
Sources With Data
April 17, 2026
Last Assessed
AI-generated analysis for PandaDoc
PandaDoc is a SaaS document management and e-signature platform assessed at Tier 3 (Moderate Risk), reflecting a vendor with a solid foundational security posture that carries several unresolved verification gaps requiring attention before unconditional approval. PandaDoc demonstrates a number of meaningful positive security signals. The domain has been established since 2013 and carries a fully clean reputation — no malware listings, no adverse media in the past 12 months, no sanctions matches, and no SEC or regulatory enforcement history. The security practices page documents strong operational controls, including:
however, none of these could be independently verified through public registries during this assessment. The inherited designations for ISO 27001 and FedRAMP indicate reliance on AWS infrastructure certifications rather than PandaDoc's own direct authorization, a distinction compliance teams should understand clearly. Additionally, the marketing site (pandadoc.com) received a HTTP security scanner grade of D (30/100), indicating gaps in HTTP security headers including Content-Security-Policy and X-Frame-Options, creating a measurable inconsistency with the otherwise strong TLS and HSTS configuration. The automated subprocessor page parser was unable to extract individual subprocessor records from pandadoc.com/docs/subprocessors, leaving the supply chain partially unvalidated. Overall, PandaDoc presents as a commercially mature SaaS vendor with credible security documentation and a clean external risk profile, but the combination of unverified certifications and HTTP header gaps warrants conditional engagement pending completion of the actions described below.
Independence Statement
All evidence in this assessment was independently sourced from public registries, threat intelligence feeds, DNS/TLS infrastructure scans, and automated web crawls without vendor participation or input.
5 findings identified for PandaDoc
PandaDoc, Inc. was first registered in the LEI system less than 1 year ago (2026-01-14T12:12:28Z).
pandadoc.com is missing 2 recommended security headers: Content-Security-Policy, X-Frame-Options.
5 potentially sensitive port(s) are publicly accessible on pandadoc.com: 21 (FTP), 110 (POP3), 143 (IMAP), 3306 (MySQL), 9200 (Elasticsearch). However, this IP belongs to Cloudflare edge infrastructure. These ports are likely CDN management interfaces, not direct access to pandadoc.com's backend services.
pandadoc.com received a poor grade (D) from Mozilla HTTP Observatory. Multiple security headers or configurations are missing. Note: This scan was performed on the marketing site (pandadoc.com). The application endpoint (app.pandadoc.com) may have different security headers. Verify the application domain separately.
pandadoc.com has certificates from 63 different Certificate Authorities. This may indicate inconsistent certificate management practices.
28 positive signals verified
Legal Entity Actively Registered
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Adverse Media Found
Adverse Media Scan →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →Established Domain (13+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Minimal Tech Community Discussion
Tech Community Sentiment →Large Certificate Footprint (106 subdomains)
Certificate Transparency →Established Web Presence (13+ years)
Web Archive History →No Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: PCI DSS (Inherited)
Trust & Compliance Page Scan →Certification Claimed: HIPAA
Trust & Compliance Page Scan →Certification Claimed: GDPR
Trust & Compliance Page Scan →Certification Claimed: CCPA
Trust & Compliance Page Scan →Certification Claimed: ISO 27001 (Inherited)
Trust & Compliance Page Scan →Certification Claimed: FedRAMP (Inherited)
Trust & Compliance Page Scan →Subprocessor Page Found, No Entries Parsed
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →No Historical Adverse Media Found
Historical Media Search →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Deep Document Crawler Results
Deep Document Analysis →Steps to address findings for PandaDoc
Request PandaDoc's current SOC 2 Type II audit report and bridge letter — email their security team via the contact form at pandadoc.com/security or ask your account executive; many vendors will share this under a standard NDA within a few business days.
Manually review the subprocessor list at pandadoc.com/docs/subprocessors and cross-reference any subprocessors that will have access to your data against your organization's vendor risk criteria; for EU-regulated data, confirm these subprocessors are covered under PandaDoc's Data Processing Agreement.
Ask PandaDoc's security team to run and share a HTTP security scanner or equivalent HTTP security header scan specifically for app.pandadoc.com (the application endpoint) to determine whether the D-grade finding on the marketing site reflects application-layer header gaps.
Request written clarification from PandaDoc distinguishing their own direct compliance authorizations (e.g., a PandaDoc-specific SOC 2 scope) from inherited cloud provider certifications (AWS ISO 27001, FedRAMP) referenced on their compliance page.
If your organization processes protected health information using PandaDoc, confirm HIPAA BAA availability and request a signed BAA before going live — contact PandaDoc's legal team through pandadoc.com/security.
If AI-assisted features within PandaDoc will process sensitive customer content, request explicit written disclosure of which AI providers are used, whether customer data is used for model training, and what opt-out mechanisms are available — this information was not publicly stated at the time of assessment.
27 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you PandaDoc? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is PandaDoc on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is PandaDoc's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is PandaDoc a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has PandaDoc appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is PandaDoc's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are PandaDoc's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does PandaDoc claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does PandaDoc depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has PandaDoc appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
ThirdProof assigned PandaDoc a High Risk (Tier 2) rating at 84% confidence. Clean sanctions, clean domain reputation, and no adverse media — but significant infrastructure exposure (247 open ports) and a weak HTTP security header profile drive the tier. Before approving PandaDoc for contract, NDA, or other legal document workflows, review the full assessment findings and request PandaDoc's SOC 2 Type II report.
Seeing this in an audit? ThirdProof lets you investigate PandaDoc and every other vendor in your stack — average report time: 7 minutes. Get PandaDoc's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates PandaDoc across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.