Executive Summary
AI-generated analysis for Zapier
Zapier (zapier.com) is a well-established workflow automation and AI orchestration platform serving over 3 million businesses, assessed at Risk Tier 3 (Moderate Risk) with a confidence score of 84%. This rating reflects a mature operational profile tempered by several compliance verification gaps and AI data handling considerations relevant to organizations sharing medium-sensitivity data. Positive signals are substantial. Zapier demonstrates a clean security posture across multiple independent threat intelligence dimensions:
Key Findings
- Domain is confirmed clean across URLhaus, SURBL, Spamhaus DBL, and Malware detection service with no active malware URLs
- Infrastructure presents only 2 open ports (80/443) behind a CDN layer, representing a minimal and well-controlled footprint significantly below the SaaS industry average of 8–12 open ports, with zero known CVEs
- No sanctions or watchlist matches were identified across OFAC, EU, and UN lists
- The company is a legally registered active entity (ZAPIER, INC., LEI: 254900XIXKZQ7A7N1M29, incorporated in Delaware)
- A 14+ year archived web presence confirms a long-established domain
- HTTP security headers earned a Grade B (70/100), indicating most headers are properly configured
- All 12 published subprocessors — including AWS, Anthropic, Google, Databricks, and Datadog — cleared sanctions and safety screening
- SOC 2 (Type II) and GDPR compliance are claimed by the vendor, with SOC 2 also referenced on the vendor's security and compliance page Several areas require attention before this vendor is approved for data-sharing workflows. SOC 2 and GDPR certifications are vendor-attested and have not been independently verified through a public registry — procurement teams should obtain the current SOC 2 Type II report and bridge letter directly. Zapier's AI data usage policy discloses an opt-out model for AI model training: Enterprise customers receive automatic opt-out, while all other customers must actively opt out — this distinction is material for non-enterprise deployments. A historical security incident involving a 2FA configuration issue was identified in media archives; while age-adjusted to low severity, it warrants review of Zapier's current MFA enforcement posture. Certificate transparency logs reveal 17 distinct certificate authorities in use across 332 subdomains, which may indicate heterogeneous certificate management practices across a large infrastructure. AI data retention periods are not clearly specified in the vendor's published policy. Overall, Zapier presents as a mature, broadly trusted SaaS platform with a clean threat profile and transparent subprocessor disclosure. The Tier 3 (Moderate Risk) rating is driven primarily by unverified compliance certifications, AI training opt-out requirements, and the absence of independently confirmed ISO 27001 certification — gaps that are resolvable through direct vendor engagement. A conditional approval is appropriate pending receipt of the SOC 2 Type II report and confirmation of AI opt-out status for the specific account tier in use.
Independence Statement
All evidence in this report was independently sourced from external public registries, threat intelligence platforms, DNS infrastructure, certificate transparency logs, web archives, and media databases without participation or input from Zapier.