CCPA-Compliant Security Vendors
Security vendors that hold CCPA certification
Okta
21/32Identity and access management platform providing secure authentication, authorization, and single sign-on for enterprises.
Wiz
13/32Cloud-native application protection platform (CNAPP) for cloud security.
Netskope
11/32Security service edge (SSE) and cloud security platform (CASB, SWG, ZTNA).
1Password
9/32Password manager and secure digital wallet that stores passwords, documents, and sensitive information with end-to-end encryption.
SentinelOne
8/32AI-powered endpoint, cloud, and identity security (XDR) platform.
Snyk
7/32Developer security platform for finding and fixing vulnerabilities in code, containers, and cloud infrastructure.
Bitwarden
7/32Open-source password manager and secrets management platform.
CPRA
Mimecast
5/32Email and collaboration security platform for threat protection and data resilience.
Same as GDPR
Lacework
5/32Cloud security and CNAPP platform for workload protection and compliance monitoring, now part of Fortinet.
Dashlane
4/32Password manager and credential security platform for individuals and businesses.
Clerk
4/32Authentication and user management platform for developers.
WorkOS
3/32Enterprise-readiness platform for SSO, directory sync, and authentication.
These security vendors do not currently hold CCPA certification:
- CrowdStrike (not documented)
- Palo Alto Networks (not documented)
- Zscaler (not documented)
- Cisco Duo (not documented)
- Splunk (not documented)
- Fortinet (not documented)
- Check Point (not documented)
- Rapid7 (not documented)
- Tenable (not documented)
- Qualys (not documented)
- Proofpoint (not documented)
- KnowBe4 (not documented)
- Auth0 (not documented)
- OneLogin (not documented)
- Ping Identity (not documented)
- JumpCloud (not documented)
- LastPass (not documented)
- Orca Security (not documented)
- Darktrace (not documented)
- Varonis (not documented)
- Cybereason (not documented)
- VMware Carbon Black (not documented)
- Trend Micro (not documented)
- McAfee (not documented)
- Symantec (not documented)
- Sophos (not documented)
- Bitdefender (not documented)
- ESET (not documented)
- Malwarebytes (not documented)
- Keeper Security (not documented)
- Ivanti (not documented)
- Keeper (not documented)
- Tailscale (not documented)
- Checkmarx (not documented)
- Veracode (not documented)
- GitGuardian (not documented)
- Semgrep (not documented)
Know a vendor we're missing?