GDPR-Compliant Security Vendors
Security vendors that hold GDPR certification
Okta
21/32Identity and access management platform providing secure authentication, authorization, and single sign-on for enterprises.
CrowdStrike
17/32Cloud-native endpoint protection platform providing threat intelligence, incident response, and cybersecurity solutions.
Zscaler
14/32Cloud-native zero trust security platform (ZIA/ZPA) for secure internet and application access.
Palo Alto Networks
10/32Cybersecurity platform spanning network security, cloud security, and SOC automation.
Regulation, not a certification
Orca Security
10/32Agentless cloud security platform (CNAPP) for cloud workload and configuration risk.
1Password
9/32Password manager and secure digital wallet that stores passwords, documents, and sensitive information with end-to-end encryption.
Fortinet
9/32Network security and cybersecurity platform (firewalls, SASE, endpoint security).
Cybereason
9/32Endpoint detection and response (EDR/XDR) cybersecurity platform.
Keeper
9/32Password management and privileged access security platform.
SentinelOne
8/32AI-powered endpoint, cloud, and identity security (XDR) platform.
Auth0
8/32Identity and access management (authentication-as-a-service) platform, owned by Okta.
Vendor states GDPR ready
Varonis
8/32Data security platform for data classification, access governance, and threat detection.
Vendor aligns with GDPR as a compliance framework; not itemized as a formal certification
Bitdefender
8/32Cybersecurity platform for consumer and enterprise endpoint protection.
Snyk
7/32Developer security platform for finding and fixing vulnerabilities in code, containers, and cloud infrastructure.
Rapid7
7/32Vulnerability management, detection, and response (SIEM/XDR) security platform.
DPO appointed; controls implemented, not itemized as a formal certification
Bitwarden
7/32Open-source password manager and secrets management platform.
Mimecast
5/32Email and collaboration security platform for threat protection and data resilience.
Addressed via DPA; referenced alongside CCPA/POPIA/PIPEDA as regulatory obligations rather than a formal certification
Lacework
5/32Cloud security and CNAPP platform for workload protection and compliance monitoring, now part of Fortinet.
Darktrace
5/32AI-powered cybersecurity platform for threat detection and autonomous response.
Vendor states compliant; ICO registered
ESET
5/32Cybersecurity platform for endpoint protection, antivirus, and threat detection.
Dashlane
4/32Password manager and credential security platform for individuals and businesses.
Ivanti
4/32IT and unified endpoint management, security, and service management software.
Ping Identity
3/32Enterprise identity and access management (IAM) platform.
Referenced as a regulation to comply with, not itemized as a certification
Checkmarx
3/32Application security testing (SAST/SCA) platform.
GitGuardian
3/32Secrets detection and non-human identity security platform.
WorkOS
3/32Enterprise-readiness platform for SSO, directory sync, and authentication.
Check Point
2/32Cybersecurity platform for network, cloud, and endpoint security.
Referenced in compliance solutions navigation
JumpCloud
2/32Cloud directory platform for identity, device, and access management.
Data Privacy Officer and dedicated GDPR page referenced, not a formal certification
Cisco Duo
1/32Multi-factor authentication (MFA) and zero-trust access security platform from Cisco.
Vendor states alignment with European data protection laws, not a formal certification on this page
OneLogin
1/32Identity and access management platform, owned by One Identity.
Primary compliance focus of vendor's compliance page
Tailscale
1/32Zero-config mesh VPN networking platform built on WireGuard.
GDPR Data Privacy Addendum offered; not framed as a standalone certification
These security vendors do not currently hold GDPR certification:
- Splunk (not documented)
- Tenable (not documented)
- Qualys (not documented)
- Proofpoint (not documented)
- KnowBe4 (not documented)
- LastPass (not documented)
- Wiz (not documented)
- Netskope (not documented)
- VMware Carbon Black (not documented)
- Trend Micro (not documented)
- McAfee (not documented)
- Symantec (not documented)
- Sophos (not documented)
- Malwarebytes (not documented)
- Keeper Security (not documented)
- Veracode (not documented)
- Semgrep (not documented)
- Clerk (not documented)
Know a vendor we're missing?