ISO 27018-Compliant Security Vendors
Security vendors that hold ISO 27018 certification
Okta
21/32Identity and access management platform providing secure authentication, authorization, and single sign-on for enterprises.
ISO/IEC 27018:2019
Zscaler
14/32Cloud-native zero trust security platform (ZIA/ZPA) for secure internet and application access.
Wiz
13/32Cloud-native application protection platform (CNAPP) for cloud security.
Splunk
11/32Data platform for security, observability, and IT operations (SIEM, log analytics), owned by Cisco.
Netskope
11/32Security service edge (SSE) and cloud security platform (CASB, SWG, ZTNA).
Orca Security
10/32Agentless cloud security platform (CNAPP) for cloud workload and configuration risk.
2025
1Password
9/32Password manager and secure digital wallet that stores passwords, documents, and sensitive information with end-to-end encryption.
ISO/IEC 27018:2019
Fortinet
9/32Network security and cybersecurity platform (firewalls, SASE, endpoint security).
Cybereason
9/32Endpoint detection and response (EDR/XDR) cybersecurity platform.
Keeper
9/32Password management and privileged access security platform.
SentinelOne
8/32AI-powered endpoint, cloud, and identity security (XDR) platform.
KnowBe4
8/32Security awareness training and simulated phishing platform.
Auth0
8/32Identity and access management (authentication-as-a-service) platform, owned by Okta.
Varonis
8/32Data security platform for data classification, access governance, and threat detection.
Bitdefender
8/32Cybersecurity platform for consumer and enterprise endpoint protection.
Darktrace
5/32AI-powered cybersecurity platform for threat detection and autonomous response.
2019
McAfee
5/32Consumer and enterprise antivirus, identity, and online privacy protection platform.
Ping Identity
3/32Enterprise identity and access management (IAM) platform.
These security vendors do not currently hold ISO 27018 certification:
- CrowdStrike (not documented)
- Snyk (not documented)
- Palo Alto Networks (not documented)
- Cisco Duo (not documented)
- Check Point (not documented)
- Rapid7 (not documented)
- Tenable (not documented)
- Qualys (not documented)
- Proofpoint (not documented)
- Mimecast (not documented)
- OneLogin (not documented)
- JumpCloud (not documented)
- LastPass (not documented)
- Dashlane (not documented)
- Bitwarden (not documented)
- Lacework (not documented)
- VMware Carbon Black (not documented)
- Trend Micro (not documented)
- Symantec (not documented)
- Sophos (not documented)
- ESET (not documented)
- Malwarebytes (not documented)
- Keeper Security (not documented)
- Ivanti (not documented)
- Tailscale (not documented)
- Checkmarx (not documented)
- Veracode (not documented)
- GitGuardian (not documented)
- Semgrep (not documented)
- Clerk (not documented)
- WorkOS (not documented)
Know a vendor we're missing?