ControlUp · Trust Center

Controlup Trust Center

Trust center

ControlUp maintains a public trust center documenting ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 27701:2019, SOC 2 Type 2, SOC 3, FIPS 140-2 Level 1, CSA STAR Level 1, and GDPR compliance.

digital-employee-experienceendpoint-managementvdidaasvirtual-desktopobservabilitymonitoringsynthetic-monitoringdevice-managementcompliancevulnerability-managementworkflow-automationcitrixazure-virtual-desktopmcpagent-native
Trust center: https://trustcenter.controlup.com/

Certifications & Compliance

ISO/IEC 27001:2022ISO/IEC 27017:2015ISO/IEC 27018:2019ISO/IEC 27701:2019SOC 2 Type 2SOC 3FIPS 140-2 Level 1CSA STAR Level 1GDPR

Source

Trust Center

Raw ↑
generated: '2026-08-04'
method: searched
probe: true
url: https://trustcenter.controlup.com/
provider: SafeBase
certifications:
- ISO/IEC 27001:2022
- ISO/IEC 27017:2015
- ISO/IEC 27018:2019
- ISO/IEC 27701:2019
- SOC 2 Type 2
- SOC 3
- FIPS 140-2 Level 1
- CSA STAR Level 1
- GDPR
programs:
- {name: Information Security Management System (ISMS), source: trust center}
- {name: Privacy Information Management System (PIMS), source: trust center}
- {name: AI Governance, source: trust center}
- {name: Application Penetration Testing, source: trust center}
- {name: Business Continuity Plan (BCP), source: trust center}
- {name: Disaster Recovery Plan (DRP), source: trust center}
- {name: Privacy Impact Assessment, source: trust center}
- {name: ISO/IEC 27001 Statement of Applicability (SoA), source: trust center}
- {name: CSA Consensus Assessments Initiative Questionnaire (CAIQ), source: https://www.controlup.com/controlling-your-security/}
in_progress:
- {name: FedRAMP authorization, status: 'ControlUp states it "has embarked on the FedRAMP authorization journey"; authorization not completed.', source: https://www.controlup.com/controlling-your-security/}
auditor:
  name: EY (Ernst & Young)
  scope: SOC 2 / SOC 3 audit of security controls and processes for ControlUp products and services
  note: SOC 3 report concluded February 2022 covering 1 January – 31 December 2021, freely distributable for public use.
  source: https://www.controlup.com/controlling-your-security/
public_documents:
- {name: ControlUp Security White Paper, host: https://www.controlup.com/controlling-your-security/}
- {name: GDPR Privacy Statement, host: https://www.controlup.com/controlling-your-security/}
- {name: AI Features Security White Paper, host: https://www.controlup.com/controlling-your-security/}
evidence:
- {source: https://trustcenter.controlup.com/, fetched: '2026-08-04', kind: trust-center, keywords: [SOC 2 Type 2, SOC 3, ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 27701:2019, ISMS, PIMS, penetration testing, BCP, DRP]}
- {source: https://www.controlup.com/controlling-your-security/, fetched: '2026-08-04', kind: public compliance page, http_status: 200, keywords: [SOC 2, SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, FIPS 140-2, CSA STAR, CAIQ, GDPR, EY, FedRAMP]}
notes:
- >-
  trustcenter.controlup.com is a SafeBase-hosted portal. It returns HTTP 403 to a plain command-line client and
  renders for a browser user-agent; the certification list above was read from the rendered page. Detailed reports
  (SOC 2 report, ISO certificates, pen-test summary) sit behind an NDA request flow, which is the normal SafeBase
  pattern — the certification INVENTORY is public, the artifacts are gated.
- HIPAA is not claimed anywhere on ControlUp's public compliance surface.