generated: '2026-09-05' method: searched probe: true url: https://www.confluent.io/trust-and-security/ trust_portal: https://confluent.safebase.us/ trust_portal_note: >- The SafeBase-hosted trust portal returned HTTP 403 to this crawler on 2026-09-05 (a bot policy, not a dead page — SafeBase gates automated agents and serves the document set to a browser session). Recorded as live-but-gated rather than dead. certifications: - SOC 1 Type 2 - SOC 2 Type 2 - SOC 3 - ISO 27001 - ISO 27701 - PCI DSS - CSA STAR Level 2 - HITRUST CSF - TISAX certification_detail: - name: SOC 1 Type 2 scope: Confluent Cloud and Confluent Platform note: User entities' internal control over financial reporting. - name: SOC 2 Type 2 scope: Confluent Cloud and Confluent Platform note: Non-financial reporting controls for security, availability and confidentiality. - name: SOC 3 scope: Confluent Cloud and Confluent Platform note: General-use report on non-financial controls. - name: ISO 27001 note: Three-year certification with annual surveillance audits. - name: ISO 27701 note: Privacy information management for personal data processing. - name: PCI DSS note: Attestation available on request. - name: CSA STAR Level 2 note: Self-assessment via the Consensus Assessments Initiative Questionnaire. - name: HITRUST CSF note: Annual certification, healthcare security framework. - name: TISAX note: 'German automotive assessment. Scope-ID: SR5PY9; Assessment-ID: AV29AS-1.' regulatory_readiness: [GDPR, CCPA, HIPAA, LGPD, DORA, 'FedRAMP Moderate (Confluent Cloud for Government)'] security_programs: bug_bounty: status: invitation-only contact: security@confluent.io penetration_testing: Third-party annual assessments with findings remediation. evidence: - source: https://www.confluent.io/trust-and-security/ http_status: 200 keywords: [soc 2, iso 27001, pci dss, hitrust, tisax, csa star, gdpr, hipaa, trust] - source: https://confluent.safebase.us/ http_status: 403 note: bot-gated trust portal - source: blogs/2026-03-10-confluent-cloud-for-government-achieves-fedramp-moderate-mis.md note: provider blog post announcing FedRAMP Moderate authorization