generated: '2026-08-04' method: searched probe: true url: https://trustcenter.controlup.com/ provider: SafeBase certifications: - ISO/IEC 27001:2022 - ISO/IEC 27017:2015 - ISO/IEC 27018:2019 - ISO/IEC 27701:2019 - SOC 2 Type 2 - SOC 3 - FIPS 140-2 Level 1 - CSA STAR Level 1 - GDPR programs: - {name: Information Security Management System (ISMS), source: trust center} - {name: Privacy Information Management System (PIMS), source: trust center} - {name: AI Governance, source: trust center} - {name: Application Penetration Testing, source: trust center} - {name: Business Continuity Plan (BCP), source: trust center} - {name: Disaster Recovery Plan (DRP), source: trust center} - {name: Privacy Impact Assessment, source: trust center} - {name: ISO/IEC 27001 Statement of Applicability (SoA), source: trust center} - {name: CSA Consensus Assessments Initiative Questionnaire (CAIQ), source: https://www.controlup.com/controlling-your-security/} in_progress: - {name: FedRAMP authorization, status: 'ControlUp states it "has embarked on the FedRAMP authorization journey"; authorization not completed.', source: https://www.controlup.com/controlling-your-security/} auditor: name: EY (Ernst & Young) scope: SOC 2 / SOC 3 audit of security controls and processes for ControlUp products and services note: SOC 3 report concluded February 2022 covering 1 January – 31 December 2021, freely distributable for public use. source: https://www.controlup.com/controlling-your-security/ public_documents: - {name: ControlUp Security White Paper, host: https://www.controlup.com/controlling-your-security/} - {name: GDPR Privacy Statement, host: https://www.controlup.com/controlling-your-security/} - {name: AI Features Security White Paper, host: https://www.controlup.com/controlling-your-security/} evidence: - {source: https://trustcenter.controlup.com/, fetched: '2026-08-04', kind: trust-center, keywords: [SOC 2 Type 2, SOC 3, ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 27701:2019, ISMS, PIMS, penetration testing, BCP, DRP]} - {source: https://www.controlup.com/controlling-your-security/, fetched: '2026-08-04', kind: public compliance page, http_status: 200, keywords: [SOC 2, SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, FIPS 140-2, CSA STAR, CAIQ, GDPR, EY, FedRAMP]} notes: - >- trustcenter.controlup.com is a SafeBase-hosted portal. It returns HTTP 403 to a plain command-line client and renders for a browser user-agent; the certification list above was read from the rendered page. Detailed reports (SOC 2 report, ISO certificates, pen-test summary) sit behind an NDA request flow, which is the normal SafeBase pattern — the certification INVENTORY is public, the artifacts are gated. - HIPAA is not claimed anywhere on ControlUp's public compliance surface.