Compliance frameworks, security audits, and quality certifications this company maintains.
1Password undergoes annual SOC 2 Type II audits across all five Trust Services Criteria, demonstrating that its password management infrastructure and internal controls meet rigorous standards for security, availability, and confidentiality.
1Password maintains ISO 27001 certification for its information security management system, providing enterprise customers with independent verification that security controls governing the platform and employee practices meet international standards.
1Password is fully GDPR-compliant, offering EU data residency options, a comprehensive Data Processing Agreement, and tools that allow customers to manage, export, and delete personal data stored in 1Password vaults.
1Password complies with the California Consumer Privacy Act, giving California residents rights to access, delete, and opt out of the sale of their personal information processed through 1Password's consumer and business products.
1Password adheres to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), reflecting its Canadian origins and ensuring Canadian users' personal data is handled in accordance with federal privacy law.
1Password is certified as a FIDO2-compliant platform, supporting passkey storage and WebAuthn-based passwordless authentication flows to help organizations transition away from knowledge-based credentials.
1Password is pursuing FedRAMP authorization to enable US federal government agencies to adopt its Enterprise Password Manager and Extended Access Management platform for securing sensitive government credentials.
1Password supports HIPAA-compliant workflows for healthcare customers, providing Business Associate Agreement (BAA) options and enabling clinical teams to store and share protected health information credentials with appropriate access controls.
1Password has completed the Cloud Security Alliance STAR Level 1 self-assessment, publishing its security controls documentation in the CSA registry to give prospective enterprise customers transparent visibility into cloud security practices.
Accessibility
Accessibility WCAG 2.1 AA
Compliant1Password's web application and browser extensions conform to WCAG 2.1 Level AA accessibility guidelines, ensuring that users with disabilities can fully use the password manager across screen readers, keyboard navigation, and assistive technologies.