Compliance frameworks, security audits, and quality certifications this company maintains.
BeyondTrust holds SOC 2 Type II for its cloud-hosted PAM and Remote Support SaaS platforms, critical for enterprise customers in regulated industries who require independent validation of BeyondTrust's security controls before entrusting it with privileged access to their infrastructure.
Regulatory
FedRAMP Moderate
CertifiedBeyondTrust is FedRAMP Moderate authorized, enabling US federal agencies to use BeyondTrust Privileged Remote Access and Password Safe for securing government IT infrastructure — a critical requirement for the agency customer base BeyondTrust serves.
BeyondTrust maintains ISO 27001 certification across its global operations, providing enterprise customers with assurance that BeyondTrust applies rigorous information security controls to protect privileged access data stored in its Password Safe vault.
BeyondTrust's cryptographic modules are FIPS 140-2 validated, meeting NIST cryptographic standards required for US federal agency deployments and defense contractor environments using BeyondTrust PAM products.
BeyondTrust complies with GDPR for European customer data processed through Password Safe and Remote Support, with EU data residency options and data processing agreements covering all privileged session recordings.
BeyondTrust's PAM capabilities directly support customer PCI DSS compliance for Requirement 8 (user identification), Requirement 10 (audit trails), and Requirement 7 (least privilege) through Password Safe and EPM controls.
BeyondTrust offers HIPAA-compliant configurations for healthcare customers using Privileged Remote Access and Password Safe to control and audit privileged access to EHR systems containing protected health information.
Security
Common Criteria EAL2+
CertifiedBeyondTrust's PowerBroker Unix & Linux product holds Common Criteria EAL2+ certification, meeting international security standards required for government and defense deployments in NATO and EU member state environments.
BeyondTrust holds SOC 1 Type II certification relevant to enterprise customers who include BeyondTrust privileged access management controls in their financial reporting scope, providing assurance that BeyondTrust access controls operate effectively.
BeyondTrust aligns its internal security program with the NIST Cybersecurity Framework, using its five core functions to structure security operations and incident response protecting BeyondTrust customer identity and privileged access data.