Compliance frameworks, security audits, and quality certifications this company maintains.
PagerDuty maintains SOC 2 Type II certification covering security, availability, and confidentiality trust service criteria, ensuring that controls protecting customer operational data and incident telemetry processed through PagerDuty Operations Cloud meet AICPA standards.
PagerDuty holds ISO 27001 certification for its information security management system, demonstrating that the policies and controls governing customer alert data, on-call schedules, and incident records meet internationally recognized security requirements.
Regulatory
FedRAMP Moderate
CertifiedPagerDuty has achieved FedRAMP Moderate authorization, enabling US federal agencies and government contractors to use PagerDuty Operations Cloud for managing operational incidents while meeting federal cloud security requirements.
PagerDuty is fully compliant with the EU General Data Protection Regulation, offering EU data residency options, Data Processing Agreements, and privacy controls enabling PagerDuty customers to process incident and operational data in accordance with GDPR obligations.
PagerDuty offers Business Associate Agreements for healthcare organizations, enabling HIPAA-compliant use of PagerDuty incident management for hospital IT and clinical operations teams where protected health information may appear in incident metadata.
PagerDuty is PCI DSS compliant, ensuring that payment card data referenced in incident alerts and operational runbooks executed through PagerDuty Process Automation is handled in accordance with Payment Card Industry Data Security Standards.
PagerDuty supports California Consumer Privacy Act compliance by providing contractual commitments and data rights tooling enabling customers to manage personal data processed through PagerDuty incident management and on-call scheduling systems.
PagerDuty holds ISO 27017 certification for cloud-specific information security controls, demonstrating that PagerDuty cloud service delivery practices for Operations Cloud and Process Automation meet internationally recognized cloud security guidelines.
PagerDuty designs its web and mobile operations platforms to conform with WCAG 2.1 Level AA accessibility standards, ensuring that on-call engineers and operations teams with disabilities can use PagerDuty incident management tools effectively.
PagerDuty holds CSA STAR Level 2 certification, demonstrating that PagerDuty cloud security practices have been independently assessed by a third-party auditor against the Cloud Security Alliance Cloud Controls Matrix requirements.