Compliance frameworks, security audits, and quality certifications this company maintains.
SailPoint holds SOC 2 Type II certification for Identity Security Cloud, required by enterprise customers in financial services and healthcare who must audit the security controls of their identity governance provider before trusting it with all access policy data.
SailPoint is ISO 27001 certified across its cloud platform operations, providing global enterprise customers with assurance that SailPoint applies systematic information security management to the identity data it processes.
Regulatory
FedRAMP Moderate
CertifiedSailPoint Identity Security Cloud is FedRAMP Moderate authorized, enabling US federal agencies to use SailPoint for governing employee and contractor access to government applications and classified systems.
SailPoint processes EU employee identity and access data in compliance with GDPR, with EU data residency options in European AWS regions and data processing agreements covering all enterprise customer identity data.
Regulatory
SOX Compliance Support
CompliantSailPoint's access certification and separation of duties capabilities directly support customer SOX IT General Controls compliance, with audit-ready reports proving that access to financial systems is periodically certified and policy violations are remediated.
SailPoint supports HIPAA-covered entity customers with BAAs covering identity governance of EHR system access, enabling healthcare organizations to demonstrate that only authorized personnel have access to PHI.
SailPoint holds ISO 27701 privacy information management certification, demonstrating its compliance with international privacy standards for the personal identity data processed as part of its enterprise IGA services.
SailPoint complies with CCPA for California employee data processed through its IGA platform, with data subject rights processes enabling enterprise customers to honor their own California employee privacy obligations.
SailPoint aligns its internal security program with the NIST Cybersecurity Framework, using the Identify, Protect, Detect, Respond, and Recover functions to structure its security operations protecting customer identity data and the IdentityNow platform.
SailPoint IdentityNow and SailPoint IdentityIQ hold Common Criteria (ISO 15408) evaluation for identity governance functionality, providing government and regulated industry customers with assurance of rigorous independent security testing.