Q39
Are you PCI DSS compliant? At what level?
There is no PCI DSS standard for password managers; 1Password is SOC 2 Type 2 certified but not PCI DSS compliant as PCI DSS does not apply to password managers.
ThirdProof independently checks public intelligence sources to show what your team can verify about 1Password before 1Password sends a questionnaire or a security document.
1Password's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from 1Password — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on 1Password's own trust page.
⚠ 1Password was not found in the FedRAMP Marketplace. Checked August 2026.
This matters if you place federal workloads with this vendor: agencies may only use cloud services holding a FedRAMP certification. It carries no weight for a purely commercial deployment.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 26 returning usable evidence. The 1Password assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest 1Password Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 64% of a 133-question vendor security questionnaire — without waiting for 1Password. The remaining 48 are listed as open, so the follow-up you send is short and specific.
Q39
There is no PCI DSS standard for password managers; 1Password is SOC 2 Type 2 certified but not PCI DSS compliant as PCI DSS does not apply to password managers.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
1Password has DPAs available including a Data Protection Addendum (DPA) document (v4.6-02032025) available at their legal center for GDPR compliance.
Q40
1Password can support many HIPAA-aligned controls but does not make you HIPAA compliant on its own; AgileBits is not defined as a Business Associate pursuant to HIPAA due to their zero-knowledge security model, so BAAs are not required.
Q23
1Password uses 256-bit AES encryption (AES-256) for data at rest, with the encrypted symmetric key itself encrypted using AES256-GCM.
+ 80 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing 1Password for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for 1Password
1Password is an established password manager and identity access platform founded over 22 years ago with a substantial security and compliance program. The vendor demonstrates meaningful strengths across infrastructure security, data protection, and regulatory alignment, including independently verified ISO 27001:2022 certification, documented incident response and penetration testing programs, and EU data residency options. Positive signals include:
Independence Statement
All evidence in this assessment was independently sourced from external data providers, publicly available registries, and the vendor's published pages without vendor participation.
4 findings identified for 1Password
The [vendor's AI-related policy page](https://1password.com/legal/api-sdk-terms-of-service) does not clearly state whether customer data is used for training AI models. The commitment is marked as 'unclear' and no explicit prohibition or opt-out mechanism is documented for core password management data. …
The vendor's policy language indicates indefinite data retention for 'trade secrets' and certain processing purposes. For AI contexts, indefinite retention creates uncertainty around when customer data will be purged after account termination or service cancellation, particularly if data has been used for model training or analysis.
The [vendor's published subprocessor page](https://trust.1password.com/subprocessors) was identified but the list of individual subprocessors could not be extracted via automated parsing. This prevents independent verification of the supply chain without manual review. …
SOC 2 Type II and CCPA compliance are mentioned on [the vendor's security page](https://1password.com/security) but could not be independently verified through public registries. SOC 2 reports are confidential by design and no public registry exists; CCPA is a privacy regulation not a certification. …
Showing the 4 most severe of 5 findings.
Evidence that positively supports 1Password's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No Sanctions Matches Found
Sanctions & Watchlist Screening →No SEC Enforcement Filings Found
SEC Filing Search →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Clean IP Reputation
IP Reputation →Established Domain (22+ years)
Domain Registration →1Password complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
1Password is a password management platform claiming SOC 2 and CCPA compliance. 1Password is not listed on the FedRAMP Marketplace and has not pursued FedRAMP authorization. For organizations managing credential vaults across teams, 1Password's zero-knowledge architecture means the vendor cannot access stored credentials — but organizations should verify this claim through 1Password's SOC 2 report and assess the security implications of 10 open ports identified during ThirdProof's infrastructure scan.
ThirdProof investigated 1Password across 27 intelligence sources. Sanctions screening returned clear with no matches. Domain reputation is clean across 93 security engines with a 22-year domain history. The SSL/TLS grade is B and the HTTP security grade is C- (45/100) — these infrastructure findings should be weighed against 1Password's application-layer security model and zero-knowledge architecture.
Represent 1Password? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The 1Password assessment above is already written; ask for it and it lands in your inbox.