Skip to main content
Skip to main content

1Password Vendor Risk & Security Assessment

ThirdProof independently checks public intelligence sources to show what your team can verify about 1Password before 1Password sends a questionnaire or a security document.

1Password's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from 1Password — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on 1Password's own trust page.

1Password was not found in the FedRAMP Marketplace. Checked August 2026.

This matters if you place federal workloads with this vendor: agencies may only use cloud services holding a FedRAMP certification. It carries no weight for a purely commercial deployment.

Risk
Tier 3Moderate Risk
Evidence confidence
100%
26 of 27 sources returned data
Questionnaire
85 / 133 answered
64% from public evidence
Last assessed
Aug 27, 2026

Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.

🟢IP Reputation: Abuse score: 0%, 0 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 22.7 years🟢Infrastructure: 9 open ports, 0 CVEs
FedRAMP Status
1Password is not listed on the FedRAMP Marketplace (checked August 2026).
SOC 2 Status
1Password — SOC 2: Vendor attested — trust page. SOC 2 reports are confidential with no public registry, so compliance status is not publicly verifiable. Request the full Type II report and bridge letter directly from the vendor.
Sanctions Screening
1Password returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned 1Password a Moderate Risk tier across 27 intelligence sources, 26 of which returned usable evidence (evidence confidence 100%).

27 sources queried, 26 returning usable evidence. The 1Password assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.

Get the Latest 1Password Vendor Assessment →
Full risk assessment + 133-question security questionnaire|Free · Delivered by email

Certification & Compliance Status

Security questionnaire — auto-filled

85 questions answered before 1Password responds.

ThirdProof used public evidence to pre-fill 64% of a 133-question vendor security questionnaire — without waiting for 1Password. The remaining 48 are listed as open, so the follow-up you send is short and specific.

Q39

Are you PCI DSS compliant? At what level?

There is no PCI DSS standard for password managers; 1Password is SOC 2 Type 2 certified but not PCI DSS compliant as PCI DSS does not apply to password managers.

Public evidencehigh confidence

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: Vendor attested — trust page

Public evidencemedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

1Password has DPAs available including a Data Protection Addendum (DPA) document (v4.6-02032025) available at their legal center for GDPR compliance.

Public evidencehigh confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

1Password can support many HIPAA-aligned controls but does not make you HIPAA compliant on its own; AgileBits is not defined as a Business Associate pursuant to HIPAA due to their zero-knowledge security model, so BAAs are not required.

Public evidencehigh confidence

Q23

Is data encrypted at rest? What encryption standard is used (e.g., AES-256)?

1Password uses 256-bit AES encryption (AES-256) for data at rest, with the encrypted symmetric key itself encrypted using AES256-GCM.

Public evidencehigh confidence

+ 80 additional evidence-backed answers

Get the Complete 1Password Assessment →

See all 133 questions, evidence links, findings, and the vendor follow-ups still required.

What you can verify before 1Password sends anything

Independent evidence settles part of the review. The rest still needs the vendor.

Public evidence establishes

  • No Sanctions Matches Found
  • No SEC Enforcement Filings Found
  • Clean domain reputation
  • Clean Safe Browsing Status
  • Clean Website Security Scan

Still requires vendor confirmation

  • Current SOC 2 report and its audit scope
  • Incident Response — 6 of 10 questions need vendor input
  • Application Security — 6 of 7 questions need vendor input
  • Access Control — 5 of 12 questions need vendor input
  • Governance & Risk — 4 of 10 questions need vendor input

Reviewing 1Password for your company?

Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.

5 vendors free · No credit card

Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing

Executive Summary

Narrative analysis for 1Password

1Password is an established password manager and identity access platform founded over 22 years ago with a substantial security and compliance program. The vendor demonstrates meaningful strengths across infrastructure security, data protection, and regulatory alignment, including independently verified ISO 27001:2022 certification, documented incident response and penetration testing programs, and EU data residency options. Positive signals include:

Key Findings

  • ISO 27001:2022 certification with active status, covering information security management
  • Clean domain reputation across threat intelligence databases; no malware or phishing threats detected
  • Documented penetration testing by independent third parties and responsive vulnerability disclosure program
  • Zero-knowledge architecture limiting the vendor's own access to customer data
  • Strong governance signals, including a named CISO and published security assessments
  • GDPR compliance with Data Protection Addendum (DPA) readily available Areas requiring attention include:
  • Subprocessor list could not be parsed from the published page; manual review is needed to understand the full supply chain
  • AI data handling practices lack clarity—the vendor does not explicitly state whether customer data is used for model training, and data retention for AI purposes is documented as indefinite
  • SOC 2 Type II certification is vendor-attested but not independently verified; a current report should be requested
  • TLS certificate renewal is approaching in 88 days; confirm automated renewal processes are in place
  • One documented security incident in adverse media scan related to the 2023 Okta breach affecting employee-facing systems Overall, 1Password presents a moderate risk profile with solid foundational security practices but requires clarification on AI data practices and confirmation of subprocessor oversight. The Tier 3 rating reflects these gaps against the backdrop of otherwise strong controls.

Independence Statement

All evidence in this assessment was independently sourced from external data providers, publicly available registries, and the vendor's published pages without vendor participation.

Investigation Findings

4 findings identified for 1Password

2 medium2 low
medium

AI training data practices unclear

The [vendor's AI-related policy page](https://1password.com/legal/api-sdk-terms-of-service) does not clearly state whether customer data is used for training AI models. The commitment is marked as 'unclear' and no explicit prohibition or opt-out mechanism is documented for core password management data. …

medium

Indefinite data retention for AI processing

The vendor's policy language indicates indefinite data retention for 'trade secrets' and certain processing purposes. For AI contexts, indefinite retention creates uncertainty around when customer data will be purged after account termination or service cancellation, particularly if data has been used for model training or analysis.

low

Subprocessor list could not be parsed

The [vendor's published subprocessor page](https://trust.1password.com/subprocessors) was identified but the list of individual subprocessors could not be extracted via automated parsing. This prevents independent verification of the supply chain without manual review. …

low

2 certifications claimed but not independently verified

SOC 2 Type II and CCPA compliance are mentioned on [the vendor's security page](https://1password.com/security) but could not be independently verified through public registries. SOC 2 reports are confidential by design and no public registry exists; CCPA is a privacy regulation not a certification. …

Showing the 4 most severe of 5 findings.

Security Strengths

Evidence that positively supports 1Password's posture

Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.

No Sanctions Matches Found

Sanctions & Watchlist Screening

No SEC Enforcement Filings Found

SEC Filing Search

Clean domain reputation

Threat Intelligence

Clean Safe Browsing Status

Malware & Phishing Check

Clean Website Security Scan

Website Security Scan

Clean IP Reputation

IP Reputation

Established Domain (22+ years)

Domain Registration

1Password complete vendor assessment

Tier 3
Moderate Risk
85 / 133
questionnaire answers
27
sources checked
Aug 27, 2026
assessment date
  • Complete 133-question security questionnaire
  • Evidence behind every answered item
  • Full findings and risk rationale
  • Recommended vendor follow-ups
  • Source and evidence inventory
  • Source-cited PDF assessment

Free · No account required

Latest ThirdProof assessment: Aug 27, 2026. Requesting it sends that existing report — it does not start a new investigation.

Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.

1Password Security and Compliance Status

1Password is a password management platform claiming SOC 2 and CCPA compliance. 1Password is not listed on the FedRAMP Marketplace and has not pursued FedRAMP authorization. For organizations managing credential vaults across teams, 1Password's zero-knowledge architecture means the vendor cannot access stored credentials — but organizations should verify this claim through 1Password's SOC 2 report and assess the security implications of 10 open ports identified during ThirdProof's infrastructure scan.

1Password Security Posture

ThirdProof investigated 1Password across 27 intelligence sources. Sanctions screening returned clear with no matches. Domain reputation is clean across 93 security engines with a 22-year domain history. The SSL/TLS grade is B and the HTTP security grade is C- (45/100) — these infrastructure findings should be weighed against 1Password's application-layer security model and zero-knowledge architecture.

Frequently asked about 1Password

Is 1Password FedRAMP authorized?+
1Password was not found in the FedRAMP Marketplace when it was checked on August 27, 2026. Absence of a public record is not evidence that the certification is absent; organisations with a hard requirement should confirm directly with the vendor.
Does 1Password have SOC 2 Type II?+
1Password states that it maintains SOC 2 on its trust page. Because SOC 2 reports are generally confidential and there is no public SOC 2 registry, ThirdProof classifies this as vendor-attested until the current report and its scope have been reviewed. Request the report directly to confirm the audit period and which systems are in scope.
Is 1Password on the OFAC sanctions list?+
1Password returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of August 2026.
What is 1Password's vendor risk tier?+
ThirdProof assigned 1Password a risk tier of Moderate Risk as of August 2026, with an evidence confidence of 100% across 27 intelligence sources. Evidence confidence describes how much of the evidence ThirdProof set out to gather it was able to gather — not certainty about every fact concerning 1Password.
Has 1Password had any data breaches or security incidents?+
ThirdProof's adverse media and incident screening as of August 2026 did not surface a validated security incident involving 1Password. Public sources do not record every incident, so this is not a guarantee that none occurred — ask 1Password directly for its incident disclosure history and breach notification commitments.
Is 1Password PCI DSS compliant?+
There is no PCI DSS standard for password managers; 1Password is SOC 2 Type 2 certified but not PCI DSS compliant as PCI DSS does not apply to password managers. ThirdProof records this from 1Password's published compliance evidence; request the current Attestation of Compliance to confirm the scope that applies to your integration.
Does 1Password support HIPAA and sign BAAs?+
1Password can support many HIPAA-aligned controls but does not make you HIPAA compliant on its own; AgileBits is not defined as a Business Associate pursuant to HIPAA due to their zero-knowledge security model, so BAAs are not required. If protected health information is in scope for your use, confirm BAA availability in writing before contracting.
Can ThirdProof pre-fill a 1Password security questionnaire?+
Yes. ThirdProof answered 85 of 133 questions (64%) about 1Password from public evidence, before contacting the vendor. Each answered item carries the evidence it was drawn from. The remaining 48 are listed as open, so the follow-up you send 1Password is short and specific.

Represent 1Password? Submit updated security evidence.

If 1Password is in your vendor stack, can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The 1Password assessment above is already written; ask for it and it lands in your inbox.

✓ This assessment: free, no account required✓ Your first 5 vendor investigations are free✓ No credit card required