Q39
Are you PCI DSS compliant? At what level?
PCI DSS compliance claim found on trust page (Vendor attested)
ThirdProof independently checks public intelligence sources to show what your team can verify about Heroku before Heroku sends a questionnaire or a security document.
Heroku's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Heroku — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Heroku's own trust page.
⚠ Heroku was not found in the FedRAMP Marketplace. Checked August 2026.
This matters if you place federal workloads with this vendor: agencies may only use cloud services holding a FedRAMP certification. It carries no weight for a purely commercial deployment.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 27 returning usable evidence. The Heroku assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Heroku Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 67% of a 133-question vendor security questionnaire — without waiting for Heroku. The remaining 44 are listed as open, so the follow-up you send is short and specific.
Q39
PCI DSS compliance claim found on trust page (Vendor attested)
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q23
All plans use AES-256 block-level storage encryption at rest, with Amazon managing the keys and individual volume keys stable for the lifetime of the volume.
+ 84 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Heroku for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Heroku
Heroku is a mature, widely-adopted cloud application platform owned by Salesforce, with an established 19-year domain history and significant technical community presence.
The vendor demonstrates solid foundational security practices, including AES-256 encryption at rest, TLS 1.3 in transit, multi-factor authentication controls, SOC 2 attestation, and a comprehensive compliance framework (ISO 27001, ISO 27017, ISO 27018, PCI DSS, HIPAA, and GDPR). Infrastructure exposure is minimal (2 open ports: 80, 443), domain reputation is clean, and the vendor maintains redundant multi-region architecture with 24/7 monitoring.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence in this assessment was independently sourced from public domain records, threat intelligence feeds, registry lookups, web archive data, and vendor-published trust pages, without vendor participation or input.
3 findings identified for Heroku
The vendor has an [AI data usage policy page](https://elements.heroku.com/addons/heroku-inference) addressing Heroku's inference and generative AI services, but the policy does not clearly state whether customer data (customer applications, configurations, or metadata) is used to train Heroku's internal or third-party AI models. The vendor discloses use of third-party AI providers (OpenAI, Anthropic, Cohere, Stability AI) but does not specify data retention periods, training consent models, or opt-out mechanisms.
The [vendor's subprocessor page](https://heroku.com/docs/subprocessors) was found and is accessible, but the automated parser could not extract individual subprocessor entries. The page may use a non-standard format, JavaScript rendering, or a format not supported by the parsing tool. …
The vendor's [trust page](https://heroku.com/security) and [compliance page](https://heroku.com/compliance) claim eight certifications: SOC 2, SOC 1, ISO 27001, ISO 27017, ISO 27018, PCI DSS, HIPAA, and GDPR compliance. However, independent registry verification found no results for ISO 27001 (IAF CertSearch) or PCI DSS (PCI Security Standards Council listing). …
Evidence that positively supports Heroku's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No Sanctions Matches Found
Sanctions & Watchlist Screening →No SEC Enforcement Filings Found
SEC Filing Search →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Clean IP Reputation
IP Reputation →Established Domain (19+ years)
Domain Registration →Heroku complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Represent Heroku? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Heroku assessment above is already written; ask for it and it lands in your inbox.