Okta

Okta publicly advertises 13 compliance frameworks through a trust center hosted by SafeBase.

Cybersecurity

13

Advertised frameworks

SafeBase

Trust center platform

First observed

Founding to trust center

Okta, Inc. is an American identity and access management company based in San Francisco.

Summary from Wikipedia.

Publicly advertised compliance posture

As observed on September 8, 2026 on the organization’s public trust center.

  • C5

    Publicly advertised on the organization’s trust center.

  • CSA STAR

    Publicly advertised on the organization’s trust center.

  • FedRAMP

    Publicly advertised on the organization’s trust center.

  • GDPR

    Public claim of alignment with the EU General Data Protection Regulation.

  • HIPAA

    Public claim of compliance with US health-data privacy and security rules. HIPAA has no certification; compliance is self-attested.

  • ISO 27001

    International standard for an information security management system, certified by accredited bodies.

  • ISO 27017

    Publicly advertised on the organization’s trust center.

  • ISO 27018

    Publicly advertised on the organization’s trust center.

  • SOC 1

    Publicly advertised on the organization’s trust center.

  • SOC 2

    Independent CPA audit of controls for security, availability, and confidentiality.

  • SOC 3

    Public summary of a SOC 2 audit, intended for general distribution.

  • EU-US DPF

    Publicly advertised on the organization’s trust center.

  • TISAX

    Publicly advertised on the organization’s trust center.

Compliance timeline

  1. 2010

    Company founded

  2. September 8, 2026

    Posture last observed by Trust Index

Security & compliance hiring

Open roles on the organization’s public job board, a signal of active investment in security and compliance.

  • Director, Corporate Counsel - Privacy
  • Product Manager, Zero Trust Authentication
  • Senior Director, GRC
  • Senior Identity Specialist-Governance
  • Senior Site Reliability Engineer - Security and Data Systems (Federal)
  • Sr. Product Manager - Agentic Security
  • Sr. Product Manager - Agentic Security
  • Staff AI Security Engineer
  • Staff Identity Governance and Access Engineer
  • Staff Product Marketing Manager, Security
  • Staff Product Security Engineer
  • Staff Product Security Engineer, PSIRT
  • Staff Product Security Engineer, Reviews
  • Staff Security Engineer, TDI
  • Staff Site Reliability Engineer, Security- GCP
  • Tax Senior Analyst, Foreign Compliance and Reporting

Named as a subprocessor by

Organizations in the Trust Index that disclose Okta as a subprocessor.

About this data

The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.

More in Cybersecurity

How can we work together

Schedule a discovery session

A complimentary, exploratory meeting to discuss your business goals and challenges, identify potential solutions, and determine if our services align with your needs.

Hire us for a project

Augmenting a specific initiative or project, leveraging our expertise and resources to deliver a defined outcome.

Retain us long term

Ongoing collaboration and support through regular meetings, check-ins, and access to our team's collective knowledge and experience, empowering you to make informed decisions and drive sustained growth.