SOC 2 company profile

hCaptcha SOC 2 status and provider evidence

Review hCaptcha’s public SOC 2 statement, report type, evidence source, and freshness.

SOC 2 statusself attested
Report typeType II
Providers found0
Last checked2026-08-29
Providers

hCaptcha’s SOC 2 stack

No provider is named on the current source.

We will update this page if the company publishes more detail.

Compliance coverage

Frameworks named by hCaptcha

GDPR

ant and UniversalWorks in every countryUnique Zero PII features simplify global compliance for regulated industries. Enable trust and safety while exceeding privacy standards like GDPR, CCPA, and HIPAA.Designed for accessibilityFlexible options to meet both your security and WCAG 2.1 accessibility requirements, from text-based challenges to our passive Universal Accessibility system.Request a VPATA new kind of MFA. Zero tolling attacks.We f

Checked 2026-08-29
View source ↗
HIPAA

lWorks in every countryUnique Zero PII features simplify global compliance for regulated industries. Enable trust and safety while exceeding privacy standards like GDPR, CCPA, and HIPAA.Designed for accessibilityFlexible options to meet both your security and WCAG 2.1 accessibility requirements, from text-based challenges to our passive Universal Accessibility system.Request a VPATA new kind of MFA. Zero tolling attacks.We flipped the script

Checked 2026-08-29
View source ↗
ISO 27001

formation while providing enterprise-grade fraud protection. The platform supports compliance with privacy regulations including GDPR and CCPA and maintains certifications such as ISO 27001, SOC 2 Type II, and PCI DSS. Organizations subject to HIPAA requirements can deploy hCaptcha in architectures designed to support those obligations.Who uses hCaptcha for bot and abuse protection?+-Thousands of organizations rely on hCaptcha to defend their di

Checked 2026-08-29
View source ↗
PCI DSS

rprise-grade fraud protection. The platform supports compliance with privacy regulations including GDPR and CCPA and maintains certifications such as ISO 27001, SOC 2 Type II, and PCI DSS. Organizations subject to HIPAA requirements can deploy hCaptcha in architectures designed to support those obligations.Who uses hCaptcha for bot and abuse protection?+-Thousands of organizations rely on hCaptcha to defend their digital services, including Sh

Checked 2026-08-29
View source ↗
SOC 2

hile providing enterprise-grade fraud protection. The platform supports compliance with privacy regulations including GDPR and CCPA and maintains certifications such as ISO 27001, SOC 2 Type II, and PCI DSS. Organizations subject to HIPAA requirements can deploy hCaptcha in architectures designed to support those obligations.Who uses hCaptcha for bot and abuse protection?+-Thousands of organizations rely on hCaptcha to defend their digital s

Checked 2026-08-29
View source ↗

Primary compliance evidence

hCaptcha public statement

hile providing enterprise-grade fraud protection. The platform supports compliance with privacy regulations including GDPR and CCPA and maintains certifications such as ISO 27001, SOC 2 Type II, and PCI DSS. Organizations subject to HIPAA requirements can deploy hCaptcha in architectures designed to support those obligations.Who uses hCaptcha for bot and abuse protection?+-Thousands of organizations rely on hCaptcha to defend their digital services,

Classification: self attested · checked 2026-08-29
Open source ↗
SOC 1SOC 2SOC 3Type IType IIAudit readinessTrust centersVendor riskSecurity evidenceProcurement