SOC 2 company profile

Retool SOC 2 status and provider evidence

Review Retool’s public SOC 2 statement, report type, evidence source, and freshness.

SOC 2 statusself attested
Report typeNot publicly specified
Providers found0
Last checked2026-08-30
Providers

Retool’s SOC 2 stack

No provider is named on the current source.

We will update this page if the company publishes more detail.

Primary compliance evidence

Retool public statement

olicyAsset Management PolicyView moreSecurity GradesQualys SSL LabsRetool CloudKnowledge Base (FAQ)Get accessTrust Center UpdatesSubscribeSOC2 Type IICopy linkComplianceOur latest SOC2 report is available now here in the trust centerVulnerabilitiesCopy linkVulnerabilitiesCVE-2025-29774 and CVE-2025-29775 (SAMLStorm) A vulnerability in an open-source library, xml-crypto, which Retool uses for SAML login implementation, allowed for account ta

Classification: self attested · checked 2026-08-30
Open source ↗
SOC 1SOC 2SOC 3Type IType IIAudit readinessTrust centersVendor riskSecurity evidenceProcurement