SaaS Ranking

Data processing agreement in Password and identity

Without a published DPA you cannot review the contract before you talk to sales.

45% here against 26% across every category we measure. Password and identity sits above the overall share for this criterion.

Back to Data processing agreement across all categories, or to Password and identity.

Published

Published and readable without a login.

VendorWhat we found
1Password https://1password.com/legal/privacy
Clerk https://clerk.com/legal/dpa
Keeper https://www.keepersecurity.com/legal/dpa/
Okta https://www.okta.com/legal/gdpr/
WorkOS https://workos.com/legal/data-processing-addendum

No data processing agreement found.

We reached at least one address for each of these vendors and none of them carried it. That is what we found at the addresses we checked, on the date we checked them, and not a statement about what the vendor has.

VendorWhat we found
Bitwarden 8 addresses checked
Dashlane 8 addresses checked
JumpCloud 8 addresses checked
LastPass 8 addresses checked
OneLogin 8 addresses checked
Stytch 8 addresses checked

Not measured

We could not look at these, or their robots.txt asks us not to. That says something about our measurement, not about them, and they are left out of the percentage above.

VendorWhat we found
Auth0 The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.

Found something we missed? Tell us and the next run picks it up.