1
0
mirror of https://github.com/bitwarden/help synced 2025-12-06 00:03:30 +00:00
Files
help/_articles/security/is-bitwarden-audited.md
fred_the_tech_writer 906e2ca0dd Promote to Master (#748)
* initial commit

* adding quotes for the array error

* Create Gemfile

* Create Gemfile.lock

* add .nvmrc and .node-version

* removed /article from URL

* update links to work with netlify

* more fixed links

* link fixes

* update bad links

* Update netlify.toml

toml test for redirects

* article redirect

* link fixes

* Update index.html

* Update netlify.toml

* Update _config.yml

* Update netlify.toml

* Update netlify.toml

* Update netlify.toml

* Update netlify.toml

* Update netlify.toml

* add article back into URL for launch

* Update netlify.toml

* Update netlify.toml

* add order to categories front matter

* Update netlify.toml

* update

* sidemenu update

* Revert "sidemenu update"

This reverts commit 5441c3d35c.

* update order prop

* Navbar updates per Gary and compiler warnings

* font/style tweaks

* Update sidebar.html

* Stage Release Documentation (#739)

* initial drafts

* rewrite Custom Fields article to prioritize new context-menu option & better organize ancillary information

* edit

* edit

* Custom Field Context Menu & CAPTCHA item in release notes

* SSO relink event

* update rn

* small edits

* improve release notes titles

* fix side menu

* Edits courtest of mportune!

* update order

* link fixes

* link cleanup

* image updates and a link

* fix trailing slash

Co-authored-by: DanHillesheim <79476558+DanHillesheim@users.noreply.github.com>
2021-09-21 13:21:11 -04:00

4.1 KiB

layout, title, categories, featured, popular, tags, order
layout title categories featured popular tags order
article Compliance, Audits, and Certifications
security
true false
audit
07

Bitwarden is a global company with customers located all over the world. Our business is to help customers protect, store, and share their sensitive data. We prioritize protecting the personal data of our customers and their end-users as paramount to our company mission. Bitwarden complies with industry standards, and conducts regular audits shared transparently with our customers and users. Our open source approach puts us in a unique position, where our software is viewed and scrutinized by a globally engaged community.

Privacy

For our privacy policy, visit bitwarden.com/privacy{:target="_blank"}.

GDPR

Bitwarden is GDPR compliant. We use applicable, approved information transfer mechanisms where required, such as EU Standard Contractual Clauses (SCCs), or the EU - U.S. Privacy Shield.

CCPA

Bitwarden is compliant with the California Consumer Privacy Act (CCPA).

Privacy Shield

Bitwarden complies with EU-U.S. Privacy Shield Frameworks. In addition, Bitwarden uses and complies with EU Standard Contractual Clauses (SCCs). For more information, please see Bitwarden Privacy Shield Frameworks{:target="_blank"}.

HIPAA

Bitwarden is HIPAA compliant.

Third Party Security Audits

SOC 2 Type 2 and SOC 3

Bitwarden has completed SOC Type 2 and SOC 3 compliance. For more information, see the blog post Bitwarden achieves SOC 2 certification{:target="_blank"}.

2020 Security Assessment

Bitwarden completed a thorough security assessment and penetration test by auditing firm Insight Risk Consulting{:target="_blank"}. For more information, please see the blog post Bitwarden 2020 Security Audit is Complete{:target="_blank"}.

Read the report.

2018 Security Assessment

Bitwarden completed a thorough security audit and cryptographic analysis by security firm Cure53{:target="_blank"}. For more information, please see the blog post Bitwarden Completes Third-party Security Audit{:target="_blank"}.

Open Source Codebase

Codebase on GitHub

Bitwarden is focused on open source software with the entirety of the codebase available on GitHub.com. For more information, please see github.com/bitwarden{:target="_blank"}.

Open Source at Bitwarden

Bitwarden is an open source password manager. For more information please visit our open source page{:target="_blank"}.

Cloud Hosting

The Bitwarden cloud service is hosted on Microsoft Azure. Please visit Microsoft Azure Compliance Offerings{:target="_blank"} for more detail.

Security Information

Zero Knowledge Encryption

Bitwarden takes a zero knowledge encryption approach to password management, meaning every piece of information in your Vault is encrypted. For more information on this approach, please see the blog post How End-to-End Encryption Paves the Way for Zero Knowledge{:target="_blank"}.

Vault Security in Bitwarden

For more information on how Bitwarden Vaults are protected, including options for Bitwarden client applications, please see the blog post Vault Security in the Bitwarden Password Manager{:target="_blank"}.

Bug Bounty Program

Bitwarden also interacts with independent security researchers through our public bug bounty program on HackerOne{:target="_blank"}.