Trust Center

Start your security review
View & download sensitive information
Ask for information
Search items
ControlK

Overview

ngrok makes it easy to secure your tunnel traffic by providing configurable modules for authentication, encryption, and network policies. By combining components, you can meet your security requirements in a matter of minutes without rearchitecting your application. From concept to connection, ngrok provides a secure, scalable tunnel to share your system with the world or just the single person you need. ngrok has implemented best-in-class security practices to keep customer data safe.

Compliance

CCPA Logo
CCPA
EU-US DPF Logo
EU-US DPF
GDPR Logo
GDPR
SOC 2 Logo
SOC 2
Start your security review
View & download sensitive information
Ask for information
Other Reports
Pentest Report
Security Whitepaper
SOC 2 Report
CAIQ Lite
Acceptable Use Policy
Access Control Policy
Asset Management Policy
Business Continuity Policy
Data Security Policy
Encryption Policy
General Incident Response Policy
Information Security Policy
Network Security Policy
Other Policies
Physical Security
Risk Management Policy
Software Development Lifecycle

Risk Profile

Third Party DependenceYes
HostingMajor Cloud Provider

Product Security

Audit Logging
Data Security
Integrations
View more

Reports

Other Reports
Pentest Report
Security Whitepaper
View more

Self-Assessments

CAIQ Lite

Data Security

Access Monitoring
Backups Enabled
Data Erasure
View more

App Security

Code Analysis
Credential Management
Software Development Lifecycle
View more

Access Control

Data Access
Logging
Password Security

Infrastructure

Amazon Web Services
BC/DR
Data Center
View more

Endpoint Security

Disk Encryption
Endpoint Detection & Response

Network Security

DNSSEC
Firewall
Traffic Filtering
View more

Corporate Security

Employee Training
HR Security
Incident Response
View more

Policies

Acceptable Use Policy
Access Control Policy
Asset Management Policy
View more

Security Grades

CryptCheck
ngrok.com
A+
api.ngrok.com
A+
Qualys SSL Labs
Ngrok Website
A
Ngrok API
A+

Trust Center Updates

Subprocessor Update - Common Room

SubprocessorsCopy link

As ngrok continues to evolve and improve our platform to meet and exceed your expectations, we have decided to engage Common Room (commonroom.io) to perform a proof of concept as a vendor and sub-processor.

Because this vendor may process your organization's data (as defined under the General Data Protection Regulation) in connection with the services & products that ngrok provides, this communication is a notification that Common Room is going to be added as a new sub-processor. ngrok will be using Common Room for business and customer analytics. Data will be stored in the United States. Please let us know if you have any questions.

Published at N/A

Subprocessor Update

SubprocessorsCopy link

As ngrok continues to evolve and improve our platform to meet and exceed your expectations, we have decided to engage ClickHouse as a vendor and sub-processor.

Because this vendor may process your organization's data (as defined under the General Data Protection Regulation) in connection with the services & products that ngrok provides, this communication is a notification that ClickHouse is going to be added as a new sub-processor. ngrok will be using ClickHouse as an observability platform. Data will be stored in the United States. Please let us know if you have any questions.

Published at N/A

ngrok Security Disclosure, May 2022

IncidentsCopy link

We had an issue in our Dashboard which leaked info between accounts.

If you're affected, we've already emailed you with mitigation steps. Please follow them asap.

We support responsible disclosure & transparency: https://blog.ngrok.com/posts/ngrok-security-disclosure-may-2022

Published at N/A

If you think you may have discovered a vulnerability, please send us a note.

Powered bySafeBase Logo