When a customer asks whether Replit has SOC 2, they mean the report an outside auditor writes about a software vendor’s own controls: not SOC 1, not SOC 3, not the accounting use of those three letters, and not a monitored room called a security operations centre. Compliance in that question means vendor paperwork as well, not the HR, finance or tax kind.

The request usually arrives with a date attached to it. Replit publishes several documents that all sound like they answer it, and they answer different questions. One describes how Replit runs its own service. One is a legal agreement that only some plans sit under. One is a list of the companies Replit passes customer data to. One is a matrix dividing the work between Replit and the person who published the app.

Replit’s compliance paperwork is four documents rather than one. The information-security page puts a SOC 2 Type 2 attestation on the record, the Data Processing Agreement lets a customer request compliance information once every twelve months, the subprocessor page lists 46 companies, and the shared responsibility model puts the regulatory obligations of your own application on you.

Every Replit fact on this page was read off Replit’s own published pages on 3 September 2026 and is dated where it sits. The account from a business owner further down is in their own words. The sister pages that own the platform-safety and launch questions are linked rather than repeated. AxonBuild built, tested, audited, hosted, certified, signed and ran none of what follows, none of this is legal advice, and no sentence here decides whether your own app meets any rule. That answer belongs to you, your customer, and whoever signs your agreements.

Is Replit SOC 2 compliant?

Four Replit documents routed to vendor status, processor terms, subprocessors, or shared responsibility questions.

Replit’s own properties give the same status three different names. The information-security page calls it a SOC 2 Type 2 Attestation of Compliance. The Trust Center description says Replit is SOC 2 Type II audited annually by an independent CPA firm. The security page’s structured data calls it a SOC 2 Type II certification.

Replit’s information-security page, read on 3 September 2026, prints the sentence “Replit has achieved SOC 2 Type 2 Attestation of Compliance”. The same page names Google Cloud Platform as the infrastructure and describes GCP as “certified for compliance with ISO 27001 and SOC 2 Type 2”. Those are two separate statements about two separate companies, and a customer who asks for Replit’s report is not asking for Google’s.

The description Replit’s Trust Center publishes about itself, read the same day, says Replit “is SOC 2 Type II audited annually by an independent CPA firm and holds an Advanced Bitsight rating.” On Replit’s security page, the answer to the question “Is Replit SOC 2 compliant?” reads in full: “Yes. Replit holds SOC 2 Type II certification. We also comply with GDPR and are working toward ISO 27001 certification.”

Three pages owned by the same company give that status three different words: attestation, audited, certification. The AICPA, which publishes the SOC 2 standard, names its own material as reporting throughout: on its SOC 2 page, read on 3 September 2026 twice, plain and browser-shaped, the guide it sells is titled “SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy” and the walkthrough it publishes is a “SOC 2 Report Walkthrough”. A questionnaire that asks for a certificate number has nowhere to put an examination report, which is worth knowing before you start typing an answer.

None of this settles whether the platform itself is safe to build on, which is a different reading of the same company and has its own page, and none of it settles the product verdict either. This page is about the documents.

Which Replit agreement covers you depends on which plan you pay for

Two Replit pages, read together, answer the question most founders skip. Neither one answers it alone, and Replit does not print the joined answer as a single sentence anywhere.

The information-security page lists the documents that govern Replit’s security and data handling, and gives each one an audience in its own words:

  • Terms of Service, “For Free and Core users”.
  • Commercial Agreement, “For Pro and Enterprise users”.
  • Privacy Policy, “For all users”.

Then Replit’s Data Processing Agreement opens by placing itself: the DPA “forms part of and is incorporated into the Replit Commercial Agreement”. Read the two pages in that order and the arithmetic does itself. The Commercial Agreement is the document Replit names for Pro and Enterprise users, and the DPA is part of that agreement.

That matters because the DPA is the document your customer’s procurement team is actually asking about. It carries the processor terms, the breach-notification clause, the subprocessor route and the transfer mechanism. A reader on a Free or Core plan looking at a customer’s data-processing questions is looking at a document Replit’s own page attaches to a different audience.

The DPA also dates itself. Its own header reads “Last updated: April 1, 2026”, and the same page links a previous version, so a founder who signed something earlier can see what changed rather than assume nothing did.

The paperwork Replit publishes is about Replit’s service. Your customer is asking about yours.

The practical answer is to read the document that names the plan you are on before you quote anything from it. What each of those plans costs, and what the meters add on top, is counted out separately. The same reading of another builder’s paperwork shows how differently two vendors in the same market can arrange the same four documents.

How do you actually get Replit’s SOC 2 report?

The route is written into the DPA rather than onto a download page. Section 6 gives a customer the right to ask once every twelve months, says Replit will make available information demonstrating compliance with the DPA, names SOC 2 as an example, and lets Replit answer with a summary at its own discretion.

Section 6 of the DPA, headed “Audit and Compliance”, reads: “Upon written request, no more than once every twelve (12) months, and subject to the confidentiality agreements in the Agreement, Company will make available to Customer information necessary to demonstrate compliance with the obligations of this DPA. This may include information pertaining to any applicable certifications (e.g. SOC 2) and other information reasonably necessary to demonstrate compliance with this DPA. Company may satisfy this obligation by providing summaries of the results and/or reports, at its sole discretion.”

Three things in that clause change how you answer a customer. The right is annual, not on demand. It is conditioned on the confidentiality terms already in the agreement, so the report arrives under those terms rather than as something you can forward. And the final sentence lets Replit answer with a summary rather than the report itself, at Replit’s own choice.

Replit’s shared responsibility model puts the same job on Replit’s side of the table. Its row for “Compliance certifications of the platform” describes the work as “Maintaining attestations (for example, SOC 2 Type II) and providing evidence to customers”, and assigns it to Replit. The same page routes the whole subject onward in one sentence: “To understand what Replit does or does not provide from a compliance standpoint (SOC 2 Type II, subprocessors, certifications, and so on), visit replit.com/security.”

That route has a snag worth knowing before you send an auditor down it. Read on 3 September 2026 with a plain request and again with a browser-shaped one, both returning HTTP 200, trust.replit.com rendered no body content at all to either shape: the only readable text on the page was its head metadata, including the SOC 2 sentence quoted earlier. replit.com/security behaved the same way. Its SOC 2, GDPR and ISO 27001 answer was readable only inside the page’s own structured data, not in any rendered body copy. Both pages presumably render normally in a browser. An auditor or a customer following either link from your questionnaire answer is being sent somewhere that needs one.

So the honest thing to tell a customer today is short: the report exists, the request goes through the agreement rather than a portal, the cadence in the agreement is annual, and what comes back may be a summary. The report is usually one line on a longer list, and the rest of that list arrives in the same week.

What Replit’s shared responsibility model puts on your side of the line

Replit’s matrix decides most of these arguments, and it reads more like an allocation of work than a compliance document. The sister page covering how the same split reads when you are deciding whether to launch works through the owner’s side of it in full, so this page takes only the rows a compliance question touches.

The row named “Regulatory compliance of your application” describes the work as “Meeting laws and regulations applicable to your app (for example, GDPR, CCPA, PHI, PCI DSS, HIPAA, SOC 2).” Its responsibility column says You. Six regimes named in one parenthesis, and every one of them landing on the person who published the app, is the clearest sentence Replit has written on this subject.

The subprocessor row is the one with two sides. It reads: “Replit vets and discloses subprocessors that process customer data on the platform; you vet and disclose subprocessors used by your app.” Replit’s list, discussed below, covers the companies Replit uses to run Replit. The email sender, the payment processor and the model vendor your published app calls at runtime are on nobody’s list until you write one.

Replit describes the matrix as “structured along the lines of established cloud and AI shared-responsibility patterns (Microsoft AI SRM, CSA AICM), and based on ISO/IEC 42001 and the NIST AI RMF”. That lineage explains its shape. It is built to answer who does what, and it answers that well. It was never built to tell a buyer whether the app running on top of it holds up.

Penetration testing sits in the same allocation, on the owner’s side, and a customer asking for one has usually asked for something more specific than they realise. That decision belongs to the page on whether a customer’s request for a penetration test means what they think it means, and there is nothing to add to it here.

The subprocessor list your own customer will ask you to reproduce

Replit’s subprocessor page carries its own date and one uniform location label, which is a company location on Replit’s list rather than a statement of where every processing step happens. The page says “Last updated: August 2026” and lists 46 companies. Every single row gives the location as USA.

Twelve of those entries carry service words that suggest a published app’s data or prompts could travel through them; the page does not say which subprocessors handle any given customer workload, so the grouping below is a reading of Replit’s own service labels rather than a map of your data:

SubprocessorService, as the page states itLocation
AnthropicAI modelsUSA
BasetenAI infrastructure platformUSA
ClerkEnterprise SSOUSA
CloudflareCloud infrastructureUSA
Fireworks AI, Inc.AI infrastructure platformUSA
Microsoft AzureCloud infrastructureUSA
NeonDatabase managementUSA
OpenAIAI modelsUSA
OpenRouterAI model selection for IntegrationsUSA
Parallel Web SystemsAI infrastructure platformUSA
StripePayment processingUSA
TwilioSMS verificationUSA

The remaining thirty-four rows carry service labels that read as Replit’s own operations: analytics, marketing, billing, support, monitoring and engineering, plus further cloud infrastructure, a domain registrar, a design import tool, a data pipeline and a payment provider. Google carries the longest service description on the page, covering cloud infrastructure for Replit’s apps and services, AI models, and analytics and customer interactions in a single cell. Stytch appears as “Analytics and identity” and WorkOS as “Engineering”, which is a reminder that the service word on a list like this is the vendor’s shorthand and not a technical description you can answer questions from.

The list is not decoration. The DPA’s section 5 states that the customer “hereby agrees, and grants a general authorization” for Replit to use subprocessors, points at that page as the current list, and commits Replit to a written agreement with each one imposing obligations “no less protective” than the DPA’s own. It then gives the customer an objection route: written notice on reasonable grounds relating to a potential or actual violation of data protection law, a good-faith discussion, and, if that fails, termination of “the affected portion of the Services”, which the clause names as the customer’s “sole and exclusive remedy with respect to the objection”.

Section 7 decides which transfer mechanism applies, and it depends on which hat you are wearing. The DPA incorporates the Standard Contractual Clauses and states that Module 2, controller to processor, applies where the customer is a controller, while Module 3, processor to processor, applies where the customer is a processor in its own right and Replit is “engaged as a Subprocessor”. A founder selling to consumers and a founder selling to enterprises are usually on different modules of the same agreement.

Reproducing a list like that inside your own agreement, and working out what you are promising when you do, is the next question and it has its own answer.

What your customer’s form asks about that the report does not answer

Replit’s matrix divides most rows one of three ways, and it says so plainly: “Replit ships the controls: RBAC, visibility settings, MFA, SSO, data residency, retention. You decide which to enable and how to configure them.” The row for “Workspace identity and access management (accounts, MFA, SSO, SCIM)” splits accordingly, with Replit under controls and You under configuration. Workspace audit logs split the same way, with Replit providing them.

That mechanism-versus-configuration line is where these conversations actually get decided, and it is not the line the attestation sits on. A business owner running internal tools on Replit wrote this about their own decision:

…We’ve been using it to build internal apps for our small business. That said, we are now considering a shift to a different platform solely because of the lack of 2FA options to secure our accounts.

Replit’s shared responsibility model, read on 3 September 2026, names MFA among the controls Replit ships and puts the configuration of it on the account holder. Read alongside that, the account above is a reminder about where these decisions get made rather than a statement about what the platform offers today: what moved a paying customer toward the exit was one control in the account, not the attestation on the trust page. Nobody in that conversation asked for a report.

Answering the form the request arrived on is a job of its own, and the piles it sorts into are not the same as the documents above.

HIPAA and a business associate agreement: what Replit’s published documents say

Replit’s published documentation does not cover this ground, and the shape of that gap matters more than a verdict would. Two named documents, read on 3 September 2026, are silent on the subject, and a silence in two documents on one date is not the same thing as an answer from the company.

As of 3 September 2026, Replit’s own documentation index at docs.replit.com/llms.txt lists no page whose title or summary names HIPAA or a business associate agreement, and Replit’s Data Processing Agreement, read in full on the same day, does not mention protected health information or a business associate agreement. Both were read with a plain request and a browser-shaped one, both returning HTTP 200 with identical bytes.

What Replit would agree to if a customer wrote and asked is a separate question, and this page has no answer to it. Neither does it have one about your app.

HIPAA appears in exactly one row of Replit’s shared responsibility model, inside the parenthesis quoted earlier, the row that assigns regulatory compliance of your application to you. Which builders put their name to that kind of agreement at all, and on which plan, is a comparison across the whole set rather than one vendor’s answer. The same question about a backend rather than a builder splits by service rather than by plan. For a vendor that does publish one, what a signed agreement and a plan gate look like when a vendor publishes one shows the shape to look for.

GDPR, ISO 27001 and where the data sits

Replit answers the GDPR half directly and the ISO half in the future tense. On the security page’s structured data, read 3 September 2026, the sentence runs: “We also comply with GDPR and are working toward ISO 27001 certification.” Replit’s own page says it is working toward that certification, which is a forward-looking statement by a vendor and worth re-reading before you quote it to anybody.

The DPA’s definitions say which laws it has in mind. “Data Protection Law” there is defined to include the California Consumer Privacy Act as amended by the California Privacy Rights Act, the General Data Protection Regulation, and the United Kingdom Data Protection Act of 2018, with the clause adding that a law applies “only to the extent it is applicable to Company’s role in Processing Customer Personal Data under the Agreement.”

Where the data physically sits has three separate answers on Replit’s own pages, and they are about three different things.

The information-security page describes Replit’s own storage footprint: “Replit hosts data primarily in Google Cloud Platform (GCP) data centers in the United States, with an optional hosting region in India for users who opt in.” That is Replit’s estate, not your app’s deployment.

The shared responsibility model then splits your side in two. For the development environment, its data-residency row says “Pro customers can choose a Workspace location during creation.” For published apps, the row reads: “Replit offers region selection at publish time; the choice is permanent after publishing.” Permanent is the operative word there, and it applies at the moment of first publishing rather than at any later point. Which plans can make that selection at all is a separate question about Replit’s plan gates, counted elsewhere.

Deletion requests, retention schedules and data exports are the questions that follow a residency answer, and no vendor page settles them for you. What the regulation asks of the company running the app, in the order a small product meets it, is the wider subject this one document sits inside.

When the customer stops asking where the data sits and starts asking for the product to run somewhere they control, the conversation changes shape. If it turns out the app has to leave, moving the app off Replit is its own piece of work.

What none of this says about the app Replit built for you

Every document above is about Replit’s service. The attestation covers Replit’s controls. The DPA binds Replit as a processor of the data you send it. The subprocessor list names the companies Replit uses. The matrix says which half of the work is Replit’s.

None of them has read the code Replit Agent generated for you. No auditor examining a hosting platform opens a route in a customer’s published application to see whether it trusts an account identifier that arrived in the request body, or whether a paid feature unlocks before the payment webhook has been verified. That gap is the paperwork working as designed, and it is why the questions your customer asks about your own app cannot be answered by forwarding a vendor’s report.

The platform-safety reading of the same company is on its own page, and the separate question of checking the code the agent generated is where a founder holding a customer’s list usually ends up.

Common questions about Replit’s compliance paperwork

Which SOC 2 report does Replit say it has?

Replit’s information-security page, read 3 September 2026, carries the sentence “Replit has achieved SOC 2 Type 2 Attestation of Compliance”. Its Trust Center description says Replit is “SOC 2 Type II audited annually by an independent CPA firm”, and the security page’s structured data calls the same status a “SOC 2 Type II certification”. All three refer to Type II rather than Type I.

How do I get a copy of Replit’s SOC 2 report?

Through the agreement rather than a download link. Section 6 of Replit’s Data Processing Agreement, read 3 September 2026, gives a customer the right to request, in writing and no more than once every twelve months, information necessary to demonstrate compliance with the DPA, names SOC 2 as an example, and says Replit “may satisfy this obligation by providing summaries of the results and/or reports, at its sole discretion”. The request is also subject to the confidentiality terms in the agreement.

Does Replit’s DPA apply to me on a free account?

Replit’s DPA states that it “forms part of and is incorporated into the Replit Commercial Agreement”, and Replit’s information-security page lists the Commercial Agreement as the document “For Pro and Enterprise users” while naming the Terms of Service as the document “For Free and Core users”. Those are two statements on two Replit pages, read 3 September 2026, and Replit does not join them into one sentence anywhere. Read the agreement your own plan is named under.

Does Replit sign a business associate agreement?

Replit’s own documentation index at docs.replit.com/llms.txt, read 3 September 2026, lists no page whose title or summary names a business associate agreement, and Replit’s DPA, read in full the same day, does not mention one. That is what those two documents say on that date rather than an answer about what Replit would agree to if asked directly.

Is Replit HIPAA compliant?

Nobody outside Replit can answer that from published pages, and the question usually belongs one level down anyway: HIPAA obligations attach to a covered entity or its business associate, not to a development platform in the abstract. What can be checked is that neither Replit’s documentation index nor its Data Processing Agreement, both read 3 September 2026, names HIPAA, protected health information or a business associate agreement, while Replit’s shared responsibility model lists HIPAA among the regimes it assigns to the owner of the application.

Does Replit have ISO 27001?

Replit’s security page, read 3 September 2026, says the company is “working toward ISO 27001 certification”. Separately, the same information-security page describes Google Cloud Platform, Replit’s infrastructure provider, as “certified for compliance with ISO 27001 and SOC 2 Type 2”. Those are statements about two different companies and a buyer’s question about Replit is not answered by Google’s certificate.

Is Replit GDPR compliant?

Replit’s security page, read 3 September 2026, states “We also comply with GDPR”. Its Data Processing Agreement defines “Data Protection Law” to include the GDPR, the UK Data Protection Act 2018 and the CCPA as amended, and incorporates the Standard Contractual Clauses for international transfers. Whether the application you published on top of Replit meets the regulation is a question of its own, and the answer depends on what your app does with personal data rather than on what Replit’s page says.

Who are Replit’s subprocessors, and do I have to list them?

Replit’s subprocessor page, dated August 2026 and read 3 September 2026, lists 46 companies, every one with the location USA. Whether they belong on a list of your own depends on your customer’s agreement rather than on Replit’s, and Replit’s shared responsibility model draws the line explicitly: Replit vets and discloses the subprocessors that process customer data on the platform, and you vet and disclose the ones your app uses.

Does Replit’s SOC 2 report cover the app you published on it?

A SOC 2 report is written about the service organization that commissioned it. Replit’s shared responsibility model, read 3 September 2026, assigns “Regulatory compliance of your application” to you and describes it as “Meeting laws and regulations applicable to your app (for example, GDPR, CCPA, PHI, PCI DSS, HIPAA, SOC 2)”. The application’s own authentication, authorization and payment logic is on the same side of that line.

Can I choose where my Replit app’s data is stored?

Replit’s shared responsibility model, read 3 September 2026, gives two answers. For the development environment, “Pro customers can choose a Workspace location during creation.” For published apps, “Replit offers region selection at publish time; the choice is permanent after publishing.” Separately, Replit’s information-security page says Replit hosts data primarily in Google Cloud Platform data centers in the United States, “with an optional hosting region in India for users who opt in”.