Splashtop Compliance: GDPR, HIPAA, FERPA, SOC 2, ISO & More

Splashtop Compliance

Compliant with ISO/IEC 27001, SOC2, GDPR, and CCPA. Supporting HIPAA, PCI, and FERPA needs.

Learn how Splashtop remote access and remote support solutions comply with or support our customers’ compliance with industry and government standards and regulations. Learn more about Splashtop and SOC 2, ISO/IEC 27001, GDPR, CCPA, PCI, HIPAA, and FERPA.

ISO/IEC 27001:2022

Splashtop is now ISO/IEC 27001:2022 certified, the latest version of the world’s leading standard for information security management systems (ISMS). This certification replaces our previous ISO/IEC 27001:2013 certification, demonstrating our continued commitment to protecting customer data with the most up-to-date security best practices.

The 2022 update to ISO 27001 strengthens requirements in areas such as:

Our ISO 27001:2022 certification means that Splashtop:

Certification scope: The development, maintenance and operation of SaaS services (Remote Desktop Service System)

SOC 2 Compliance

Splashtop has achieved SOC 2 Type 2 compliance, validated by independent auditors under the AICPA Trust Services Criteria for Security, Availability, and Confidentiality.

Foxpass customers benefit from the same rigorously controlled environment for data protection and service reliability.

A public SOC 3 report is available for reference.

How Foxpass supports your SOC 2 compliance:

Foxpass helps customers meet key SOC 2 Trust Services Criteria — especially those addressing Access Controls (CC6.x) and System Operations (CC7.x).

Through centralized authentication, detailed access logging, and certificate-based verification, Foxpass enables customers to demonstrate effective access management and monitoring in their own SOC 2 audits.

CSA STAR Compliance

Splashtop has earned CSA STAR Level 1 compliance, underscoring our dedication to cloud security excellence. By completing a thorough self-assessment against the CSA Cloud Controls Matrix (CCM) and CAIQ, we uphold the highest standards of transparency - so you can trust that your data is always protected. You can review our published assessment on the CSA STAR Registry here.

GDPR (General Data Protection Regulation)

Foxpass and Splashtop comply with the principles and obligations of the EU GDPR as both Data Controller and Data Processor.

We implement data-protection-by-design practices, limit personal data collection to what’s necessary to service our customers, and secure all data in transit and at rest using strong encryption.

We maintain Data Processing Agreements (DPAs) with sub-processors and support customer requests related to access, correction, and deletion of personal data.

We have formally reviewed our GDPR readiness with a third party professional firm, put in place additional processes, and set up proper communication channels to handle all GDPR related inquiries and tasks both internally and externally.

See the Splashtop Privacy Policy and Corporate Data Processing Agreement for details.

How Foxpass Supports Your GDPR Compliance

Foxpass helps organizations strengthen their compliance with the EU General Data Protection Regulation (GDPR) by enabling key technical and organizational controls around data access, authentication, and security.

Specifically, Foxpass supports GDPR requirements by:

CCPA (California Consumer Privacy Act)

In compliance with the CCPA, California residents may request access to, deletion of, or opt-out from the sale or sharing of their personal information.

Splashtop — and by extension Foxpass — maintains transparent privacy practices and provides mechanisms to exercise these rights as outlined in our Privacy Policy.

HIPAA Compliance

Every business that is part of the U.S. healthcare industry must comply with Federal standards regulating sensitive and private patient information. In addition to protecting worker health insurance coverage, HIPAA sets forth standards for protecting the integrity, confidentiality, and availability of electronic health information. Splashtop does not process, store, or have any access to any of the users’ computer data such as patient data or medical records. Therefore, Splashtop should not be considered as your business associate. While no single product or solution can make an organization HIPAA-compliant, the Splashtop Remote Access, Splashtop Remote Support, SRS Premium, Splashtop Enterprise, and Splashtop On-Prem products, when used properly, may help organizations fulfill HIPAA guidelines for the privacy and security of remote access to healthcare information and may be used within a larger system to support HIPAA compliance (see whitepaper below). Some key points to note are:

All of these measures should help ensure that Splashtop may be securely deployed in your organization without affecting HIPAA compliance.

White Paper: Splashtop HIPAA Compliance and Security

PCI DSS (Payment Card Industry Data Security Standard)

The Payment Card Industry Data Security Standard (PCI DSS) establishes strict requirements for protecting cardholder data and securing networks that process or transmit payment information.

While Foxpass does not store or process cardholder data, it supports PCI DSS compliance by providing the identity and access controls, audit logging, and network segmentation capabilities required to protect cardholder-data environments (CDEs).

Organizations use Foxpass to:

Splashtop partners exclusively with PCI DSS-compliant payment providers for secure transaction processing, ensuring all card data is handled in accordance with PCI requirements.

FERPA (Family Educational Rights and Privacy Act)

FERPA protects personally identifiable information (PII) in students’ education records from unauthorized disclosure.

Foxpass helps educational institutions support FERPA compliance by securing network and system access through identity- and certificate-based authentication. By ensuring that only verified users and managed devices can access campus Wi-Fi, servers, and systems, Foxpass strengthens protection of sensitive student and institutional data.

Foxpass does not access or store student records and follows industry best practices for encryption and privacy.

Learn more about Splashtop and FERPA: Splashtop FERPA Info Sheet

Security & Technical Controls

Foxpass is backed by Splashtop’s secure cloud infrastructure, incorporating:

For compliance documentation, questionnaires, or security inquiries, contact us at sales@splashtop.com or speak with us at +1.408.886.7177.