// Trust & Security Report

    Activepieces logo

    Activepieces

    AI-first workflow automation platform (no-code builder + 750+ integrations, AI agents, open-source MIT-licensed self-host edition, and managed cloud with enterprise governance tier)

    Certifications held

    0

    Maturity

    Growth

    Trains on your data

    Unknown

    Trust center

    Yes

    // Certification ledger

    Each held certification is backed by a verbatim quote from the vendor's own trust or security page. “Not confirmed” means we could not verify it publicly, not that the vendor lacks it.

    > Show 8 unconfirmed / not-held certifications
    SOC 2 Type II
    NOT CONFIRMED

    Trust center page (trust.activepieces.com) lists 'SOC 2 Type 2 - In progress' under Compliance overview. No published report or certificate is found on any vendor-domain page. The homepage and deployment page list 'SOC 2 Type II & GDPR', which could be read as implying the certification is already held.

    source: trust.activepieces.com
    ISO 27001
    NOT CONFIRMED

    No public evidence of ISO 27001 certification on activepieces.com, the trust center, or any vendor-domain source.

    source: trust.activepieces.com
    GDPR (compliance posture)
    NOT CONFIRMED

    Privacy policy references GDPR Article 6.1 lawful bases and data subject rights for EEA residents. Vendor states it complies with data protection regulations including GDPR on its blog. No independent GDPR certification exists, and no public customer-facing Data Processing Agreement was found; the /dpa URL returns HTTP 404. GDPR-aware posture but no formal certification or public DPA artifact.

    source: activepieces.com
    HIPAA
    NOT CONFIRMED

    No public evidence of HIPAA compliance or BAA availability on any vendor-domain page.

    source: trust.activepieces.com
    PCI DSS
    NOT CONFIRMED

    No public evidence of PCI DSS compliance on any vendor-domain page.

    source: trust.activepieces.com
    ISO 42001 (AI Governance)
    NOT CONFIRMED

    No public evidence of ISO/IEC 42001 certification on any vendor-domain page.

    source: trust.activepieces.com
    CSA STAR
    NOT CONFIRMED

    No public evidence of CSA STAR registration or certification on any vendor-domain page.

    source: trust.activepieces.com
    FedRAMP
    NOT CONFIRMED

    No public evidence of FedRAMP authorization on any vendor-domain page.

    source: trust.activepieces.com

    // Privacy & AI training

    Trains on customer data

    Not stated

    Data processing agreement

    Not offered

    Data region

    Cloud customers can select an EU or US data region (deployment page: 'EU & US data regions'). Per the engineering handbook, Hetzner provides the machines running services and DigitalOcean hosts the databases (Redis, PostgreSQL), a functional split rather than a documented region-to-provider mapping; specific data-center cities are not stated on any vendor-domain page. Privacy policy states data is transmitted to the United States to fulfill contractual obligations.

    Privacy policy explicitly states: 'We do not use Google Workspace data for advertising, marketing, user profiling, analytics, or to develop, train, refine, or improve generalized or non-personalized artificial intelligence (AI) or machine learning (ML) models.' However, this restriction is scoped explicitly to Google Workspace data. The Terms of Service do not contain equivalent language covering ALL customer data for AI/ML training. The broader AI training posture for non-Google-Workspace customer data is not explicitly addressed in public documents.

    // Security controls

    Encryption in transit

    Yes, trust center lists 'Data encrypted in-transit' as a confirmed control

    trust.activepieces.com

    Encryption at rest

    Yes, trust center lists 'Data encrypted at rest' as a confirmed control

    trust.activepieces.com

    MFA

    Required for critical services per trust center controls

    trust.activepieces.com

    Penetration testing

    Performed within the last 12 months; findings remediated per trust center

    trust.activepieces.com

    SSO / SAML

    SAML 2.0 and Google SSO available; SCIM provisioning for enterprise tier

    activepieces.com

    RBAC

    Advanced RBAC with granular role control; Custom RBAC on enterprise (Ultimate) plan

    activepieces.com

    Audit logs

    Available on enterprise tier

    activepieces.com

    Vulnerability management

    Vulnerability scanning, remediation, and management policy established per trust center

    trust.activepieces.com

    Email security

    DMARC policy enforced per trust center

    trust.activepieces.com

    Endpoint security

    MDM, anti-malware, device encryption, and firewall on endpoints per trust center

    trust.activepieces.com

    Cloud infrastructure

    Machines running services on Hetzner; databases (Redis, PostgreSQL) on DigitalOcean, per engineering handbook. Firewall restricts public access and buckets not exposed publicly, per trust center

    activepieces.com

    Incident response

    Incident response policy established and documented per trust center

    trust.activepieces.com

    Security awareness training

    Conducted per trust center organizational security controls

    trust.activepieces.com

    // Products & data scope

    Cloud (Standard)Managed SaaS

    Data it handles: Workflow metadata, integration credentials, run history stored in vendor-managed cloud (EU or US region selectable)

    Usage-based pricing at $5/active flow/month. EU and US data regions selectable. SOC 2 Type II listed in marketing but is still in-progress per trust center.

    Cloud (Ultimate / Enterprise)Managed SaaS - Enterprise

    Data it handles: Same as Standard plus additional governance controls

    Custom annual contract pricing. Includes SSO (SAML 2.0), SCIM, Custom RBAC, Audit Logs, Global Connections, dedicated workers. Contact sales required.

    Self-Hosted (Community Edition)Open-Source Self-Hosted

    Data it handles: All data stays within customer's own network/infrastructure

    MIT licensed. Deployable via Docker, Helm, or any cloud. Core features only; enterprise governance features (SSO, advanced RBAC, audit logs) require paid license. Suitable for any compliance requirement including air-gapped or regulated environments.

    // What to watch

    • The homepage and deployment page display 'SOC 2 Type II & GDPR' as if the SOC 2 Type II certification is already held. The trust center at trust.activepieces.com shows 'SOC 2 Type 2 - In progress'. The certification has not been published; buyers relying on the homepage marketing claim may be misled.
    • No customer-facing Data Processing Agreement was found. The /dpa URL returns HTTP 404. The privacy policy mentions DPAs only in reference to Activepieces' own vendor management as a controller, not as a document customers can sign.
    • The privacy policy restricts AI/ML model training only for Google Workspace data. The Terms of Service contain no equivalent restriction for all customer data. The broader AI training posture for non-Google-Workspace workflow data is unaddressed in public documents.
    • Hetzner and DigitalOcean host Activepieces' infrastructure; any certifications these providers hold (for example ISO 27001) are the hosts' certifications, not Activepieces' own. Activepieces does not claim host certifications as its own.

    // At a glance

    Pricing model

    Usage-based for Standard ($5/active flow/month, unlimited runs); custom annual contract for Ultimate/Enterprise; free Community self-hosted edition (MIT license)

    Self-hostable

    Yes

    // How we verified this

    Every certification marked HELD is confirmed against a verbatim quote on Activepieces Inc.'s own trust, security, or privacy pages. We reject certifications claimed only on third-party aggregators, on a cloud host's behalf, or by a similarly named company.

    Last verified 2026-06-29. Compliance changes over time. Always confirm directly with the vendor before relying on any certification for a purchasing or compliance decision.

    trust.activepieces.com

    > Browse all vendor trust reports