suno.com

Featured in our Forbes AI 50 security study: see how suno.com compares with the other 49 →
B
Trust rating
Good · 85/100
Procurement snapshot
0 critical findings identified — these point to architectural gaps, not just configuration tweaks.
Strengths
MX Records & Mail Provider
TLS Configuration
TLS Protocol Support
HSTS Header
Questions to ask
Confirm MTA-STS rollout plans for inbound email
Sign in to see 2 more
Estimated remediation effort: 2–4 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change 1 scan · Last scanned September 28, 2026
Score
100 75 50 25 0
B
suno.com
85/100
Compliance & Certifications
Not yet verified
SOC 2 TYPE II
SOC 2 Type II
Audit report not on file
3rd party · AICPA
ISO 27001
ISO 27001
Certificate not on file
3rd party · accredited body
GDPR
GDPR
DPA not on file
Self-reported
CCPA
CCPA
Privacy policy not on file
Self-reported
Incident History
1 public breach on record
November 2025
Suno data breach
Have I Been Pwned · 55.3M accounts
Security Posture
7 items need attention
8 passed
Add missing cookie security settings
Cookie Security
1–2 hours High

This makes it meaningfully easier for an attacker to hijack authenticated customer sessions, increasing account-takeover risk. On suno.com, most cookies are missing key protections: 3 cookie(s) can be sent over an unencrypted connection (missing the "Secure" flag); 3 cookie(s) can be read by page scripts, including malicious ones (missing "HttpOnly").

OWASP ASVS3.4
Session cookies use Secure, HttpOnly, and SameSite attributes
How to fix this
1Add Secure to every cookie your site sets — this is usually one line in your app's session/cookie config, not a DNS or hosting setting.
2Add HttpOnly to login/session cookies — same place as above, in your app's cookie settings.
3This needs a developer — it's a one-line change per cookie in your website's code, not something changeable from a hosting dashboard.
4Re-scan afterward to confirm all three flags are now set.
Report unlocked.
View all 8 passed checks
MX Records & Mail Provider
TLS Configuration
TLS Protocol Support
HSTS Header
Subprocessors & Tech Stack
CVE Exposure
Certificate Hygiene
DMARC / Email Security
Couldn't check: Malware / Phishing Blocklist — the check didn't complete (the site blocked or timed out our scanner, or a data source was unavailable), so this isn't counted in the score.
Company Signals
Operational risk
Last funding
Employees
Trust Resources
Claim profile →
Trust Center
Not detected
Privacy Policy
DPA (Data Processing Agreement)
Subprocessors List
Similar companies
Appears in
Vendors graded B
791 companies · LynxRadar ranking