Permutive · Trust Center

Permutive Trust Center

Trust center

Permutive maintains a public trust center documenting SOC 2 Type II and SOC 3 compliance.

CompanyPublishingAdvertisingAdTechMarTechAudienceData CollaborationData Management PlatformContextualIdentitySegmentationAgents
Trust center: https://trust.permutive.com/

Certifications & Compliance

SOC 2 Type IISOC 3

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
url: https://trust.permutive.com/
source: https://docs.permutive.com/governance/security
notes: >-
  UPGRADE to the 2026-07-20 file, which recorded the Trust Center as live but
  asserted no certifications because trust.permutive.com is a client-rendered
  Vanta application that no crawler can read. The certifications are now
  recorded because Permutive states them itself, in prose, on its own
  developer-documentation security page — a source that is fetchable and
  quotable — rather than being inferred from the Trust Center shell.
certifications:
- {name: SOC 2 Type II, status: audited-annually, evidence: 'https://docs.permutive.com/governance/security'}
- {name: SOC 3, status: published, note: 'SOC 3 reports available publicly', evidence: 'https://docs.permutive.com/governance/security'}
compliance_program:
  attestations_via: https://trust.permutive.com
  trust_center_contents: [compliance reports, penetration testing documentation, security FAQs,
    subprocessors, live compliance status]
  privacy_regimes: [GDPR, ePrivacy Directive, CCPA]
  data_role: >-
    Permutive operates as a DATA PROCESSOR on behalf of customers (media
    companies and advertisers) who are the data controllers, governed by a DPA.
security_posture:
  encryption_at_rest: AES-256
  encryption_in_transit: TLS 1.2 or higher
  key_management: cloud KMS with separation of duties and auditing
  tenant_isolation: application- and infrastructure-level access controls
  sso: [SAML, OpenID Connect]
  mfa: enforced via customer IdP for privileged and administrative access
  rbac: true
  just_in_time_privileged_access: true
  vulnerability_management: continuous scanning across application code, cloud infrastructure and workloads
  secure_sdlc: automated code analysis and dependency scanning in pipelines
  penetration_testing: independent third-party, regular cadence
  bug_bounty: private
consent_controls:
  mechanisms: [consent-by-token, consent-by-default, opt-out]
  source: https://docs.permutive.com/governance/consent
  note: >-
    Relevant to an advertising-data platform: the SDK can be configured with
    `consentRequired: true` so no user data is collected until a consent token
    is supplied. The CCS API has NO server-side consent gate — Permutive
    documents that the caller is responsible for enforcing consent before
    sending events.
evidence:
- {source: 'https://docs.permutive.com/governance/security', kind: security-practices-page,
   http_status: 200, keywords: ['SOC 2 Type II', 'SOC 3', 'penetration testing', 'AES-256',
     'TLS 1.2', 'SAML', 'OpenID Connect'], fetched: '2026-08-13'}
- {source: 'https://trust.permutive.com/', kind: trust-center, http_status: 200,
   detail: 'Vanta-hosted; client-rendered, not machine-readable', fetched: '2026-08-13'}
- {source: 'https://docs.permutive.com/governance/consent', kind: consent-documentation,
   http_status: 200, fetched: '2026-08-13'}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/permutive-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.