Permutive · Trust Center

Permutive Trust Center

Trust center

Permutive maintains a public trust center documenting SOC 2 Type II and SOC 3 compliance.

CompanyPublishingAdvertisingAdTechMarTechAudienceData CollaborationData Management PlatformContextualIdentitySegmentationAgents
Trust center: https://trust.permutive.com/

Certifications & Compliance

SOC 2 Type IISOC 3

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
url: https://trust.permutive.com/
source: https://docs.permutive.com/governance/security
notes: >-
  UPGRADE to the 2026-07-20 file, which recorded the Trust Center as live but
  asserted no certifications because trust.permutive.com is a client-rendered
  Vanta application that no crawler can read. The certifications are now
  recorded because Permutive states them itself, in prose, on its own
  developer-documentation security page — a source that is fetchable and
  quotable — rather than being inferred from the Trust Center shell.
certifications:
- {name: SOC 2 Type II, status: audited-annually, evidence: 'https://docs.permutive.com/governance/security'}
- {name: SOC 3, status: published, note: 'SOC 3 reports available publicly', evidence: 'https://docs.permutive.com/governance/security'}
compliance_program:
  attestations_via: https://trust.permutive.com
  trust_center_contents: [compliance reports, penetration testing documentation, security FAQs,
    subprocessors, live compliance status]
  privacy_regimes: [GDPR, ePrivacy Directive, CCPA]
  data_role: >-
    Permutive operates as a DATA PROCESSOR on behalf of customers (media
    companies and advertisers) who are the data controllers, governed by a DPA.
security_posture:
  encryption_at_rest: AES-256
  encryption_in_transit: TLS 1.2 or higher
  key_management: cloud KMS with separation of duties and auditing
  tenant_isolation: application- and infrastructure-level access controls
  sso: [SAML, OpenID Connect]
  mfa: enforced via customer IdP for privileged and administrative access
  rbac: true
  just_in_time_privileged_access: true
  vulnerability_management: continuous scanning across application code, cloud infrastructure and workloads
  secure_sdlc: automated code analysis and dependency scanning in pipelines
  penetration_testing: independent third-party, regular cadence
  bug_bounty: private
consent_controls:
  mechanisms: [consent-by-token, consent-by-default, opt-out]
  source: https://docs.permutive.com/governance/consent
  note: >-
    Relevant to an advertising-data platform: the SDK can be configured with
    `consentRequired: true` so no user data is collected until a consent token
    is supplied. The CCS API has NO server-side consent gate — Permutive
    documents that the caller is responsible for enforcing consent before
    sending events.
evidence:
- {source: 'https://docs.permutive.com/governance/security', kind: security-practices-page,
   http_status: 200, keywords: ['SOC 2 Type II', 'SOC 3', 'penetration testing', 'AES-256',
     'TLS 1.2', 'SAML', 'OpenID Connect'], fetched: '2026-08-13'}
- {source: 'https://trust.permutive.com/', kind: trust-center, http_status: 200,
   detail: 'Vanta-hosted; client-rendered, not machine-readable', fetched: '2026-08-13'}
- {source: 'https://docs.permutive.com/governance/consent', kind: consent-documentation,
   http_status: 200, fetched: '2026-08-13'}