Permutive · Trust Center
Permutive Trust Center
Trust center
Permutive maintains a public trust center documenting SOC 2 Type II and SOC 3 compliance.
CompanyPublishingAdvertisingAdTechMarTechAudienceData CollaborationData Management PlatformContextualIdentitySegmentationAgents
Trust center: https://trust.permutive.com/
Certifications & Compliance
SOC 2 Type IISOC 3
Source
Trust Center
generated: '2026-08-13'
method: searched
probe: true
url: https://trust.permutive.com/
source: https://docs.permutive.com/governance/security
notes: >-
UPGRADE to the 2026-07-20 file, which recorded the Trust Center as live but
asserted no certifications because trust.permutive.com is a client-rendered
Vanta application that no crawler can read. The certifications are now
recorded because Permutive states them itself, in prose, on its own
developer-documentation security page — a source that is fetchable and
quotable — rather than being inferred from the Trust Center shell.
certifications:
- {name: SOC 2 Type II, status: audited-annually, evidence: 'https://docs.permutive.com/governance/security'}
- {name: SOC 3, status: published, note: 'SOC 3 reports available publicly', evidence: 'https://docs.permutive.com/governance/security'}
compliance_program:
attestations_via: https://trust.permutive.com
trust_center_contents: [compliance reports, penetration testing documentation, security FAQs,
subprocessors, live compliance status]
privacy_regimes: [GDPR, ePrivacy Directive, CCPA]
data_role: >-
Permutive operates as a DATA PROCESSOR on behalf of customers (media
companies and advertisers) who are the data controllers, governed by a DPA.
security_posture:
encryption_at_rest: AES-256
encryption_in_transit: TLS 1.2 or higher
key_management: cloud KMS with separation of duties and auditing
tenant_isolation: application- and infrastructure-level access controls
sso: [SAML, OpenID Connect]
mfa: enforced via customer IdP for privileged and administrative access
rbac: true
just_in_time_privileged_access: true
vulnerability_management: continuous scanning across application code, cloud infrastructure and workloads
secure_sdlc: automated code analysis and dependency scanning in pipelines
penetration_testing: independent third-party, regular cadence
bug_bounty: private
consent_controls:
mechanisms: [consent-by-token, consent-by-default, opt-out]
source: https://docs.permutive.com/governance/consent
note: >-
Relevant to an advertising-data platform: the SDK can be configured with
`consentRequired: true` so no user data is collected until a consent token
is supplied. The CCS API has NO server-side consent gate — Permutive
documents that the caller is responsible for enforcing consent before
sending events.
evidence:
- {source: 'https://docs.permutive.com/governance/security', kind: security-practices-page,
http_status: 200, keywords: ['SOC 2 Type II', 'SOC 3', 'penetration testing', 'AES-256',
'TLS 1.2', 'SAML', 'OpenID Connect'], fetched: '2026-08-13'}
- {source: 'https://trust.permutive.com/', kind: trust-center, http_status: 200,
detail: 'Vanta-hosted; client-rendered, not machine-readable', fetched: '2026-08-13'}
- {source: 'https://docs.permutive.com/governance/consent', kind: consent-documentation,
http_status: 200, fetched: '2026-08-13'}