ThreatLocker · Trust Center

Threatlocker Trust Center

Trust center

ThreatLocker maintains a public trust center documenting SOC 2 Type II, ISO 27001, and FedRAMP compliance.

CybersecurityZero TrustEndpoint SecurityApplication-ControlallowlistingRansomware PreventionPrivileged Access ManagementNetwork Access ControlManaged Detection and ResponseDevice ManagementMSPCompliance
Trust center: https://threatlocker.kb.help/threatlocker-security-and-privacy/

Certifications & Compliance

SOC 2 Type IIISO 27001FedRAMP

Source

Trust Center

Raw ↑
generated: '2026-08-02'
method: searched
probe: true
source: >-
  https://threatlocker.kb.help/threatlocker-security-and-privacy/, https://threatlocker.kb.help/compliance/,
  https://www.threatlocker.com/software-security-audit
url: https://threatlocker.kb.help/threatlocker-security-and-privacy/
dedicated_trust_center: false
note: >-
  ThreatLocker publishes no trust.threatlocker.com or /trust page — trust.threatlocker.com does not
  resolve and www.threatlocker.com/security and /compliance both 404. Its security and compliance
  posture is published inside the Help Center instead. The automated probe
  (0-working/probe-security-programs.py) therefore returned trust=none; this file records the posture
  found by manual search of the pages ThreatLocker actually publishes.
certifications:
- {name: SOC 2 Type II, status: certified, detail: 'Security controls audited at least annually by an independent AICPA-certified auditor; the SOC 2 Type II report is available to customers on request under NDA'}
- {name: ISO 27001, status: in-progress, detail: 'Stated in progress as of March 2026; ThreatLocker states ISO 27001/2 compliance in its security documentation'}
- {name: FedRAMP, status: instance-published, detail: 'A dedicated "Portal [Instance FedRAMP]" component is published on the public status page'}
practices:
  encryption: All confidential information, including data transmitted to and from the ThreatLocker agent, is encrypted in transit and at rest using industry-standard encryption protocols.
  penetration_testing: ThreatLocker undergoes regular internal and external penetration tests.
  data_residency: Regionally isolated instances (AE1, AU1, CA1, EU1, SA1 and lettered US/global instances) with per-instance portal and API hosts.
vulnerability_disclosure:
  found: false
  policy: null
  contact: null
  bug_bounty: null
  note: >-
    NO vulnerability disclosure program, responsible-disclosure policy, published security contact, or
    bug bounty was found — notable for a security vendor. /.well-known/security.txt returns 404 on
    every ThreatLocker host, and /security, /responsible-disclosure and /vulnerability-disclosure all
    404 on www.threatlocker.com. No HackerOne, Bugcrowd or Intigriti program was found. No `Security`
    or `VulnerabilityDisclosure` pointer is wired in apis.yml because nothing is published; this is a
    verified absence, not an untested one.
  probes:
  - {url: 'https://www.threatlocker.com/.well-known/security.txt', http_status: 404}
  - {url: 'https://www.threatlocker.com/security.txt', http_status: 404}
  - {url: 'https://portalapi.threatlocker.com/.well-known/security.txt', http_status: 404}
  - {url: 'https://threatlocker.kb.help/.well-known/security.txt', http_status: 404}
  - {url: 'https://www.threatlocker.com/responsible-disclosure', http_status: 404}
  - {url: 'https://www.threatlocker.com/vulnerability-disclosure', http_status: 404}
frameworks_page: https://threatlocker.kb.help/compliance/
audit_report_page: https://www.threatlocker.com/software-security-audit
evidence:
- {source: 'https://threatlocker.kb.help/threatlocker-security-and-privacy/', http_status: 200, keywords: [soc 2 type ii, iso 27001, encryption, penetration test, cmmc level 2, hipaa]}
- {source: 'https://threatlocker.kb.help/compliance/', http_status: 200, keywords: [nist, cmmc, pci-dss, iso 27001 annex a, hipaa security rule, cis controls]}
- {source: 'https://www.threatlocker.com/software-security-audit', http_status: 200}
- {source: 'https://trust.threatlocker.com/', http_status: 0, result: does-not-resolve}
- {source: 'https://www.threatlocker.com/security', http_status: 404}
- {source: 'https://www.threatlocker.com/compliance', http_status: 404}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/threatlocker-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.