SOC2C

Is this your company? Buyers are checking Exterro here. Claim exterro.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Exterro logo

Exterro

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Exterro is SOC 2 Type II compliant. Exterro also holds ISO 27001, FedRAMP, and HITRUST.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Exterro was founded with the simple vision that applying the concepts of process optimization and data science to how companies manage digital information and respond to requests for that information would drive more successful outcomes at a lower cost. Exterro executed on this vision by building a platform-based, comprehensive software suite to address the needs of organizations to manage the risk associated with the data they stored and used. To this day, the company remains committed to our original vision as a provider of data risk management software applications, delivering solutions tha

Compliance & infrastructure

Hosting
AWSGCPAzure

Documents

2

Subprocessors

8
  • A
    Amazon Web Services · Public Cloud Infrastructure
    US, EU, CA Regions
  • G
    Google, Inc · Google Cloud Platform (GCP)
    United States, EU
  • M
    Microsoft Azure · Public Cloud Infrastructure
    United States
  • S
    Snowflake · Data Analytics
    United States
  • S
    Salesforce · Account Management, Customer Relationship Support, and Customer Support Ticketin
    United States
  • S
    SendSafely Website · Secure File Transfer and Message Exchange
    United States
  • C
    Canny · Product Feedback
    United States
  • A
    Atlassian Confluence · Collaboration
    United States

Compliance leadership

The person who leads Exterro's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Exterro's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Gainsight Communication UpdateMar 2026

On December 8, 2025, Exterro received an Indicator of Compromise (IOC) notification of a potential data issue with the Gainsight application. Exterro investigated the issue with guidance from the vendor. Exterro has reviewed the issue and has not seen any indication of compromise or unauthorized access to systems that hold customer data. As always, the security and integrity of our systems remain a top priority. We will continue monitoring potential threats and take necessary precautions to safeguard our operations. If you have any questions or concerns about this matter, please don't hesitate to contact us. Thank you for your attention to this update.

Update: CVE-2024-50623 and CVE-2024-55956 (Cleo Multiple Products) – No Impact on ExterroDec 2024

We would like to provide an update regarding the recently disclosed vulnerabilities, CVE-2024-50623 and CVE-2024-55956. After thorough review we are pleased to confirm that these vulnerabilities have no impact on Exterro, as our systems do not utilize the affected components. At Exterro, the security and integrity of our systems are of the utmost importance. We remain vigilant in monitoring emerging threats and are committed to implementing all necessary measures to ensure the safety of our operations. If you have any questions or require additional information, please feel free to contact us. Thank you for your continued trust and attention to this matter.

Snowflake Communication UpdateJun 2024

On June 2,2024, Snowflake indicated a recent increase in cyber threat activity targeting customer accounts on its cloud data platform. Snowflake issued a recommendation for users to query for unusual activity and conduct further analysis to prevent unauthorized user access. Exterro has reviewed the provided instructions. Exterro has not seen any indication of compromise or unauthorized access to systems that hold customer data. As always, the security and integrity of our systems remain a top priority. We will continue monitoring potential threats and take necessary precautions to safeguard our operations. If you have any questions or concerns about this matter, please don't hesitate to contact us. Thank you for your attention to this update.

Update: CVE-2024-3094 - No Impact on Our FirmApr 2024

We are providing a brief update regarding CVE-2024-3094, a recently discovered vulnerability. We are pleased to inform you that this vulnerability does not impact Exterro. After careful review and analysis, it has been determined that the vulnerability affects a higher version of XZUtils, which we do not utilize in our systems. Our current version is not susceptible to the identified issue. We want to assure you that the security and integrity of our systems remain a top priority. We will continue monitoring potential threats and take necessary precautions to safeguard our operations. If you have any questions or concerns about this matter, please don't hesitate to contact us. Thank you for your attention to this update.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Exterro SOC 2 compliant?
Exterro is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Exterro ISO 27001 certified?
According to Exterro's public trust center, Exterro is ISO 27001 certified. On SOC2C this listing is Listed.
Is Exterro FedRAMP compliant?
According to Exterro's public trust center, Exterro is FedRAMP compliant. On SOC2C this listing is Listed.
Is Exterro HITRUST certified?
According to Exterro's public trust center, Exterro is HITRUST certified. On SOC2C this listing is Listed.
Is Exterro SOC 2 Type I or Type II?
Exterro is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Business & Industrial peers that completed SOC 2