Is this your company? Buyers are checking Exterro here. Claim exterro.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Exterro
Sourced from public information. Not yet verified by the company.
Exterro is SOC 2 Type II compliant. Exterro also holds ISO 27001, FedRAMP, and HITRUST.
About
Exterro was founded with the simple vision that applying the concepts of process optimization and data science to how companies manage digital information and respond to requests for that information would drive more successful outcomes at a lower cost. Exterro executed on this vision by building a platform-based, comprehensive software suite to address the needs of organizations to manage the risk associated with the data they stored and used. To this day, the company remains committed to our original vision as a provider of data risk management software applications, delivering solutions tha
Compliance & infrastructure
Documents
2Subprocessors
8- AAmazon Web Services · Public Cloud InfrastructureUS, EU, CA Regions
- GGoogle, Inc · Google Cloud Platform (GCP)United States, EU
- MMicrosoft Azure · Public Cloud InfrastructureUnited States
- SSnowflake · Data AnalyticsUnited States
- SSalesforce · Account Management, Customer Relationship Support, and Customer Support TicketinUnited States
- SSendSafely Website · Secure File Transfer and Message ExchangeUnited States
- CCanny · Product FeedbackUnited States
- AAtlassian Confluence · CollaborationUnited States
Compliance leadership
The person who leads Exterro's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Exterro's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
Gainsight Communication UpdateMar 2026
On December 8, 2025, Exterro received an Indicator of Compromise (IOC) notification of a potential data issue with the Gainsight application. Exterro investigated the issue with guidance from the vendor. Exterro has reviewed the issue and has not seen any indication of compromise or unauthorized access to systems that hold customer data. As always, the security and integrity of our systems remain a top priority. We will continue monitoring potential threats and take necessary precautions to safeguard our operations. If you have any questions or concerns about this matter, please don't hesitate to contact us. Thank you for your attention to this update.
Update: CVE-2024-50623 and CVE-2024-55956 (Cleo Multiple Products) – No Impact on ExterroDec 2024
We would like to provide an update regarding the recently disclosed vulnerabilities, CVE-2024-50623 and CVE-2024-55956. After thorough review we are pleased to confirm that these vulnerabilities have no impact on Exterro, as our systems do not utilize the affected components. At Exterro, the security and integrity of our systems are of the utmost importance. We remain vigilant in monitoring emerging threats and are committed to implementing all necessary measures to ensure the safety of our operations. If you have any questions or require additional information, please feel free to contact us. Thank you for your continued trust and attention to this matter.
Snowflake Communication UpdateJun 2024
On June 2,2024, Snowflake indicated a recent increase in cyber threat activity targeting customer accounts on its cloud data platform. Snowflake issued a recommendation for users to query for unusual activity and conduct further analysis to prevent unauthorized user access. Exterro has reviewed the provided instructions. Exterro has not seen any indication of compromise or unauthorized access to systems that hold customer data. As always, the security and integrity of our systems remain a top priority. We will continue monitoring potential threats and take necessary precautions to safeguard our operations. If you have any questions or concerns about this matter, please don't hesitate to contact us. Thank you for your attention to this update.
Update: CVE-2024-3094 - No Impact on Our FirmApr 2024
We are providing a brief update regarding CVE-2024-3094, a recently discovered vulnerability. We are pleased to inform you that this vulnerability does not impact Exterro. After careful review and analysis, it has been determined that the vulnerability affects a higher version of XZUtils, which we do not utilize in our systems. Our current version is not susceptible to the identified issue. We want to assure you that the security and integrity of our systems remain a top priority. We will continue monitoring potential threats and take necessary precautions to safeguard our operations. If you have any questions or concerns about this matter, please don't hesitate to contact us. Thank you for your attention to this update.
This listing is partial
7/11 details · 64%SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Exterro SOC 2 compliant?
Is Exterro ISO 27001 certified?
Is Exterro FedRAMP compliant?
Is Exterro HITRUST certified?
Is Exterro SOC 2 Type I or Type II?
Can I use Exterro's SOC 2 for a vendor risk assessment?
Is Exterro penetration tested?
Can I get Exterro's SOC 2 report?
Is Exterro secure?
Does Exterro have a bug bounty or vulnerability disclosure program?
Who are Exterro's subprocessors?
Where does Exterro host or store data?
Where is Exterro's trust center or security page?
What is SendSafely and why is Exterro adding it as a subprocessor?
Where is SendSafely based and what compliance standards do they meet?
How will Exterro use SendSafely?
What benefits does this addition provide to Exterro customers?
How does SendSafely protect data during transmission?
What encryption methods does SendSafely use?
What security certifications does SendSafely maintain?
How does SendSafely handle vulnerability testing and security audits?
What happens if there is a data breach at SendSafely?
What types of data will SendSafely process?
Where is customer data stored and processed?
What is SendSafely's data retention policy?
Business & Industrial peers that completed SOC 2

Newsworthy.ai

Octopus Deploy

1099-Prep
