Is this your company? Buyers are checking Patch My PC here. Claim patchmypc.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Patch My PC
Sourced from public information. Not yet verified by the company.
Patch My PC is SOC 2 Type II compliant. Patch My PC also holds ISO 27001, and GDPR.
About
Founded in 2011, we’re a team of 125 dedicated to keeping you more secure online and making application management easy. Our Trust portal provides access security and privacy related resources, certificates, sub-processor information and documentation.
Compliance & infrastructure
Subprocessors
14- MMicrosoft · Cloud providerUnited States & EEA
- SSalesforce · Customer Relationship ManagementUnited States
- CCloudFlare · Cloud Monitoring & WAFUnited States
- HHubSpot · Marketing Behavior AnalyticsUnited States
- SSendGrid · Customer CommunicationUnited States & EEA
- CCalendly · Meeting Scheduling SystemUnited States
- MMaxio · Finance and PaymentsUnited States
- LLinkSquares · Contract ManagementUnited States
- DDocuSign · Contract ManagementUnited States
- TTidio · Chat Helpdesk ToolEEA
- IIntuit · Accounting SoftwareUnited States
- CClickUp · Project PlanningUnited States
Show all 14 subprocessorsShow fewer
- FFront · Customer communication platformUnited States
- MMethod CRM · Customer relationship managementUnited States
Compliance leadership
The person who leads Patch My PC's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Patch My PC's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
New SOC 2 Type II ReportJun 2026
Patch My PC is happy to announce that a new SOC 2 Type II report is available and can be found in the Overview Tab or the Resources Tab. The new report covers an audit period of April 1, 2025 to March 31, 2026.
Subprocessors Clarity UpdateMar 2026
For increased clarity, we have implemented some new features in the trust center and provided a short written explanation on the usage of each of our subprocessors. The new feature allows the usage of tagging, to define what the subprocessors are used for. We have added, internal, cloud, on-prem, website and tagged each of the subprocessors to their appropriate use cases. Our goal with this is to provide clarity when trying to understand which services use which tools. Tools marked with only the internal tag, are back office tools used for running the business that may process the first and last name of the contract holder or the administrator. Additionally, a short purpose statement has been added to each subprocessor.
New penetration test report available + FAQ updatesMar 2026
Hello everyone, Our latest penetration test report, along with an attestation signed by our Director of Security & IT, has been released for customer review. These documents can be found in the Resources tab. We've also updated our FAQ page. You'll find expanded FAQ categories for easier navigation as well as a new section about the PSADT App Migration AI tool we've added into Patch My PC Cloud. If there are any questions, please feel free to reach out to security@patchmypc.com.
Notepad++/State-Sponsored Hacking ResponseFeb 2026
Patch My PC is aware of a supply‑chain attack (Notepad++ Hijacked by State-Sponsored Hackers | Notepad++) that redirected legitimate Notepad++ update traffic to malicious servers between June and December 2025, affecting only users who used the app’s internal updater. Organizations using Patch My PC were protected, assuming the end user did not leverage the built in update service in Notepad++. Our process downloads vendor‑supplied binaries directly from their GitHub repository and blocks anything that fails strict hash validation (Security Validation of Updates & Apps: Deep Dive - Patch My PC), which prevented any tampered Notepad++ update from being deployed. To be on the safe side you should assume the automatic updater was used during the six-month window by some users in your org. Therefore, we recommend ensuring all users have the latest Notepad++ version (at least 8.8.9) installed and then investigating using your EDR tooling. Rapid 7 has published, what they believe to be an IOC, and some files to investigate; Message from Rapid7 Chat
React RSC Vulnerability (CVE-2025-55182)Dec 2025
A recently disclosed vulnerability in React RSC (CVE-2025-55182) has been brought to our attention. Patch My PC has thoroughly reviewed this issue and confirmed that our products do not utilize the affected NPM packages. Furthermore, we have additional safeguards in place through Cloudflare to provide enhanced protection. We will continue to monitor the situation and maintain our commitment to security best practices.
This listing is partial
6/11 details · 55%SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Patch My PC SOC 2 compliant?
Is Patch My PC ISO 27001 certified?
Is Patch My PC GDPR compliant?
Is Patch My PC SOC 2 Type I or Type II?
Can I use Patch My PC's SOC 2 for a vendor risk assessment?
Is Patch My PC penetration tested?
Is Patch My PC secure?
Does Patch My PC have a bug bounty or vulnerability disclosure program?
Who are Patch My PC's subprocessors?
Where does Patch My PC host or store data?
Where is Patch My PC's trust center or security page?
Does Patch My PC hold any security certifications?
Does Patch My PC conduct external IT audits? May we have the report?
Is Patch My PC GDPR compliant?
Is Patch My PC FedRAMP compliant?
Is Patch My PC HIPAA compliant?
Does Patch My PC handle credit card data? Can you provide documentation of PCI DSS compliance?
What company or personal user data is required to use your service?
Where is customer data stored and processed?
Do third-party entities have access to Patch My PC's customer data?
Does Patch My PC handle their customer’s student/patient/customer data?
How long is data retained?
How do I report a potential security issue?
Technology peers that completed SOC 2

Action1

ELJUN LLC

equipifi
