SOC2C

Is this your company? Buyers are checking Patch My PC here. Claim patchmypc.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Patch My PC logo

Patch My PC

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Patch My PC is SOC 2 Type II compliant. Patch My PC also holds ISO 27001, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Founded in 2011, we’re a team of 125 dedicated to keeping you more secure online and making application management easy. Our Trust portal provides access security and privacy related resources, certificates, sub-processor information and documentation.

Compliance & infrastructure

Hosting
Azure
Data handled
Employee personally identifiable informationCredit card informationPersonal health information

Subprocessors

14
  • M
    Microsoft · Cloud provider
    United States & EEA
  • S
    Salesforce · Customer Relationship Management
    United States
  • C
    CloudFlare · Cloud Monitoring & WAF
    United States
  • H
    HubSpot · Marketing Behavior Analytics
    United States
  • S
    SendGrid · Customer Communication
    United States & EEA
  • C
    Calendly · Meeting Scheduling System
    United States
  • M
    Maxio · Finance and Payments
    United States
  • L
    LinkSquares · Contract Management
    United States
  • D
    DocuSign · Contract Management
    United States
  • T
    Tidio · Chat Helpdesk Tool
    EEA
  • I
    Intuit · Accounting Software
    United States
  • C
    ClickUp · Project Planning
    United States
Show all 14 subprocessors
  • F
    Front · Customer communication platform
    United States
  • M
    Method CRM · Customer relationship management
    United States

Compliance leadership

The person who leads Patch My PC's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Patch My PC's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

New SOC 2 Type II ReportJun 2026

Patch My PC is happy to announce that a new SOC 2 Type II report is available and can be found in the Overview Tab or the Resources Tab. The new report covers an audit period of April 1, 2025 to March 31, 2026.

Subprocessors Clarity UpdateMar 2026

For increased clarity, we have implemented some new features in the trust center and provided a short written explanation on the usage of each of our subprocessors. The new feature allows the usage of tagging, to define what the subprocessors are used for. We have added, internal, cloud, on-prem, website and tagged each of the subprocessors to their appropriate use cases. Our goal with this is to provide clarity when trying to understand which services use which tools. Tools marked with only the internal tag, are back office tools used for running the business that may process the first and last name of the contract holder or the administrator. Additionally, a short purpose statement has been added to each subprocessor.

New penetration test report available + FAQ updatesMar 2026

Hello everyone, Our latest penetration test report, along with an attestation signed by our Director of Security & IT, has been released for customer review. These documents can be found in the Resources tab. We've also updated our FAQ page. You'll find expanded FAQ categories for easier navigation as well as a new section about the PSADT App Migration AI tool we've added into Patch My PC Cloud. If there are any questions, please feel free to reach out to security@patchmypc.com.

Notepad++/State-Sponsored Hacking ResponseFeb 2026

Patch My PC is aware of a supply‑chain attack (Notepad++ Hijacked by State-Sponsored Hackers | Notepad++) that redirected legitimate Notepad++ update traffic to malicious servers between June and December 2025, affecting only users who used the app’s internal updater. Organizations using Patch My PC were protected, assuming the end user did not leverage the built in update service in Notepad++. Our process downloads vendor‑supplied binaries directly from their GitHub repository and blocks anything that fails strict hash validation (Security Validation of Updates & Apps: Deep Dive - Patch My PC), which prevented any tampered Notepad++ update from being deployed. To be on the safe side you should assume the automatic updater was used during the six-month window by some users in your org. Therefore, we recommend ensuring all users have the latest Notepad++ version (at least 8.8.9) installed and then investigating using your EDR tooling. Rapid 7 has published, what they believe to be an IOC, and some files to investigate; Message from Rapid7 Chat

React RSC Vulnerability (CVE-2025-55182)Dec 2025

A recently disclosed vulnerability in React RSC (CVE-2025-55182) has been brought to our attention. Patch My PC has thoroughly reviewed this issue and confirmed that our products do not utilize the affected NPM packages. Furthermore, we have additional safeguards in place through Cloudflare to provide enhanced protection. We will continue to monitor the situation and maintain our commitment to security best practices.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Patch My PC SOC 2 compliant?
Patch My PC is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Patch My PC ISO 27001 certified?
According to Patch My PC's public trust center, Patch My PC is ISO 27001 certified. On SOC2C this listing is Listed.
Is Patch My PC GDPR compliant?
According to Patch My PC's public trust center, Patch My PC is GDPR compliant. On SOC2C this listing is Listed.
Is Patch My PC SOC 2 Type I or Type II?
Patch My PC is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Patch My PC's SOC 2 for a vendor risk assessment?
Yes. Patch My PC's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.