SOC2C

Peppy Health security & compliance

An overview of Peppy Health's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 · Listed
FrameworksISO 27001, GDPR
Penetration testNot listed
Subprocessors11 listed
HostingGCP
Trust centerView

Security questions about Peppy Health

Is Peppy Health secure?
Security isn't a single yes/no, but Peppy Health is SOC 2 compliant and holds ISO 27001, GDPR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Peppy Health have a bug bounty or vulnerability disclosure program?
Peppy Health hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@peppy.health or via a /security page (Peppy Health lists a security contact).
Who are Peppy Health's subprocessors?
Peppy Health lists 11 subprocessors on its trust center, including Google Cloud Platform, Mixpanel, Sentry, Customer.IO, Vanta. Buyers use this for fourth-party risk review.
Where does Peppy Health host or store data?
Peppy Health hosts on GCP, and handles Customer personally identifiable information, Personal health information. Data residency details are on its trust center.
Where is Peppy Health's trust center or security page?
Peppy Health's trust center is at https://trust.peppy.health. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Peppy Health's full SOC 2 profile →