Is this your company? Buyers are checking Pigment here. Claim pigment.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Pigment
Sourced from public information. Not yet verified by the company.
Pigment is SOC 2 Type II compliant. Pigment also holds ISO 27001, GDPR, CCPA, and CSA STAR.
About
The business planning and performance management platform for visionary organizations.
Compliance & infrastructure
Compliance leadership
The person who leads Pigment's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Pigment's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
NEW: Structured API key format to support automated secret scanning integrationsMay 2026
We have released an update which changes the format of all newly generated API keys within Pigment. The new format is more predictable and designed for discoverability by secret scanning programmes. Refer to the newly updated Secure Implementation Guidebook resource with more information on the format, including a regex you can use in your security tooling.
Pigment achieves ISO 27001 Certification, strengthening commitment to data securityApr 2026
Pigment has achieved ISO 27001 certification following an independent audit of our information security management system. This milestone strengthens our commitment to rigorous security standards and provides customers with independent assurance that a comprehensive, risk-based set of controls is in place to help protect their data. As part of this update, we’ve added our ISO 27001 certificate and Statement of Applicability (SoA) to the Trust Center, so you can review the scope of our certification and the security controls under our program.
UPDATED: Pigment Security Whitepaper & Secure Implementation GuidebookApr 2026
We have updated our Security Whitepaper to reflect changes introduced with the release of Pigment’s Modeler Agent. We have also updated the Secure Implementation Guidebook to describe new and updated security features in Pigment, including the new “Essential Contacts” feature, which lets you specify dedicated email addresses for ad hoc communications about privacy, legal, or security matters.
SOC compliance updateFeb 2026
We're happy to announce that our latest SOC1 and SOC2 audit reports are available on the Trust Center. We improved the level of assurance they bring by adding the “Availability” and “Confidentiality” Trust Criteria on top of "Security" for this iteration.
UPDATED DOCUMENT: 2025 attestation for performance of annual penetration testJun 2025
Pigment's 2025 attestation for performance of annual penetration test has been updated in the Trust Center
This listing is partial
4/11 details · 36%SOC2C shows the verified essentials. 7 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- SubprocessorsList your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
- HostingAdd where you host (AWS, GCP, Azure) and data residency.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Pigment SOC 2 compliant?
Is Pigment ISO 27001 certified?
Is Pigment GDPR compliant?
Is Pigment CCPA compliant?
Is Pigment CSA STAR certified?
Is Pigment SOC 2 Type I or Type II?
Can I use Pigment's SOC 2 for a vendor risk assessment?
Is Pigment penetration tested?
Is Pigment secure?
Does Pigment have a bug bounty or vulnerability disclosure program?
Who are Pigment's subprocessors?
Where does Pigment host or store data?
Where is Pigment's trust center or security page?
Does Pigment publish its standard terms?
Where is Pigment's infrastructure located?
Does Pigment support Single Sign-On (SSO)?
Does Pigment encrypt data at rest?
How does Pigment protect data in transit?
How does Pigment manage vulnerabilities?
What are Pigment's business continuity and disaster recovery practices?
How does Pigment manage customer data removal?
How does Pigment manage vendor security?
Does Pigment notify its customer in case of a data breach?
How is access control managed in Pigment?
How is Pigment clients' data segmented from from one another?
Business & Industrial peers that completed SOC 2

Newsworthy.ai

1099-Prep

Octopus Deploy
