SOC2C

Is this your company? Buyers are checking Pigment here. Claim pigment.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Pigment logo

Pigment

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Pigment is SOC 2 Type II compliant. Pigment also holds ISO 27001, GDPR, CCPA, and CSA STAR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

The business planning and performance management platform for visionary organizations.

Compliance & infrastructure

Compliance leadership

The person who leads Pigment's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Pigment's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

NEW: Structured API key format to support automated secret scanning integrationsMay 2026

We have released an update which changes the format of all newly generated API keys within Pigment. The new format is more predictable and designed for discoverability by secret scanning programmes. Refer to the newly updated Secure Implementation Guidebook resource with more information on the format, including a regex you can use in your security tooling.

Pigment achieves ISO 27001 Certification, strengthening commitment to data securityApr 2026

Pigment has achieved ISO 27001 certification following an independent audit of our information security management system. This milestone strengthens our commitment to rigorous security standards and provides customers with independent assurance that a comprehensive, risk-based set of controls is in place to help protect their data. As part of this update, we’ve added our ISO 27001 certificate and Statement of Applicability (SoA) to the Trust Center, so you can review the scope of our certification and the security controls under our program.

UPDATED: Pigment Security Whitepaper & Secure Implementation GuidebookApr 2026

We have updated our Security Whitepaper to reflect changes introduced with the release of Pigment’s Modeler Agent. We have also updated the Secure Implementation Guidebook to describe new and updated security features in Pigment, including the new “Essential Contacts” feature, which lets you specify dedicated email addresses for ad hoc communications about privacy, legal, or security matters.

SOC compliance updateFeb 2026

We're happy to announce that our latest SOC1 and SOC2 audit reports are available on the Trust Center. We improved the level of assurance they bring by adding the “Availability” and “Confidentiality” Trust Criteria on top of "Security" for this iteration.

UPDATED DOCUMENT: 2025 attestation for performance of annual penetration testJun 2025

Pigment's 2025 attestation for performance of annual penetration test has been updated in the Trust Center

This listing is partial

4/11 details · 36%

SOC2C shows the verified essentials. 7 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Pigment SOC 2 compliant?
Pigment is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Pigment ISO 27001 certified?
According to Pigment's public trust center, Pigment is ISO 27001 certified. On SOC2C this listing is Listed.
Is Pigment GDPR compliant?
According to Pigment's public trust center, Pigment is GDPR compliant. On SOC2C this listing is Listed.
Is Pigment CCPA compliant?
According to Pigment's public trust center, Pigment is CCPA compliant. On SOC2C this listing is Listed.
Is Pigment CSA STAR certified?
According to Pigment's public trust center, Pigment is CSA STAR certified. On SOC2C this listing is Listed.

Answers published by Pigment

Reproduced from Pigment's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Does Pigment publish its standard terms?
Pigment publishes the following documents: Publicly available - Master Service Agreement - Data Protection Addendum - Security Addendum - Acceptable Use Policy - Privacy Policy - Vulnerability Disclosure Policy - List of sub-processors - Support and Maintenance Policy - CAIQ Under NDA - General Information Security Policy - SOC1 report - SOC2 report - Security whitepaper - Evidence of penetration test performance - Cyber insurance policy - BCDR test summary
Where is Pigment's infrastructure located?
All customer content data is hosted in Google Cloud Platform. Pigment offers several data localisation options in Europe and in the USA. Customers may choose the localisation of their data amongst these options during the initial setup. For Europe, the infrastructure is located in Frankfurt, Germany (europe-west-3), whereas the backups are replicated in geo-distributed storage buckets in member states of the European Union. For the USA, the infrastructure is located in The Dalles, Oregon (us-west-1), whereas the backups are replicated in geo-distributed storage buckets in the USA. Although the data processed by the product remains in the chosen localisation, some customer data such as user identities, list of tenants, analytics, email notifications, supports tickets, learning centre, CRM, etc. may be processed or stored outside of the chosen data locality for technical reasons. Please refer to the sub-processor list for a detailed list of data transfers: https://www.pigment.com/msa/dpa-subprocessors
Does Pigment support Single Sign-On (SSO)?
Pigment supports the following authentication methods: - Email / Password - Federated identity through SAMLv2 standard protocol - Open ID Connect through Google social login
Does Pigment encrypt data at rest?
All customer data is encrypted at rest at any time. We currently use multiple storage-as-a-service built in encryption features to ensure consistent enforcement and state of the art encryption and key management practices. AES 256 is the main standard in use. Database encryption is currently performed through Cloud SQL's and SingleStore's encryption features. Backups are encrypted through Google Cloud Storage's encryption. For technical details, please refer to the vendor's documentation: - Google Cloud SQL - Google Cloud Storage - SingleStore
How does Pigment protect data in transit?
All Pigment web properties have mandatory encryption in transit. We implement HSTS on all domains with subdomain enforcement and systematic preloading. We're not supporting any protocol weaker than TLS1.2 and we ensure we remain on the "modern" compatibility policies (as defined by Mozilla and Google guidance) to avoid accepting legacy, unsafe cipher suites. To minimise the impact of a compromission of a certificate, we use short lived, programmatically renewed certificates and prohibit the use of wildcard certificates. We also procure certificates from providers adhering to the certificate transparency initiative. See how Pigment scores on the reference TLS configuration scoring tool: https://www.ssllabs.com/ssltest/analyze.html?d=pigment.app

Business & Industrial peers that completed SOC 2