SOC2C

Prisma security & compliance

An overview of Prisma's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksGDPR, HIPAA, ISO 27001, SOC 2 Type II
Penetration testNot listed
Subprocessors23 listed
HostingAWS
Trust centerView

Security questions about Prisma

Is Prisma secure?
Security isn't a single yes/no, but Prisma is SOC 2 Type II compliant and holds GDPR, HIPAA, ISO 27001, SOC 2 Type II. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Prisma have a bug bounty or vulnerability disclosure program?
Prisma hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@prisma.io or via a /security page (Prisma lists a security contact).
Who are Prisma's subprocessors?
Prisma lists 23 subprocessors on its trust center, including Amazon Web Services, Brevo (SendinBlue), Cloudflare, Stripe, Inc., Google Workspace. Buyers use this for fourth-party risk review.
Where does Prisma host or store data?
Prisma hosts on AWS. Data residency details are on its trust center.
Where is Prisma's trust center or security page?
Prisma's trust center is at https://trust.prisma.io. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Prisma's full SOC 2 profile →