Perplexity

perplexity.ai

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
54 / 100D
Procurement decision
Approve with conditions
2 conditions outstanding
  • Data retention window not stated
  • Underlying model providers not named

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Partial

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Vendor publishedPerplexity Privacy Noticeretrieved Aug 24, 2026
We keep your personal data for only as long as necessary to fulfil the purposes in this Notice unless a longer retention period is required or permitted by law.
Underlying model providers not namedCondition

Why it matters: AI is used but the public sources scanned do not name which foundation models or providers sit in the request path.

What to ask for: Require named providers and model versions, plus notice before any model change.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

Will they train on your data?Clear

The privacy notice states email content from connected accounts is not used to create, train, improve or fine-tune AI models.

Evidence
Vendor publishedPerplexity Privacy Noticeretrieved Aug 24, 2026
We do not use the content of emails to create, train, improve, or fine-tune AI models.
!How long do they keep your data?Ask the vendor

Retention is bounded by necessity against stated purposes, with legal, accounting and reporting requirements as the extension basis.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedPerplexity Privacy Noticeretrieved Aug 24, 2026
We keep your personal data for only as long as necessary to fulfil the purposes in this Notice unless a longer retention period is required or permitted by law.
Who else can access your data?Clear

Perplexity publishes a subprocessor register on its trust portal.

Evidence
Vendor publishedSubprocessors — Perplexity AI Trust Centerretrieved Aug 24, 2026
subprocessors.
Vendor publishedPerplexity Terms of Serviceretrieved Aug 24, 2026
we do not sell your personal data or send your queries, prompts, or conversation content to advertisers.
!Where is your data processed?Ask the vendor

Transfers outside the EEA/UK are disclosed with Standard Contractual Clauses available on request.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedPerplexity Privacy Noticeretrieved Aug 24, 2026
transfer, storage, and processing of your data in a country other than your country of residence including, but not limited to, the United States.
What happens in a security incident?Clear

Perplexity documents SIEM-based monitoring, behavioural threat detection, and rapid incident response with remote forensics.

Evidence
Vendor publishedPerplexity AIretrieved Aug 24, 2026
and analysis of endpoint activity, advanced threat detection using behavioral analysis and machine learning, and rapid incident response capabilities. It also enables remote forensics to investigate and contain potential security incidents.

Key findingsclick a row for the evidence

Security engineering detail is unusually specificStrong

Named tooling (SIEM, cloud security platform, WAF), annual pentests, bounty plus public VDP, and secure SDLC detail.

Specific, falsifiable security claims beat generic assurances.

Evidence
Vendor publishedPerplexity AIretrieved Aug 24, 2026
Bug Bounty and Vulnerability Disclosure Program We are committed to building strong partnerships with the security research community. In addition to conducting annual third-party penetration tests, we actively collaborate with researchers through our private Bug Bounty program on BugCrowd and our public Vulnerability Disclosure Program (VDP)
Vendor publishedPerplexity AIretrieved Aug 24, 2026
and analysis of endpoint activity, advanced threat detection using behavioral analysis and machine learning, and rapid incident response capabilities. It also enables remote forensics to investigate and contain potential security incidents.
Vendor publishedPerplexity AIretrieved Aug 24, 2026
suite of integration and unit tests, and preview deployments to non-production environments for manual QA. Developers are trained to adhere to secure coding guidelines and are aware of the OWASP Top 10 issues. Security-sensitive code is always reviewed by domain experts.
!Enterprise AI data terms are thinner than the security storyGap

Training commitments in the collected sources are scoped to connected email content; a general no-training commitment for enterprise prompts was not found in the collected pages.

The core enterprise question needs the enterprise terms, which sit behind the trust portal.

Question for vendor: Confirm training and retention terms for Enterprise Pro and API prompts.

Evidence
Vendor publishedPerplexity Privacy Noticeretrieved Aug 24, 2026
We do not use the content of emails to create, train, improve, or fine-tune AI models.
Vendor publishedPerplexity Privacy Noticeretrieved Aug 24, 2026
We keep your personal data for only as long as necessary to fulfil the purposes in this Notice unless a longer retention period is required or permitted by law.
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedPerplexity AIretrieved Aug 24, 2026
we assess third-party sub-processors and vendors using a risk-based framework to ensure their privacy, security, and confidentiality practices align with our commitment to safeguarding customer data and maintaining a highly available service.
Vendor publishedSubprocessors — Perplexity AI Trust Centerretrieved Aug 24, 2026
subprocessors.
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedPerplexity AIretrieved Aug 24, 2026
we assess third-party sub-processors and vendors using a risk-based framework to ensure their privacy, security, and confidentiality practices align with our commitment to safeguarding customer data and maintaining a highly available service.
Vendor publishedSubprocessors — Perplexity AI Trust Centerretrieved Aug 24, 2026
subprocessors.
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedPerplexity AIretrieved Aug 24, 2026
we assess third-party sub-processors and vendors using a risk-based framework to ensure their privacy, security, and confidentiality practices align with our commitment to safeguarding customer data and maintaining a highly available service.
Vendor publishedSubprocessors — Perplexity AI Trust Centerretrieved Aug 24, 2026
subprocessors.

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score40
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedPerplexity AIretrieved Aug 24, 2026
we assess third-party sub-processors and vendors using a risk-based framework to ensure their privacy, security, and confidentiality practices align with our commitment to safeguarding customer data and maintaining a highly available service.
AI system15% of the score27
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedPerplexity AIretrieved Aug 24, 2026
suite of integration and unit tests, and preview deployments to non-production environments for manual QA. Developers are trained to adhere to secure coding guidelines and are aware of the OWASP Top 10 issues. Security-sensitive code is always reviewed by domain experts.
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedPerplexity AIretrieved Aug 24, 2026
suite of integration and unit tests, and preview deployments to non-production environments for manual QA. Developers are trained to adhere to secure coding guidelines and are aware of the OWASP Top 10 issues. Security-sensitive code is always reviewed by domain experts.
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

Change management: not publicly evidenced.

Model10% of the score0
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Not Evidenced

Model provider transparency: not publicly evidenced.

Customer data15% of the score72
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedPerplexity Privacy Noticeretrieved Aug 24, 2026
We do not use the content of emails to create, train, improve, or fine-tune AI models.
Vendor publishedPerplexity Privacy Noticeretrieved Aug 24, 2026
We keep your personal data for only as long as necessary to fulfil the purposes in this Notice unless a longer retention period is required or permitted by law.
Vendor publishedPerplexity Privacy Noticeretrieved Aug 24, 2026
transfer, storage, and processing of your data in a country other than your country of residence including, but not limited to, the United States.

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the score60
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedPerplexity AIretrieved Aug 24, 2026
we assess third-party sub-processors and vendors using a risk-based framework to ensure their privacy, security, and confidentiality practices align with our commitment to safeguarding customer data and maintaining a highly available service.
Vendor publishedSubprocessors — Perplexity AI Trust Centerretrieved Aug 24, 2026
subprocessors.

Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.

Security foundation15% of the score85
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedPerplexity AIretrieved Aug 24, 2026
Bug Bounty and Vulnerability Disclosure Program We are committed to building strong partnerships with the security research community. In addition to conducting annual third-party penetration tests, we actively collaborate with researchers through our private Bug Bounty program on BugCrowd and our public Vulnerability Disclosure Program (VDP)
Vendor publishedPerplexity AIretrieved Aug 24, 2026
and analysis of endpoint activity, advanced threat detection using behavioral analysis and machine learning, and rapid incident response capabilities. It also enables remote forensics to investigate and contain potential security incidents.

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the score85
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Partial
Evidence — Independent assurance
Vendor publishedPerplexity AIretrieved Aug 24, 2026
Bug Bounty and Vulnerability Disclosure Program We are committed to building strong partnerships with the security research community. In addition to conducting annual third-party penetration tests, we actively collaborate with researchers through our private Bug Bounty program on BugCrowd and our public Vulnerability Disclosure Program (VDP)

Read from the registry record above — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Capped at 85: none of the corroborated certifications is AI-specific — this is security attestation, not AI-management-system assurance.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedPerplexity Privacy Noticeretrieved Aug 24, 2026
transfer, storage, and processing of your data in a country other than your country of residence including, but not limited to, the United States.
Vendor publishedPerplexity Terms of Serviceretrieved Aug 24, 2026
we do not sell your personal data or send your queries, prompts, or conversation content to advertisers.

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+6Publish Model provider transparency evidenceModel 060
+3Publish Change management evidenceAI System 2747
+3Complete the Governance & accountability disclosureOrganisation 4060
+3Publish independently corroborated ISO/IEC 42001 (AI management system) certificationIndependent Assurance 85100
+2Have Customer data treatment disclosures independently corroboratedData 7287

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 54 → up to 80 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONINFRASTRUCTUREPerplexityPerplexityAmazon Web ServicesAmazon Web ServicesCloudflareCloudflare
View as list
Perplexity Uses Infrastructure Amazon Web Services
Perplexity Uses Infrastructure Cloudflare

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 5 — registry checks and verification ladders, click to view
ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

SOC 2 Type 2Claimed & corroborated

SOC 2 Type 2 by Insight Assurance (Tampa, Florida), report dated 31 Mar 2026, unqualified; system: Perplexity's Text Generation and Information Retrieval Platform; period 1 Mar 2025 - 28 Feb 2026, so current. Type 2 covers both suitability of design AND operating effectiveness. IMPORTANT LIMITATION: the criteria in scope are SECURITY, AVAILABILITY AND CONFIDENTIALITY ONLY - privacy is NOT among them, nor is processing integrity. A buyer asking about privacy commitments gets no assurance from this report, and it is not equivalent to a SOC 2 that includes the privacy criterion. Report held in the TrustyCyber vault.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 2 Type 2 report held in the TrustyCyber vault (supplied by Perplexity), Aug 24, 2026: Verified on the registry

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry

ISO/IEC 27001Claimed & corroborated

ISO/IEC 27001:2022, Insight Assurance (MSCB-306), certificate IS-IA-2026-07-29-01, issued 29 Jul 2026, expires 28 Jul 2029, next surveillance 28 Jul 2027; statement of applicability v1.0 dated 24 Dec 2025. SCOPE COVERS CONSUMER AND ENTERPRISE ALIKE: the management system supporting Perplexity Free, Pro and Max, Enterprise Pro and Enterprise Max, the Sonar API, Search API and API Platform, Computer and Comet. Functional areas: Security, Engineering, Infrastructure, Legal, HR, GRC and Product development. Broader than OpenAI's 27001, whose scope names the business offerings only. Certificate held in the TrustyCyber vault.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Jul 28, 2029

Checked against ISO/IEC 27001:2022 certificate held in the TrustyCyber vault (supplied by Perplexity), Aug 24, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry

Sources 18 — click to view
Metal AI - Perplexity API Platform
AI Documentation · Vendor · retrieved Aug 24, 2026
Perplexity Legal Hub
Trust Or Security Page · Vendor · retrieved Aug 24, 2026
Perplexity AI
Trust Or Security Page · Vendor · retrieved Aug 24, 2026
https://perplexity.ai/.well-known/security.txt
Trust Or Security Page · Vendor · retrieved Aug 24, 2026
Perplexity Privacy Notice
Privacy Notice · Vendor · retrieved Aug 24, 2026
Perplexity Terms of Service
Terms · Vendor · retrieved Aug 24, 2026
Perplexity Data Processing Addendum
DPA · Vendor · retrieved Aug 24, 2026
Subprocessors — Perplexity AI Trust Center
Subprocessor List · Vendor · retrieved Aug 24, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
ISO/IEC 27001:2022 certificate held in the TrustyCyber vault (supplied by Perplexity) record — ISO/IEC 27001
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
SOC 2 Type 2 report held in the TrustyCyber vault (supplied by Perplexity) record — SOC 2 Type 2
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Aug 28, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Perplexity at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.