Security FAQ
Picus holds ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 22301, and ISO/IEC 20000-1 certificates and SOC 2 Type 2 Report.
Picus undergoes regular surveillance and recertification audits to ensure the continuous effectiveness of its Information Security, Privacy, Business Continuity, and Service Management controls.
You can submit your request from here.
Please note that our SOC 2 Type 2 Report is only shared under a signed Non-Disclosure Agreement (NDA).
Yes. Picus has a documented, approved, and communicated Information Security Policy. In line with its ISO/IEC 27001 and ISO/IEC 27701 certifications, Picus operates a Privacy and Information Security Management System aligned with international standards.
The policy is approved by Senior Management, communicated to all employees and relevant external parties.
Yes, but only to a limited extent and for clearly defined purposes related to user account management, service provision, and service communications.
Personal data processed by Picus are as follows:
Identity information: Full name
Contact information: Email address, country
Employment information: Company name, job title
Online/technical identifiers: IP address, login credentials, login time, device and browser information, and cookie data.
In the Picus Platform, technical data is processed solely for security monitoring, trend analysis, service improvement, and customer experience optimization.
For the personal data collected by the use of our Website and other services, please refer to our Privacy Policy and Cookie Policy.
Picus protects personal data through a comprehensive set of technical and organizational security measures designed to ensure confidentiality, integrity, availability, and privacy.
Security and privacy are embedded into Picus’s processes by design and by default. Picus is ISO/IEC 27701 certified and operates a Privacy Information Management System (PIMS) aligned with internationally recognized standards..
Personal data processed by Picus is limited to what is necessary for user account management, service provision, and service-related communications. This may include identity and contact information, employment-related details, and technical or online identifiers such as IP address, login timestamps, device and browser information, and cookie data. Technical data is used solely for security monitoring, trend analysis, service improvement, and customer experience optimization.
Key security controls include strong authentication and role-based access control (RBAC) with least-privilege enforcement, encryption of data both at rest and in transit using industry-standard cryptography, continuous logging and monitoring, data loss prevention (DLP) measures, web application firewalls, and protections against malicious activity. Customer data is logically isolated in production environments, and access to systems and data is strictly restricted to authorized personnel and reviewed periodically.
For additional details about our corporate security practices in detail, please click here.
Picus products are hosted on Amazon Web Services (AWS), and all data stored at rest is encrypted using the industry-standard AES-256 algorithm.
By default, customer data is hosted in AWS US region. Where required, customers may also choose deployment in alternative AWS regions offered by Picus, including the EU, Middle East, or India, to meet specific legal or business requirements.
Picus retains personal data only for as long as necessary to provide its services, fulfill legitimate business purposes, or comply with applicable legal and regulatory requirements.
When personal data is no longer required, it is securely deleted, aggregated or de-identified in accordance with Picus’s data retention and disposal procedures and applicable legal requirements.
To submit a DSAR request, please click here.
Yes. Customer data is encrypted at rest using industry-standard AES-256 encryption. Data in transit is protected using secure TLS 1.2 or higher with strong cryptographic algorithms and secure cipher suites, ensuring confidentiality and integrity during transmission.
Yes. Picus applies Zero Trust principles across its cloud environment, supported by identity-centric controls, least privilege access, continuous authentication, and ZTNA implemented through a dedicated security tool.
Yes. Picus uses a limited number of vetted sub-processors and cloud service providers to support its infrastructure and business operations, such as hosting and related services.
Picus does not outsource its core product development, security management, or administrative control of its services.
All sub-processors are engaged under appropriate contractual safeguards, including Data Processing Agreements (DPAs), confidentiality obligations, and Standard Contractual Clauses (SCCs).
A current list of sub-processors is available here.
Yes. Picus operates a third-party risk management (TPRM) program and conducts regular risk assessments for vendors that provide critical services, both prior to onboarding and periodically thereafter.
Third parties are continuously monitored through reviews of standardized assessment reports, security certifications, and other appropriate assurance measures. No third party vendors are granted system administration-level privileges to Picus services.
In the event of a security incident affecting customer resources or personal data, Picus will notify impacted customers without undue delay and in accordance with applicable legal and regulatory requirements.
Notifications are provided through established communication channels and include relevant details such as the nature of the incident, affected resources or data, mitigation actions taken by Picus, and any recommended customer actions. Picus coordinates incident response activities through its internal security, legal, and customer-facing teams to ensure timely and transparent communication.
If you believe you have discovered a vulnerability, please reach out to us by filling out the report. Click here to report a vulnerability.
For your questions, comments, or feedback related to security, privacy, and compliance, please contact us at security@picussecurity.com.