SOC 2 Type II · ISO 27001 · 1,400 security teams
SOC 2 Type II · ISO 27001 · 1,400 security teams
Palisade
Palisade
Risk score82/100open
Next page/
Home
Trust centre
How we keep your data safe.
The reports, the subprocessors and the practices, on one page. Ask for any document and we send it the same day.
SOC 2 Type II · ISO 27001 · 1,400 security teams
- 1Stale admin accountLeft the company 212 days ago and is still a global adminHigh
- 2Leaked API keyFound in a public repository six hours agoCritical
- 3Contractor · MFA offSigns in to production with a password onlyHigh
- 4Laptop · 41 days unpatchedThree critical fixes are waiting to installMedium
Trust centre
How we keep your data safe.
The reports, the subprocessors and the practices, on one page. Ask for any document and we send it the same day.
SOC 2 Type II · ISO 27001 · 1,400 security teams
- 1Stale admin accountLeft the company 212 days ago and is still a global adminHigh
- 2Leaked API keyFound in a public repository six hours agoCritical
- 3Contractor · MFA offSigns in to production with a password onlyHigh
- 4Laptop · 41 days unpatchedThree critical fixes are waiting to installMedium
Trust centre
How we keep your data safe.
The reports, the subprocessors and the practices, on one page. Ask for any document and we send it the same day.
SOC 2 Type II · ISO 27001 · 1,400 security teams
- 1Stale admin accountLeft the company 212 days ago and is still a global adminHigh
- 2Leaked API keyFound in a public repository six hours agoCritical
- 3Contractor · MFA offSigns in to production with a password onlyHigh
Reports
Proof you can read.
We ask customers for evidence, so we publish ours. Every report below is available to customers and to prospects under NDA.
0 / 6 reports current
Current
SOC 2 Type II
Audited every year by an independent firm. Covers security, availability and confidentiality.
RequestCertified
ISO 27001
The certificate covers the platform, the company and the people who run it.
RequestTwice a year
Penetration test
Independent testers attack the platform. The summary letter is yours on request.
Request
Sample reports, vendors and regions — demo data. Replace them with your own before you publish.
How we protect your data
- 01
Read-only by default
Every source connects with a read-only role. A fix that changes something uses a separate permission you grant per action.
- 02
Findings, never content
We store what is exposed and where. We do not store the content of your files, mail or messages.
- 03
Encrypted everywhere
TLS 1.3 in transit and AES-256 at rest, with keys held in a managed key service and rotated on a schedule.
- 04
Access by named people
Staff access to production needs SSO, a hardware key and a ticket. Every session is logged and reviewed.
- 05
Tested before it ships
Every change is reviewed by a second engineer and scanned for secrets and known flaws before it is merged.
- 06
A plan for the bad day
Incidents follow a written plan. If your data is affected you hear from us within 72 hours, with what we know.
Where it lives
You pick the region at sign-up and it does not change unless you ask. Enterprise plans can run in a private region.
- European UnionFrankfurt and DublinData never leaves the EU
- United KingdomLondonFor UK public sector and finance
- United StatesVirginia and OregonThe default for US accounts
Who else touches it
The vendors that process customer data on our behalf. We tell customers 30 days before a new one is added.
Scroll sideways to read
| Vendor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting, storage and key management | EU, UK, US |
| Cloudflare | Network edge and protection from floods of traffic | Global |
| Postmark | Sending alert and account emails | US |
| Stripe | Card payments and invoices | US, EU |
| Sentry | Error reports from the app, without customer data | EU |
Last updated 1 October 2026
Need the full report?
Tell us which document you need and who should receive it. Reports are shared under NDA, usually the same working day.
Reports
Proof you can read.
We ask customers for evidence, so we publish ours. Every report below is available to customers and to prospects under NDA.
0 / 6 reports current
Current
SOC 2 Type II
Audited every year by an independent firm. Covers security, availability and confidentiality.
RequestCertified
ISO 27001
The certificate covers the platform, the company and the people who run it.
RequestTwice a year
Penetration test
Independent testers attack the platform. The summary letter is yours on request.
Request
Sample reports, vendors and regions — demo data. Replace them with your own before you publish.
How we protect your data
- 01
Read-only by default
Every source connects with a read-only role. A fix that changes something uses a separate permission you grant per action.
- 02
Findings, never content
We store what is exposed and where. We do not store the content of your files, mail or messages.
- 03
Encrypted everywhere
TLS 1.3 in transit and AES-256 at rest, with keys held in a managed key service and rotated on a schedule.
- 04
Access by named people
Staff access to production needs SSO, a hardware key and a ticket. Every session is logged and reviewed.
- 05
Tested before it ships
Every change is reviewed by a second engineer and scanned for secrets and known flaws before it is merged.
- 06
A plan for the bad day
Incidents follow a written plan. If your data is affected you hear from us within 72 hours, with what we know.
Where it lives
You pick the region at sign-up and it does not change unless you ask. Enterprise plans can run in a private region.
- European UnionFrankfurt and DublinData never leaves the EU
- United KingdomLondonFor UK public sector and finance
- United StatesVirginia and OregonThe default for US accounts
Who else touches it
The vendors that process customer data on our behalf. We tell customers 30 days before a new one is added.
Scroll sideways to read
| Vendor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting, storage and key management | EU, UK, US |
| Cloudflare | Network edge and protection from floods of traffic | Global |
| Postmark | Sending alert and account emails | US |
| Stripe | Card payments and invoices | US, EU |
| Sentry | Error reports from the app, without customer data | EU |
Last updated 1 October 2026
Need the full report?
Tell us which document you need and who should receive it. Reports are shared under NDA, usually the same working day.
Reports
Proof you can read.
We ask customers for evidence, so we publish ours. Every report below is available to customers and to prospects under NDA.
0 / 6 reports current
Current
SOC 2 Type II
Audited every year by an independent firm. Covers security, availability and confidentiality.
RequestCertified
ISO 27001
The certificate covers the platform, the company and the people who run it.
RequestTwice a year
Penetration test
Independent testers attack the platform. The summary letter is yours on request.
Request
Sample reports, vendors and regions — demo data. Replace them with your own before you publish.
How we protect your data
- 01
Read-only by default
Every source connects with a read-only role. A fix that changes something uses a separate permission you grant per action.
- 02
Findings, never content
We store what is exposed and where. We do not store the content of your files, mail or messages.
- 03
Encrypted everywhere
TLS 1.3 in transit and AES-256 at rest, with keys held in a managed key service and rotated on a schedule.
- 04
Access by named people
Staff access to production needs SSO, a hardware key and a ticket. Every session is logged and reviewed.
- 05
Tested before it ships
Every change is reviewed by a second engineer and scanned for secrets and known flaws before it is merged.
- 06
A plan for the bad day
Incidents follow a written plan. If your data is affected you hear from us within 72 hours, with what we know.
Where it lives
You pick the region at sign-up and it does not change unless you ask. Enterprise plans can run in a private region.
- European UnionFrankfurt and DublinData never leaves the EU
- United KingdomLondonFor UK public sector and finance
- United StatesVirginia and OregonThe default for US accounts
Who else touches it
The vendors that process customer data on our behalf. We tell customers 30 days before a new one is added.
Scroll sideways to read
| Vendor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting, storage and key management | EU, UK, US |
| Cloudflare | Network edge and protection from floods of traffic | Global |
| Postmark | Sending alert and account emails | US |
| Stripe | Card payments and invoices | US, EU |
| Sentry | Error reports from the app, without customer data | EU |
Last updated 1 October 2026
Need the full report?
Tell us which document you need and who should receive it. Reports are shared under NDA, usually the same working day.
Questions
Asked before every rollout.
What security and IT teams want to know before they connect the first source.
Connect your identity provider and most teams see their first findings in under an hour. Cloud accounts and device managers each add a few minutes. Nothing is installed on a server to get started.
Read-only access to every source. Fixes that change something, such as revoking a key or disabling an account, use a separate write permission that you grant per action and can remove at any time.
No. Palisade finds what is exposed before an attack and reads from the tools you already run. It sends findings to your SIEM and takes alerts from it, so the two work as one queue.
Each open finding carries a weight from its severity and from what it can reach. The score is the weighted share of your surface that is exposed, from 0 to 100. Closing a critical finding moves it more than closing ten low ones.
In the region you pick at sign-up: the EU, the UK or the US. Enterprise plans can use a private region. Data is encrypted in transit and at rest, and we keep findings, never the content of your files or mail.
Yes. Every finding has an owner taken from your directory or device manager. They get a message in Slack or email with the exact step, and the finding closes itself when the fix lands.
SOC 2, ISO 27001, GDPR and HIPAA out of the box, with each control mapped to live checks. You can add your own controls and map them to the same evidence.
One person in your directory. Service accounts, devices and cloud resources are not counted, however many you have. Yearly billing takes two months off the price.
Questions
Asked before every rollout.
What security and IT teams want to know before they connect the first source.
Connect your identity provider and most teams see their first findings in under an hour. Cloud accounts and device managers each add a few minutes. Nothing is installed on a server to get started.
Read-only access to every source. Fixes that change something, such as revoking a key or disabling an account, use a separate write permission that you grant per action and can remove at any time.
No. Palisade finds what is exposed before an attack and reads from the tools you already run. It sends findings to your SIEM and takes alerts from it, so the two work as one queue.
Each open finding carries a weight from its severity and from what it can reach. The score is the weighted share of your surface that is exposed, from 0 to 100. Closing a critical finding moves it more than closing ten low ones.
In the region you pick at sign-up: the EU, the UK or the US. Enterprise plans can use a private region. Data is encrypted in transit and at rest, and we keep findings, never the content of your files or mail.
Yes. Every finding has an owner taken from your directory or device manager. They get a message in Slack or email with the exact step, and the finding closes itself when the fix lands.
SOC 2, ISO 27001, GDPR and HIPAA out of the box, with each control mapped to live checks. You can add your own controls and map them to the same evidence.
One person in your directory. Service accounts, devices and cloud resources are not counted, however many you have. Yearly billing takes two months off the price.
Questions
Asked before every rollout.
What security and IT teams want to know before they connect the first source.
Connect your identity provider and most teams see their first findings in under an hour. Cloud accounts and device managers each add a few minutes. Nothing is installed on a server to get started.
Read-only access to every source. Fixes that change something, such as revoking a key or disabling an account, use a separate write permission that you grant per action and can remove at any time.
No. Palisade finds what is exposed before an attack and reads from the tools you already run. It sends findings to your SIEM and takes alerts from it, so the two work as one queue.
Each open finding carries a weight from its severity and from what it can reach. The score is the weighted share of your surface that is exposed, from 0 to 100. Closing a critical finding moves it more than closing ten low ones.
In the region you pick at sign-up: the EU, the UK or the US. Enterprise plans can use a private region. Data is encrypted in transit and at rest, and we keep findings, never the content of your files or mail.
Yes. Every finding has an owner taken from your directory or device manager. They get a message in Slack or email with the exact step, and the finding closes itself when the fix lands.
SOC 2, ISO 27001, GDPR and HIPAA out of the box, with each control mapped to live checks. You can add your own controls and map them to the same evidence.
One person in your directory. Service accounts, devices and cloud resources are not counted, however many you have. Yearly billing takes two months off the price.
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected