Annual SOC 2 Type II Examination in Progress
PKWARE Logo

PKWARE Trust Center

background-image
Start your security review
View & download sensitive information
Ask for information
ControlK

  • Fiserv
  • JPMorgan Chase & Co.
  • Truist
  • Western Union

As a provider of sensitive data discovery and remediation tools, PKWARE’s priority is to maintain a safe, secure, and compliant environment for hosted applications it provides to customers as well as providing secure development, professional, and support engineering services. To ensure the highest level of security and compliance, PKWARE is continually investing in our overall information security program, resources, and expertise.

We understand the importance of providing clear information about our security practices, tools, resources and responsibilities within PKWARE so that our customers can feel confident in choosing us as a trusted service provider.

Within this portal, we provide various information about our compliance controls, policies, practices, and evidence for your varying risk assessment and assurance activities. PKWARE is committed to transparent and open communication in order to provide you with the ability to make accurate decisions when it comes to your own data security.

Training

We provide recurring security awareness training to all employees to ensure that they are aware of security best practices. This training includes regular phishing tests, rotating cyber security topics, and secure application development training including OWASP Top 10.

PKWARE Trust Center Updates

PKWARE Achieves SOC 2 Type II Certification

Compliance

We’re proud to announce that PKWARE has successfully achieved SOC 2 Type II certification, demonstrating our ongoing commitment to the highest standards of security, availability, and confidentiality in the protection of customer data.

This independent audit, conducted by a third-party firm, validates that our policies, controls, and operational practices are designed and operating effectively over time to safeguard sensitive information. The audit covered critical aspects of our SaaS infrastructure, internal security processes, and organizational controls to ensure continuous compliance with the AICPA Trust Services Criteria.


What This Means for Our Customers

  • Verified Security and Compliance: Independent validation that PKWARE’s security controls are robust and effective.
  • Ongoing Commitment: SOC 2 Type II certification evaluates control effectiveness over an extended period, reflecting our dedication to maintaining strong operational discipline.
  • Customer Confidence: Our customers can trust that their data is managed with the highest level of security and integrity.

Looking Ahead

Security and compliance are foundational to our mission. We will continue to invest in process improvements, transparency, and regular third-party audits to ensure that PKWARE remains a trusted partner for sensitive data discovery, protection, and compliance.

For more details or to request a copy of our latest SOC 2 Type II report, please visit our [Trust Center]

Annual SOC 2 Type II Examination in Progress

Compliance

PKWARE has moved from its initial three-month SOC 2 Type II examination to an annual twelve-month examination with our independent auditor, Sensiba.

  • Examination period: September 1, 2025 to August 31, 2026, continuing directly from the end of the prior period
  • Criteria: Security, Availability, and Confidentiality
  • Report expected: mid-December 2026

Until the new report is issued, the auditor's engagement letter and our October 2026 management bridge letter are available in the Trust Center alongside the most recent SOC 2 Type II report.

Third-Party Penetration Test Scheduled for Q1 2027

General

PKWARE has scheduled an independent third-party penetration test of the PK Protect platform for Q1 2027. A summary of the results will be made available in the Trust Center once the test is complete.

Information Security Policies Reviewed and Updated

Compliance

PKWARE completed a full review of its information security policies and plans in March and April 2026. Each policy, along with our Incident Response, Business Continuity, and Disaster Recovery plans, was reissued as version 2.0, and a new Change Management Policy was added.

The current versions are available in the Trust Center.

Security Update: No Impact from Salesloft Drift Salesforce Vulnerability

Vulnerabilities

We are aware of the Salesloft-Drift Salesforce integration vulnerability and related data breaches that took place. PKWARE does not use the Salesloft Drift integration. At no time was our Salesforce data exposed through this tool.

For further information see the vendor's published disclosure:
https://trust.salesloft.com/?uid=Drift%2FSalesforce+Security+Update

Knowledge Base (FAQ)
  • How does PKWARE secure and manage the exchange of troubleshooting and debug files with customers?
  • Does PKWARE host or have access to my sensitive data?
View more

Documents

REPORTS - PK PROTECT ENDPOINT MANAGERData Flow Diagram (DFD)
If you need help using this PKWARE Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue