TRUST CENTER
At Picus Security, we enable security teams to continuously validate and enhance organizations’ cyber resilience. The Picus Trust Center helps you discover all about our company’s corporate policies and practices, legal information and materials that explain how we comply with privacy and security fundamentals.
Vulnerability Disclosure Program
Welcome to the PICUS Vulnerability Disclosure Program! This program provides detailed information about the systems and research areas covered, along with instructions on how to submit vulnerability reports. We kindly request to adhere to a waiting period before publicly disclosing any vulnerabilities you might have found. If you believe you have discovered a vulnerability, please reach out to us by filling out the report below
What is The Picus Trust Center?
The Picus Trust Center is a centralized resource, which is created to inform you about our corporate policies and practices, legal information and materials that explain how Picus Security complies with security and privacy fundamentals.
Which standards, regulations and best practices does Picus compliant with?
Picus holds ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 22301, and ISO/IEC 20000-1 certificates and SOC 2 Type 2 report.
Does Picus conduct third-party risk assessments?
Yes, Picus conducts third party risk assessments on a regular basis and continuously monitors the third party vendors which provide critical services to the business. It should also be noted that no third party vendors have system administration level privileges to Picus services.
Does Picus have a documented, approved, and communicated information security policy?
Yes, Picus has a documented, approved, and communicated Information Security Policy. As part of our ISO/IEC 27001 and ISO/IEC 27701 certifications, we operate within a Privacy and Information Security Management System that adheres to these international standards. The Information Security Policy is approved by our Senior Management and is communicated to all employees and relevant external parties.