generated: '2026-08-29' method: searched source: https://www.blueprism.com/blue-prism-security/ provider: Blue Prism providerId: blue-prism trust_center: published: true url: https://www.blueprism.com/blue-prism-security/ http_status: 200 probed: '2026-08-29' name: Blue Prism Security type: security program page (not a hosted trust portal — no Vanta/Drata/SafeBase surface, no document request flow) certifications: - name: ISO/IEC 27001 status: certified certificate_url: https://files.blueprism.com/downloads/public/data-sheets/2.1-ISO-27001-SSC-Blue-Prism-Certificate-2026.pdf issuer: BSI note: >- Certificate PDF is served openly from files.blueprism.com — no gate. The page body renders the standard number as "ISO270001", which is a typo for ISO 27001. - name: Cyber Essentials status: certified certificate_url: https://files.blueprism.com/downloads/public/data-sheets/6.1-Cyber-Essentials-Certificate-2026.pdf note: UK NCSC scheme. Certificate PDF served openly. frameworks: - NIST Risk Management Framework (cloud operations controls) - OWASP (secure development training) - PCI (secure development training alignment only — no PCI DSS certification claimed) program_elements: - Company-level security policies built on ISO 27001 and Cyber Essentials guidance - Secure Code Warrior developer certification required before production access - Static application security testing (SAST) in the development process - Third-party vulnerability identification and management partners - Continuous scanning by a dedicated Cloud Operations Security team other_public_documents: - name: Modern Slavery Statement FY2021 url: https://files.blueprism.com/uploads/resources/Blue_Prism-Modern-Slavery-Statement-FY2021-SIGNED.pdf gaps: - No SOC 2 report or attestation is referenced. - No subprocessor list, no data-residency matrix, no pen-test summary is published. - No machine-readable trust surface of any kind. maintainers: - FN: Kin Lane email: kin@apievangelist.com