generated: '2026-08-02'
method: searched
probe: true
probe_result: >-
probe-security-programs.py returned trust=none — trust.picarro.com is a Vanta-hosted
single-page app whose certification list renders client-side, so the keyword check on the
raw body found nothing. The trust center is real: the served HTML identifies itself as a
Vanta trust report (assets.vanta.com), carries
Picarro Trust Center and a
meta description written by Picarro. Certifications below are taken from Picarro's own
compliance page and press release, not from the trust center body.
url: https://trust.picarro.com/
platform: Vanta Trust Center
certifications:
- id: iso-27001-2022
name: ISO/IEC 27001:2022
scope: Information Security Management Systems (ISMS)
auditor: A-LIGN
announced: '2025-11-13'
- id: iso-27017
name: ISO/IEC 27017
scope: Cloud security
auditor: A-LIGN
announced: '2025-11-13'
- id: iso-27018
name: ISO/IEC 27018
scope: Protection of personally identifiable information in public clouds
auditor: A-LIGN
announced: '2025-11-13'
- id: soc-2-type-2
name: SOC 2 Type 2
scope: 'Trust Services Criteria — security, availability, processing integrity, confidentiality, privacy'
auditor: A-LIGN
announced: '2025-11-13'
- id: iso-9001-2015
name: ISO 9001:2015
scope: Quality management system
page: https://www.picarro.com/picarros_iso_90012015_certification
document_access: >-
Sensitive documents in the trust center are gated — "click the lock icon next to the
document and provide the requested information" (Picarro's own trust center description).
compliance_page: https://www.picarro.com/ensuring_data_security_and_compliance
privacy:
- {name: Privacy Policy (EU & US), url: 'https://www.picarro.com/privacy_policy'}
- {name: Privacy Policy (California Residents), url: 'https://www.picarro.com/environmental/picarro_privacy_policy_california_residents'}
- {name: Terms of Service, url: 'https://www.picarro.com/terms_of_service'}
vulnerability_disclosure:
found: false
probed:
- {url: 'https://www.picarro.com/.well-known/security.txt', status: 404}
- {url: 'https://www.picarro.com/security', status: 404}
- {url: 'https://www.picarro.com/responsible-disclosure', status: 404}
- {url: 'https://www.picarro.com/vulnerability-disclosure', status: 404}
- {url: 'https://www.picarro.com/security/responsible-disclosure', status: 404}
note: >-
No RFC 9116 security.txt, no published responsible-disclosure policy, no bug bounty on
HackerOne / Bugcrowd / Intigriti, and no security@ address found. No `Security` or
`VulnerabilityDisclosure` pointer is emitted — there is nothing to point at. This is a
real, reportable gap for a company that just completed SOC 2 Type 2 and ISO 27001.
evidence:
- {source: 'https://trust.picarro.com/', kind: trust-center, http_status: 200, detail: 'Vanta trust report SPA; title and meta description authored by Picarro'}
- {source: 'https://www.picarro.com/ensuring_data_security_and_compliance', kind: compliance-page, detail: 'names ISO/IEC 27001:2022, ISO 27017, ISO 27018, SOC 2 Type 2'}
- {source: 'https://www.picarro.com/gas/company/press-releases/2025/picarro_achieves_isoiec_270012022_27017_and_27018_certifications', kind: press-release, detail: 'A-LIGN as auditor; November 2025'}
x-evidence:
fetched: '2026-08-02'