generated: '2026-08-02' method: searched probe: true source: https://www.salsify.com/security-and-reliability url: https://www.salsify.com/security-and-reliability name: Salsify Security and Reliability certifications: - SOC 2 Type II - ISO 27001:2013 frameworks: - NIST 800 - OWASP regulatory: - GDPR - CCPA practices: encryption_in_transit: TLS 1.2 minimum encryption_at_rest: 256-bit AES certificate_keys: 2048-bit with SHA-256 penetration_testing: Third-party network, application vulnerability and penetration testing at least annually sso: SAML 2.0 (Okta, OneLogin, AD FS, Google) mfa: required tenancy: Multi-tenant with application-level data separation per customer contacts: security: security@salsify.com vulnerability_disclosure: vdp@salsify.com scope: - ProductXM - SupplierXM reports: soc2: self_serve: false note: SOC 2 Type II report available on request through a Salsify sales or customer success contact. iso27001: self_serve: true note: ISO 27001 certificate downloadable from the security and reliability page. dedicated_trust_domain: false evidence: - source: https://www.salsify.com/security-and-reliability keywords: - SOC 2 Type II - ISO 27001:2013 - GDPR - CCPA - NIST 800 - OWASP - source: https://www.salsify.com/press-release-security-certifications-soc2-type2-iso27001 keywords: - SOC 2 Type 2 - ISO 27001 note: >- trust.salsify.com does not resolve and /trust-center and /security both return 404; Salsify's compliance posture is published on the marketing-site security page above rather than in a dedicated trust portal.