generated: '2026-08-02' method: searched probe: true source: >- https://threatlocker.kb.help/threatlocker-security-and-privacy/, https://threatlocker.kb.help/compliance/, https://www.threatlocker.com/software-security-audit url: https://threatlocker.kb.help/threatlocker-security-and-privacy/ dedicated_trust_center: false note: >- ThreatLocker publishes no trust.threatlocker.com or /trust page — trust.threatlocker.com does not resolve and www.threatlocker.com/security and /compliance both 404. Its security and compliance posture is published inside the Help Center instead. The automated probe (0-working/probe-security-programs.py) therefore returned trust=none; this file records the posture found by manual search of the pages ThreatLocker actually publishes. certifications: - {name: SOC 2 Type II, status: certified, detail: 'Security controls audited at least annually by an independent AICPA-certified auditor; the SOC 2 Type II report is available to customers on request under NDA'} - {name: ISO 27001, status: in-progress, detail: 'Stated in progress as of March 2026; ThreatLocker states ISO 27001/2 compliance in its security documentation'} - {name: FedRAMP, status: instance-published, detail: 'A dedicated "Portal [Instance FedRAMP]" component is published on the public status page'} practices: encryption: All confidential information, including data transmitted to and from the ThreatLocker agent, is encrypted in transit and at rest using industry-standard encryption protocols. penetration_testing: ThreatLocker undergoes regular internal and external penetration tests. data_residency: Regionally isolated instances (AE1, AU1, CA1, EU1, SA1 and lettered US/global instances) with per-instance portal and API hosts. vulnerability_disclosure: found: false policy: null contact: null bug_bounty: null note: >- NO vulnerability disclosure program, responsible-disclosure policy, published security contact, or bug bounty was found — notable for a security vendor. /.well-known/security.txt returns 404 on every ThreatLocker host, and /security, /responsible-disclosure and /vulnerability-disclosure all 404 on www.threatlocker.com. No HackerOne, Bugcrowd or Intigriti program was found. No `Security` or `VulnerabilityDisclosure` pointer is wired in apis.yml because nothing is published; this is a verified absence, not an untested one. probes: - {url: 'https://www.threatlocker.com/.well-known/security.txt', http_status: 404} - {url: 'https://www.threatlocker.com/security.txt', http_status: 404} - {url: 'https://portalapi.threatlocker.com/.well-known/security.txt', http_status: 404} - {url: 'https://threatlocker.kb.help/.well-known/security.txt', http_status: 404} - {url: 'https://www.threatlocker.com/responsible-disclosure', http_status: 404} - {url: 'https://www.threatlocker.com/vulnerability-disclosure', http_status: 404} frameworks_page: https://threatlocker.kb.help/compliance/ audit_report_page: https://www.threatlocker.com/software-security-audit evidence: - {source: 'https://threatlocker.kb.help/threatlocker-security-and-privacy/', http_status: 200, keywords: [soc 2 type ii, iso 27001, encryption, penetration test, cmmc level 2, hipaa]} - {source: 'https://threatlocker.kb.help/compliance/', http_status: 200, keywords: [nist, cmmc, pci-dss, iso 27001 annex a, hipaa security rule, cis controls]} - {source: 'https://www.threatlocker.com/software-security-audit', http_status: 200} - {source: 'https://trust.threatlocker.com/', http_status: 0, result: does-not-resolve} - {source: 'https://www.threatlocker.com/security', http_status: 404} - {source: 'https://www.threatlocker.com/compliance', http_status: 404}