Is Perplexity SOC 2 compliant?
YesPerplexity AI, Inc. · Search
Yes. Perplexity AI, Inc. holds a SOC 2 report covering Perplexity, which gives independent assurance over its security controls.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- SOC 2 report
- Confirmed
- Perplexity AI, Inc. reports a SOC 2 attestation. Request the current report and relevant bridge letter during procurement.
- ISO 27001
- Not verified
- No ISO/IEC 27001 certification was confirmed in the sources reviewed for this profile.
- Default data training
- Opt-out required
- On consumer/free/Pro accounts an 'AI data retention' setting is on by default and can be used to improve models; logged-in users can opt out in Settings > Account, but logged-out users cannot.
- Business-tier training
- No by default
- Perplexity Enterprise Pro and the Sonar API operate under Zero Data Retention and state customer/enterprise data is never used to train models.
Practical risk: On consumer plans data is used to improve models unless you turn off the default-on 'AI data retention' toggle, and reporting alleges Perplexity shared conversational data with ad/tracking platforms (incl. in Incognito).
How to make a decision
Check the precise account tier, written contract and intended data before approving Perplexity. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Perplexity
Is Perplexity HIPAA compliant?Is Perplexity GDPR compliant?Is Perplexity ISO 27001 certified?Does Perplexity train on your data?
See the full Perplexity risk profile, with every data-handling fact and its source, or browse all rated AI tools.