ModelCharter

Is Perplexity SOC 2 compliant?

Yes

Perplexity AI, Inc. · Search

Yes. Perplexity AI, Inc. holds a SOC 2 report covering Perplexity, which gives independent assurance over its security controls.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

SOC 2 report
Confirmed
Perplexity AI, Inc. reports a SOC 2 attestation. Request the current report and relevant bridge letter during procurement.
ISO 27001
Not verified
No ISO/IEC 27001 certification was confirmed in the sources reviewed for this profile.
Default data training
Opt-out required
On consumer/free/Pro accounts an 'AI data retention' setting is on by default and can be used to improve models; logged-in users can opt out in Settings > Account, but logged-out users cannot.
Business-tier training
No by default
Perplexity Enterprise Pro and the Sonar API operate under Zero Data Retention and state customer/enterprise data is never used to train models.
Practical risk: On consumer plans data is used to improve models unless you turn off the default-on 'AI data retention' toggle, and reporting alleges Perplexity shared conversational data with ad/tracking platforms (incl. in Incognito).

How to make a decision

Check the precise account tier, written contract and intended data before approving Perplexity. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Perplexity

See the full Perplexity risk profile, with every data-handling fact and its source, or browse all rated AI tools.