Third Party Index

Snapshot 21398

Document
Trust center
URL
https://trust.coalfire.com/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
350983 bytes
SHA-256 (raw)
c32f6c4805d3b546c4e29cfc8dee0a781636282e079e23ccbf6691505d134270
SHA-256 (normalized text)
7c00fd6df6f3f975fab8f1ae12bc3abf5824489ca10184b4d6a22920ffee0229

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Coalfire
Search the Trust Center...
Ctrl +K
Quick links
Website URL
Quick links
Website URL
Badges
ISO 9001
ISO 27701
GDPR
CCPA
Our Philosophy
As a cybersecurity company, we work hard to improve the cybersecurity of our clients. But, we must also lead by example, and we are not immune to cybersecurity threats. Coalfire takes the security of our organization and customer data with the utmost priority and has built a strong information security program to see that our mission is safeguarded against these threats.
Coming Soon
The Coalfire Cybersecurity team and DivHex is finalizing certification to the CyberEssentials Plus standards.
Quick Summary
One or more annual third-party audit(s)
Has a formal mobile device management (MDM) program
Annual third-party penetration testing
Has a disaster recovery plan
Has cyber insurance
Will enter into a DPA
Deletes customer data on request
Has an API available
Uses a centralized IAM solution (SSO) to manage employee access
Has a privacy policy
Documents & Knowledge Base FAQs
Announcements
May 2, 2026, 12:55 UTC
Coalfire SOC2 Type 2 for 2026
Coalfire has released our newest SOC2 Type 2 report covering the examination period of 3/1/2025 - 2/28/2026.
Dec 25, 2025, 13:55 UTC
Coalfire Trust Portal
Coalfire's new trust and assurance portal is live! In this portal you will find a number of resources that demonstrate Coalfire's diligence to organizational governance, compliance, security, and privacy. Please reach out with any questions you might have.
What we offer
Compliance Essentials
Coalfire Compliance Essentials is a SaaS platform enterprises use to manage complex compliance programs and audit
cycles. The platform incorporates over 20 years of compliance advisory and audit expertise, providing compliance teams
with continuous visibility to constantly changing controls and evidence requirements. It enables evidence-based mapping
and coordinated assessments for over 75 frameworks utilizing our proprietary controls mapping. Compliance Essentials
helps companies achieve compliance up to two times faster than competing platforms by aligning efforts across
programs to reduce the duplication of requests and improve evidence collection and workflow.
Typical data access: No direct access to your data, systems, or services is required. Data is provided to Compliance Essentials by your organization's assessment users.
Certifications: ISO 27001:2022, ISO 27701, SOC 2 Type 2
Hexeon
Launched this year, the Hexeon platform enhances the traditional penetration testing model by intertwining high-frequency offensive pen testing with strategic defensive risk management. This dual-focused approach orchestrates a synchronized, continuous exploration and management of vulnerabilities, veering away from the conventional, snapshot-based methodologies that have proven insufficient in the contemporary digital ecosystem.
Hexeon melds a platform-fueled customer experience with advanced analytics into a singular, potent approach to offensive security, translating complex data into actionable insights and facilitating custom risk mitigation for customers.
Typical data access: Hexeon uses data collected by Coalfire offensive security teams, such as penetration testing findings, vulnerability data, and other data concerning technical risk.
Certifications: ISO 27001:2022, ISO 27701, SOC 2 Type 2
General Advisory, Audit, and Assessment Services
Our general Advisory, Audit, and Assessment services cover the professional services layer of Coalfire. These services may or may not leverage the Hexeon or Compliance Essentials products.
Advisory Services
Specializing in GRC, AI cloud engineering, healthcare risk and FedRAMP, our Advisory expertise and governance is trusted throughout even the most complex and highly regulatory environments. We listen, investigate and advise to anticipate, adapt and cut through inefficiency. Creating bespoke solutions that implement security first – across all frameworks – to help you meet and exceed diverse requirements quickly, effectively and with complete and utter confidence.
Audit and Assessment
Our Audit and Assessment services tackle the world’s toughest, most complicated compliance challenges. Analyzing, automating and streamlining them through our mastery of expedited compliance protocols. With expertise across PCI DSS, HITRUST, ISO, FedRAMP and 85+ frameworks, we assess, simplify and provide guidance through rigorous attestations and certifications. All, to empower you with the support and tools needed to meet objectives, simplify and synchronize processes and confirm system readiness.
Security
DivisionHex marks the evolution of Coalfire – going beyond compliance to tackle the threats compliance alone can’t stop. We hand-picked a team of offensive, defensive and managed cybersecurity experts to close the gap between compliance and achieving full security on all sides.
Typical data access: These services typically interact with the aspects of your organization's IT and Information Security Program. These documents include security and HR policies, technology architecture, and written processes/procedures.
Certifications: ISO 27001:2022, ISO 27701, SOC 2 Type 2
Featured Documents
Subprocessors16
Subprocessor
Location of Processing
Usage Details
Atlassian Jira
United States
Customer support and ticketing system for Compliance Essentials and Hexeon.
AWS
United States
Infrastructure as a service for our Hexeon and Compliance Essentials products, as well as infrastructure for DivisionHex and Cloud Management teams.
B
Box
United States
Document management, document storage, and data retention.
Contrast Security
United States
Interactive application security testing to identify flaws within code at runtime.
Cyera
United States
Data security posture management (DSPM) service that monitors data-at-rest repositories for compliance against organizational security standards.
Ironclad
United States
Contract management and collaboration.
Lumos
United States
Identity Governance and Administration, privileged identity management.
Microsoft
United States
Microsoft O365, AzureAD, and Entra SSO/IAM.
MongoDB
United States
Relational database management system (RDBMS) backend for Compliance Essentials.
Netskope
United States
Cloud access security broker (CASB) for monitoring user cloud activity.
NetSuite
United States
AP/GL supporting core accounting and finance processes.
PlexTrac
United States
Aggregation of penetration testing findings and reporting.
Proofpoint
United States
Email security gateway (ESG) for Coalfire corporate email..
Salesforce
United States
Sales customer relationship management and order processing.
SonarQube
United States
Static analysis security testing for Coalfire application code and product development.
Splunk
United States
Security Event Information Management (SEIM) for log aggregation, analysis, and security event alerting.
Last updated December 16, 2025. .
View as:
Powered by Conveyor, the first end-to-end customer trust platform.
Learn more