Third Party Index

Snapshot 22204

Document
Trust center
URL
https://trust.perforce.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
122503 bytes
SHA-256 (raw)
650a9619dccf5d2e6c2973f7af46365c8d1efcf4cc5575e897de2d059bfbea09
SHA-256 (normalized text)
05e6492974bb8ddd4e945eb11aaa7fb1c42435e04a9c72e043bb5807d8a6a720

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
Perforce Software
Welcome to Perforce Software's Trust Center. We deliver leading-edge products that span the demands of the DevOps lifecycle and bring the most imaginative solutions to life more quickly and securely, with business-changing outcomes.
Privacy PolicyOpens in new tab
Filter by
For more information about Perforce and our DevOps Products, please see the following resources:
Perforce DevOps Product SuiteOpens in new tab
Perforce Security & ComplianceOpens in new tab
Compliance
SOC 2
ISO 27001:2022
ISO/IEC 42001:2023
ISO 9001:2015
GDPR
CCPA
HIPAA
Resources
View all
Perforce Software
Certificate of Insurance
ISO 42001
ISO 42001 Certificate
BlazeMeter
SOC 2 Type 2 Report
Penetration Test Executive Summary
Delphix
SOC 2 Type 2 Report
ISO 27001 Certificate
HIPAA Attestation Report
Gliffy
SOC 2 Type 2 Report
Penetration Test Executive Summary
Gliffy Architecture Diagrams
Gliffy Data Encryption at Rest
View 3 more
Perfecto
SOC 2 Type 2 Report
Penetration Test Executive Summary
Perfecto Security Overview
Puppet
Puppet Enterprise - Pen Test Executive Attestation
Puppet Cloud - Pen Test Executive Attestation
QAC / Klocwork
ISO 27001 Certificate
ISO 9001 Certificate
Subprocessors
View all
Amazon Web Services (AWS)
•
Cloud Provider
Multiple
Gliffy, Perfecto
Google Cloud
•
Cloud Provider
Multiple
BlazeMeter
Microsoft Azure
•
Cloud Provider
Multiple
Delphix (SaaS)
OpenAI
•
Gliffy Diagram Generation
United States
Gliffy
FAQ
View all
Updates
View all
Security
Akana API Platform (CVE-2026-85978) - UPDATE
Published September 10, 2026
Perforce has released security updates addressing CVE-2026-85978, an unauthenticated remote code execution vulnerability affecting the Akana API Platform Policy Manager component. The issue could impact customers running vulnerable Akana deployments with the Policy Manager Console exposed to the internet.
Status: Security patches are now available for all supported affected versions, including Akana 2024.1.6, 2025.1.2, and 2026.2. Customers running supported on-premises or hybrid deployments should apply the applicable update as soon as possible.
Mitigation: For customers unable to patch immediately, Perforce has provided interim mitigation guidance that can be implemented at the network edge to reduce exposure until updates can be applied.
Akana SaaS Customers: All Akana SaaS environments have already been protected, and no customer action is required.
Customers requiring assistance should contact Perforce Support for remediation guidance and update assistance.
Compliance
Perforce has achieved ISO/IEC 42001:2023 Certification
Published February 6, 2026
Perforce has achieved ISO/IEC 42001:2023 certification for several of our AI-powered products, including:
Delphix Data Control Tower
BlazeMeter Test Data Pro
BlazeMeter AI Log Analysis
Gliffy Diagrams for Confluence Cloud - Create with AI
Perfecto AI
Puppet Infra Assistant
Puppet Infra Assistant: Code Assist
This certification demonstrates our commitment to responsible, transparent, and secure AI practices. Perforce applies the same unified AI governance framework across our products, ensuring consistent oversight, ethical standards, and rigorous risk management throughout our portfolio.
ISO 42001 certification is the first international certification that validates an organization’s responsible management of Artificial Intelligence (AI), through an AI Management System (AIMS). To learn more about the certification, please head hereOpens in new tab.
General
MongoDB CVE-2025-14847 (MongoBleed) Advisory – IPLM Customers
Published January 7, 2026
MongoDB disclosed CVE-2025-14847 (MongoBleed) on December 19, 2025, a high-severity vulnerability affecting MongoDB instances using zlib compression. Exploitation could expose sensitive data from memory.
Who is impacted?
MongoDB is an optional backend for PiCache, used for workspace creation logging and IPV cleanup. Customers who have enabled zlib compression on the MongoDB server and are running a vulnerable version are at risk.
Action Required
Upgrade to patched versions: 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30.
If upgrade is not possible, disable zlib compression or restrict MongoDB access to trusted networks.
For details, see MongoDB SecurityOpens in new tab.
General
Apache Tika Parsers CVE-2025-66516 Security Advisory – UPDATE FOR BLAZEMETER CUSTOMERS
Published December 15, 2025
On December 4, Apache disclosed CVE-2025-66516, an XML External Entity (XXE) vulnerability in the Tika framework’s PDF parsing functionality. This library is included in the JMeter distribution that ships with BlazeMeter.
While the CVE is rated Critical in general PDF parsing scenarios, the vulnerable PDF parsing code in JMeter is not reachable in the default BlazeMeter distribution because the necessary dependencies are not included. Exploitation would require modifying or extending JMeter to enable PDF parsing. In standard deployments, there is no practical attack path.
Perforce will continue to monitor updates to JMeter and will implement a BlazeMeter update when a patched version becomes available. We recommend that all Private Location installations follow engineering best practices, including segregating test and production systems and keeping BlazeMeter installations behind a firewall.