Snapshot 22204
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to navigationSkip to main content Perforce Software Welcome to Perforce Software's Trust Center. We deliver leading-edge products that span the demands of the DevOps lifecycle and bring the most imaginative solutions to life more quickly and securely, with business-changing outcomes. Privacy PolicyOpens in new tab Filter by For more information about Perforce and our DevOps Products, please see the following resources: Perforce DevOps Product SuiteOpens in new tab Perforce Security & ComplianceOpens in new tab Compliance SOC 2 ISO 27001:2022 ISO/IEC 42001:2023 ISO 9001:2015 GDPR CCPA HIPAA Resources View all Perforce Software Certificate of Insurance ISO 42001 ISO 42001 Certificate BlazeMeter SOC 2 Type 2 Report Penetration Test Executive Summary Delphix SOC 2 Type 2 Report ISO 27001 Certificate HIPAA Attestation Report Gliffy SOC 2 Type 2 Report Penetration Test Executive Summary Gliffy Architecture Diagrams Gliffy Data Encryption at Rest View 3 more Perfecto SOC 2 Type 2 Report Penetration Test Executive Summary Perfecto Security Overview Puppet Puppet Enterprise - Pen Test Executive Attestation Puppet Cloud - Pen Test Executive Attestation QAC / Klocwork ISO 27001 Certificate ISO 9001 Certificate Subprocessors View all Amazon Web Services (AWS) • Cloud Provider Multiple Gliffy, Perfecto Google Cloud • Cloud Provider Multiple BlazeMeter Microsoft Azure • Cloud Provider Multiple Delphix (SaaS) OpenAI • Gliffy Diagram Generation United States Gliffy FAQ View all Updates View all Security Akana API Platform (CVE-2026-85978) - UPDATE Published September 10, 2026 Perforce has released security updates addressing CVE-2026-85978, an unauthenticated remote code execution vulnerability affecting the Akana API Platform Policy Manager component. The issue could impact customers running vulnerable Akana deployments with the Policy Manager Console exposed to the internet. Status: Security patches are now available for all supported affected versions, including Akana 2024.1.6, 2025.1.2, and 2026.2. Customers running supported on-premises or hybrid deployments should apply the applicable update as soon as possible. Mitigation: For customers unable to patch immediately, Perforce has provided interim mitigation guidance that can be implemented at the network edge to reduce exposure until updates can be applied. Akana SaaS Customers: All Akana SaaS environments have already been protected, and no customer action is required. Customers requiring assistance should contact Perforce Support for remediation guidance and update assistance. Compliance Perforce has achieved ISO/IEC 42001:2023 Certification Published February 6, 2026 Perforce has achieved ISO/IEC 42001:2023 certification for several of our AI-powered products, including: Delphix Data Control Tower BlazeMeter Test Data Pro BlazeMeter AI Log Analysis Gliffy Diagrams for Confluence Cloud - Create with AI Perfecto AI Puppet Infra Assistant Puppet Infra Assistant: Code Assist This certification demonstrates our commitment to responsible, transparent, and secure AI practices. Perforce applies the same unified AI governance framework across our products, ensuring consistent oversight, ethical standards, and rigorous risk management throughout our portfolio. ISO 42001 certification is the first international certification that validates an organization’s responsible management of Artificial Intelligence (AI), through an AI Management System (AIMS). To learn more about the certification, please head hereOpens in new tab. General MongoDB CVE-2025-14847 (MongoBleed) Advisory – IPLM Customers Published January 7, 2026 MongoDB disclosed CVE-2025-14847 (MongoBleed) on December 19, 2025, a high-severity vulnerability affecting MongoDB instances using zlib compression. Exploitation could expose sensitive data from memory. Who is impacted? MongoDB is an optional backend for PiCache, used for workspace creation logging and IPV cleanup. Customers who have enabled zlib compression on the MongoDB server and are running a vulnerable version are at risk. Action Required Upgrade to patched versions: 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30. If upgrade is not possible, disable zlib compression or restrict MongoDB access to trusted networks. For details, see MongoDB SecurityOpens in new tab. General Apache Tika Parsers CVE-2025-66516 Security Advisory – UPDATE FOR BLAZEMETER CUSTOMERS Published December 15, 2025 On December 4, Apache disclosed CVE-2025-66516, an XML External Entity (XXE) vulnerability in the Tika framework’s PDF parsing functionality. This library is included in the JMeter distribution that ships with BlazeMeter. While the CVE is rated Critical in general PDF parsing scenarios, the vulnerable PDF parsing code in JMeter is not reachable in the default BlazeMeter distribution because the necessary dependencies are not included. Exploitation would require modifying or extending JMeter to enable PDF parsing. In standard deployments, there is no practical attack path. Perforce will continue to monitor updates to JMeter and will implement a BlazeMeter update when a patched version becomes available. We recommend that all Private Location installations follow engineering best practices, including segregating test and production systems and keeping BlazeMeter installations behind a firewall.