Third Party Index

Viant Technology

viantinc.com

Subprocessors

None extracted.

ComplianceCSVof Viant Technology's compliance · Atomfeed of Viant Technology's compliance

Certified
Says it complies with

Security program

How Viant Technology says it manages cybersecurity risk, in its annual report to the SEC.

Board oversight
Audit Committee
quote While primary oversight is delegated to the Audit Committee, the Board directly oversees management’s implementation of our cybersecurity risk management program.
Frameworks named
  • CIS Controls
quote We use the CIS Critical Security Controls Version 8 (“CIS Controls”) as a framework to help guide the design and assessment of our cybersecurity risk management program.
Outside review
Engages outside assessors or consultants
quote Our CIO has primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants.
Its own suppliers
Reviews their security
quote a third-party risk management process that evaluates significant service providers, suppliers, and vendors for cybersecurity risks based on our assessment of their criticality to our operations and respective risk profile.
Practices named
  • Incident response plan
  • Threat intelligence
  • Security training
Material incidents
None so far, it says
quote We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
Read Item 1C in full

Cybersecurity Risk Management and Strategy

We have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information.

We use the CIS Critical Security Controls Version 8 (“CIS Controls”) as a framework to help guide the design and assessment of our cybersecurity risk management program. Reference to the CIS Controls does not imply that we meet any particular technical standards, specifications, or requirements, rather, we use the framework as a tool to inform our identification, assessment, and management of cybersecurity risks relevant to our business.

Our cybersecurity risk management program operates under its own governance structure and includes established processes for identifying, monitoring, and reporting cybersecurity risks. The initial phase of the Company's enterprise risk management ("ERM") program has been completed and incorporates cybersecurity risk as part of the broader enterprise risk framework, alongside governance, process, technology, financial reporting, and fraud risks that could impact our financial statements. The Company continues to enhance and expand its ERM program to further integrate risk identification, assessment, and response activities across the enterprise on an ongoing basis.

Key elements of our cybersecurity risk management program include, but are not limited to, the following:

•risk assessments designed to identify material risks from cybersecurity threats to our critical systems and information;

•a dedicated security team principally responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls, and (3) our response to cybersecurity incidents;

•the use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security controls;

•cybersecurity awareness training of our employees, including incident response personnel and senior management;

•a formal cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents; and

•a third-party risk management process that evaluates significant service providers, suppliers, and vendors for cybersecurity risks based on our assessment of their criticality to our operations and respective risk profile.

We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition. We face risks from cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition. See “Risk Factors – A significant breach of our IT Systems or disclosure of our Confidential Data, or of the security of our or our customers’, suppliers’, or other third parties’ systems upon which we rely could be detrimental to our business, reputation and results of operations.”

Cybersecurity Governance

Our board of directors (the "Board") considers cybersecurity risk as part of its risk oversight responsibilities. While primary oversight is delegated to the Audit Committee, the Board directly oversees management’s implementation of our cybersecurity risk management program.

The Board receives regular reports from management on our cybersecurity risks. In addition, management updates the Board, where it deems appropriate, regarding any cybersecurity incidents it considers significant or potentially significant. Board members receive presentations on cybersecurity topics from our Chief Information Officer ("CIO").

Our management team, including our CIO, is responsible for assessing and managing our material risks from cybersecurity threats. Our CIO has primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants. Our CIO's experience includes over twenty (20) years of design, implementation and management of cybersecurity programs at various levels and organizations.

Management oversight of cybersecurity risks includes ongoing efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means. These efforts may include briefings from internal security personnel; threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us; and alerts, dashboards and reports generated by security tools deployed throughout our IT environment.

Certifications as Viant Technology's trust center lists them; reports are usually shared on request (evidence) Security program from Viant Technology Inc.'s Form 10-K for fiscal 2025, filed Mar 11, 2026, Item 1C, in its words (evidence)

Service statusCSVof Viant Technology's status page incidents · Atomfeed of Viant Technology's status page incidents

Jul 10: no incident reportedJul 11: no incident reportedJul 12: no incident reportedJul 13: no incident reportedJul 14: no incident reportedJul 15: no incident reportedJul 16: no incident reportedJul 17: no incident reportedJul 18: no incident reportedJul 19: no incident reportedJul 20: no incident reportedJul 21: no incident reportedJul 22: no incident reportedJul 23: no incident reportedJul 24: no incident reportedJul 25: no incident reportedJul 26: no incident reportedJul 27: no incident reportedJul 28: no incident reportedJul 29: no incident reportedJul 30: no incident reportedJul 31: no incident reportedAug 1: no incident reportedAug 2: no incident reportedAug 3: no incident reportedAug 4: no incident reportedAug 5: no incident reportedAug 6: no incident reportedAug 7: no incident reportedAug 8: no incident reportedAug 9: no incident reportedAug 10: no incident reportedAug 11: no incident reportedAug 12: no incident reportedAug 13: no incident reportedAug 14: no incident reportedAug 15: no incident reportedAug 16: no incident reportedAug 17: no incident reportedAug 18: no incident reportedAug 19: no incident reportedAug 20: no incident reportedAug 21: no incident reportedAug 22: no incident reportedAug 23: no incident reportedAug 24: no incident reportedAug 25: no incident reportedAug 26: no incident reportedAug 27: no incident reportedAug 28: no incident reportedAug 29: no incident reportedAug 30: no incident reportedAug 31: no incident reportedSep 1: no incident reportedSep 2: no incident reportedSep 3: no incident reportedSep 4: no incident reportedSep 5: no incident reportedSep 6: no incident reportedSep 7: no incident reportedSep 8: no incident reportedSep 9: no incident reportedSep 10: no incident reportedSep 11: no incident reportedSep 12: no incident reportedSep 13: no incident reportedSep 14: no incident reportedSep 15: no incident reportedSep 16: no incident reportedSep 17: no incident reportedSep 18: no incident reportedSep 19: no incident reportedSep 20: no incident reportedSep 21: no incident reportedSep 22: no incident reportedSep 23: no incident reportedSep 24: no incident reportedSep 25: no incident reportedSep 26: no incident reportedSep 27: no incident reportedSep 28: no incident reportedSep 29: no incident reportedSep 30: no incident reportedOct 1: no incident reportedOct 2: no incident reportedOct 3: no incident reportedOct 4: no incident reportedOct 5: no incident reportedOct 6: no incident reportedOct 7: no incident reported

90 days agotoday

No incidents reported since Nov 1, 2025

As Viant Technology's status page reports its own incidents (scheduled maintenance left out), read every few hours since (evidence)

ChangesCSVof Viant Technology's changes · Atomfeed of Viant Technology's changes

None since tracking began.

Rating badge for Viant Technology's site

Viant Technology transparency rating

It updates with the rating.

<a href="https://thirdpartyindex.com/vendors/viant-technology"><img src="https://thirdpartyindex.com/badge/viant-technology.svg" alt="Viant Technology transparency rating on Third Party Index" height="20"></a>
[![Viant Technology transparency rating on Third Party Index](https://thirdpartyindex.com/badge/viant-technology.svg)](https://thirdpartyindex.com/vendors/viant-technology)