Viant Technology
Subprocessors
None extracted.
ComplianceCSVof Viant Technology's compliance · Atomfeed of Viant Technology's compliance
Security program
How Viant Technology says it manages cybersecurity risk, in its annual report to the SEC.
- Board oversight
- Audit Committee
quote
While primary oversight is delegated to the Audit Committee, the Board directly oversees management’s implementation of our cybersecurity risk management program.
- Frameworks named
- CIS Controls
quote
We use the CIS Critical Security Controls Version 8 (“CIS Controls”) as a framework to help guide the design and assessment of our cybersecurity risk management program.
- Outside review
- Engages outside assessors or consultants
quote
Our CIO has primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants.
- Its own suppliers
- Reviews their security
quote
a third-party risk management process that evaluates significant service providers, suppliers, and vendors for cybersecurity risks based on our assessment of their criticality to our operations and respective risk profile.
- Practices named
- Incident response plan
- Threat intelligence
- Security training
- Material incidents
- None so far, it says
quote
We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
Read Item 1C in full
Cybersecurity Risk Management and Strategy
We have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information.
We use the CIS Critical Security Controls Version 8 (“CIS Controls”) as a framework to help guide the design and assessment of our cybersecurity risk management program. Reference to the CIS Controls does not imply that we meet any particular technical standards, specifications, or requirements, rather, we use the framework as a tool to inform our identification, assessment, and management of cybersecurity risks relevant to our business.
Our cybersecurity risk management program operates under its own governance structure and includes established processes for identifying, monitoring, and reporting cybersecurity risks. The initial phase of the Company's enterprise risk management ("ERM") program has been completed and incorporates cybersecurity risk as part of the broader enterprise risk framework, alongside governance, process, technology, financial reporting, and fraud risks that could impact our financial statements. The Company continues to enhance and expand its ERM program to further integrate risk identification, assessment, and response activities across the enterprise on an ongoing basis.
Key elements of our cybersecurity risk management program include, but are not limited to, the following:
•risk assessments designed to identify material risks from cybersecurity threats to our critical systems and information;
•a dedicated security team principally responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls, and (3) our response to cybersecurity incidents;
•the use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security controls;
•cybersecurity awareness training of our employees, including incident response personnel and senior management;
•a formal cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents; and
•a third-party risk management process that evaluates significant service providers, suppliers, and vendors for cybersecurity risks based on our assessment of their criticality to our operations and respective risk profile.
We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition. We face risks from cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition. See “Risk Factors – A significant breach of our IT Systems or disclosure of our Confidential Data, or of the security of our or our customers’, suppliers’, or other third parties’ systems upon which we rely could be detrimental to our business, reputation and results of operations.”
Cybersecurity Governance
Our board of directors (the "Board") considers cybersecurity risk as part of its risk oversight responsibilities. While primary oversight is delegated to the Audit Committee, the Board directly oversees management’s implementation of our cybersecurity risk management program.
The Board receives regular reports from management on our cybersecurity risks. In addition, management updates the Board, where it deems appropriate, regarding any cybersecurity incidents it considers significant or potentially significant. Board members receive presentations on cybersecurity topics from our Chief Information Officer ("CIO").
Our management team, including our CIO, is responsible for assessing and managing our material risks from cybersecurity threats. Our CIO has primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants. Our CIO's experience includes over twenty (20) years of design, implementation and management of cybersecurity programs at various levels and organizations.
Management oversight of cybersecurity risks includes ongoing efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means. These efforts may include briefings from internal security personnel; threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us; and alerts, dashboards and reports generated by security tools deployed throughout our IT environment.
Certifications as Viant Technology's trust center lists them; reports are usually shared on request (evidence) Security program from Viant Technology Inc.'s Form 10-K for fiscal 2025, filed Mar 11, 2026, Item 1C, in its words (evidence)
Service statusCSVof Viant Technology's status page incidents · Atomfeed of Viant Technology's status page incidents
90 days agotoday
No incidents reported since Nov 1, 2025
As Viant Technology's status page reports its own incidents (scheduled maintenance left out), read every few hours since (evidence)
ChangesCSVof Viant Technology's changes · Atomfeed of Viant Technology's changes
None since tracking began.