Peec enterprise security, SSO and procurement
What Peec publishes about SSO, SOC 2, roles, audit logs, encryption, residency, legal terms, data export, and the evidence procurement still needs.
Quick answer
Does Peec meet enterprise identity, security, privacy and procurement requirements?
Peec lists SSO on Enterprise, encrypts data in transit and at rest, restricts personnel access, and hosts its application backend and core data on Google Cloud. It is pursuing SOC 2 and is not yet certified. Public pages do not identify the SSO protocol, an admin audit-log product, customer-selectable core-data residency, or a downloadable customer DPA and subprocessor schedule, so regulated buyers need a security review and contract evidence.
Key facts and evidence
- SSO
- Enterprise; public protocol not identifiedEvidence: Peec AI pricing for brands, Peec AI official AI instructions, Peec AI documentation indexNot publicly verified. SSO itself is documented on Enterprise. The protocol, provisioning, deprovisioning, domain claim, and identity-provider compatibility require written confirmation.
- SOC 2
- Pursuing certification; not currently certifiedEvidence: Peec AI official AI instructions
- Access
- Company or project membership; owner permission for MCP writesEvidence: Peec AI sidebar and settings reference, Peec AI MCP Server documentation
- Audit logs
- No administrator audit-log product publicly documentedEvidence: Peec AI pricing for brands, Peec AI sidebar and settings reference, Peec AI documentation indexNot publicly verified. Peec may provide private security logs or contractual logging on Enterprise. Buyers should request event coverage, retention, export, actor, IP, and timestamp fields.
- Core hosting
- Google Cloud; no public customer-selectable residency optionEvidence: Peec AI Privacy PolicyNot publicly verified. The public policy does not state the exact Google Cloud region for core customer data or offer a residency menu. This does not rule out negotiated regional terms.
- Legal
- B2B terms under German law with EU Data Act switching languageEvidence: Peec AI Terms of Service
Peec enterprise control and evidence map
| Requirement | Peec | Trakkr | Procurement check |
|---|---|---|---|
| Enterprise identity | SSO listed, but public protocol and SCIM support are not identified | SAML or OIDC SSO and SCIM documented on Enterprise | Test the exact identity provider, provisioning lifecycle, and emergency accessEvidence: Peec AI pricing for brands, Peec AI official AI instructions, Peec AI documentation index, Trakkr Frequently Asked QuestionsNot publicly verified. SSO itself is documented on Enterprise. The protocol, provisioning, deprovisioning, domain claim, and identity-provider compatibility require written confirmation. |
| SOC 2 | Pursuing; not yet certified | No Trakkr-owned SOC 2 claim; infrastructure providers are certified | Do not treat either product as currently SOC 2 certifiedEvidence: Peec AI official AI instructions, Security at Trakkr |
| Roles and auditability | Company and project membership documented; admin audit log not public | Owner, Admin, Viewer, brand restrictions, billing grants, and team MFA controls documented | Request a permission matrix, audit-event list, retention, and export routeEvidence: Peec AI sidebar and settings reference, Peec AI MCP Server documentation, Peec AI pricing for brands, Peec AI documentation index, Trakkr Teams documentationNot publicly verified. Peec may provide private security logs or contractual logging on Enterprise. Buyers should request event coverage, retention, export, actor, IP, and timestamp fields. |
| Security controls | HTTPS, encryption at rest, credential safeguards, restricted staff access, and Google Cloud | TLS 1.3, AES-256, row-level isolation, RBAC, MFA, secure sessions, and regional isolation | Review architecture, vulnerability management, incident response, backups, and recovery evidenceEvidence: Peec AI Privacy Policy, Security at Trakkr |
| Residency and contracting | No public customer-selectable core residency; German B2B terms and switching provisions | Custom DPA and legal terms documented on Enterprise | Obtain data locations, subprocessors, transfer mechanism, DPA, deletion, and exit termsEvidence: Peec AI Privacy Policy, Peec AI Terms of Service, Trakkr Frequently Asked QuestionsNot publicly verified. The public policy does not state the exact Google Cloud region for core customer data or offer a residency menu. This does not rule out negotiated regional terms.Not publicly verified. A customer DPA may be available during sales or procurement. Request the current agreement, transfer mechanism, subprocessor annex, incident terms, deletion, and audit rights. |
Public documentation is a screening tool, not a completed vendor-security review. Contract exhibits, current reports, technical evidence, and the configured tenant determine the final answer.
Does Peec support SAML SSO or SCIM provisioning?
Peec's live pricing lists SSO on Enterprise. The current public pricing, product reference, and documentation index do not identify SAML, OIDC, SCIM, or another implementation protocol.
That does not mean those protocols are unavailable. Buyers should provide the identity provider, domain-claim, provisioning, deprovisioning, group mapping, break-glass, and session requirements for a written response and live test.
Is Peec SOC 2 certified, and what controls are public?
No. Peec's current official product reference says it is pursuing SOC 2 and is not yet certified. Buyers should not convert that roadmap statement into a current assurance claim.
Its Privacy Policy does publish HTTPS in transit, encryption at rest, secure credential management, restricted personnel access, and Google Cloud for the application backend and core data.
Can Peec restrict users and show an audit trail?
Peec documents member access at company or project level. MCP writes require organization-owner access and respect existing project permissions, which provides useful evidence of permission-aware automation.
We did not find an administrator-facing audit or activity-log product in the current public pricing, settings reference, or documentation index. Buyers should request the exact logged events, retention, search, export, and alerting behavior.
Does Peec guarantee EU data residency?
Peec's Privacy Policy names EU-hosted PostHog for product analytics and Google Cloud for the application backend and core data. It does not publish a customer-selectable core-data residency option.
The same policy describes transfers to the United States, United Kingdom, and other third countries. Buyers needing a residency boundary should obtain precise service locations, subprocessor locations, support access, backup locations, and transfer safeguards.
What public legal and exit terms can procurement review?
Peec's public terms are B2B, apply German law and Berlin jurisdiction, and describe EU Data Act switching assistance with machine-readable exportable data on up to two months' written notice.
Peec says it has DPAs with subprocessors, but the public legal pages checked do not link a customer DPA and subprocessor schedule. Procurement should request both, plus deletion certification and transition fees.
Evidence and method
SOC 2 status is explicit
Peec's official product reference distinguishes pursuing certification from holding a current SOC 2 report.
Evidence: Peec AI official AI instructionsCore safeguards are stated in the privacy notice
Peec publishes transport and storage encryption, credential, personnel-access, and backend-provider statements that buyers can test further.
Evidence: Peec AI Privacy PolicyIdentity and audit gaps are bounded
Enterprise SSO is verified, while the missing protocol and audit-log details are limited to the current public pages checked.
Evidence: Peec AI pricing for brands, Peec AI official AI instructions, Peec AI documentation index, Peec AI sidebar and settings referenceNot publicly verified. SSO itself is documented on Enterprise. The protocol, provisioning, deprovisioning, domain claim, and identity-provider compatibility require written confirmation.Not publicly verified. Peec may provide private security logs or contractual logging on Enterprise. Buyers should request event coverage, retention, export, actor, IP, and timestamp fields.Residency and exit require different evidence
The privacy notice describes hosting and transfers, while the terms separately provide a business-customer switching process and export language.
Evidence: Peec AI Privacy Policy, Peec AI Terms of ServiceNot publicly verified. The public policy does not state the exact Google Cloud region for core customer data or offer a residency menu. This does not rule out negotiated regional terms.How we checked this page
We separated certification, technical safeguards, identity protocols, permissions, audit evidence, hosting locations, international transfers, customer contracts, and exit rights before comparing public enterprise readiness.
- 1. Read Peec's live pricing, official product reference, settings and MCP documentation, Privacy Policy, Terms of Use, and documentation index.
- 2. Classified each requirement as verified, partially verified, or not publicly documented without treating silence as proof of unavailability.
- 3. Checked current official Trakkr security, Enterprise FAQ, and team-access documentation for the corresponding published controls.
- Limitation: We did not receive Peec's private security pack, penetration test, architecture diagram, insurance evidence, customer DPA, or subprocessor schedule.
- Limitation: Public legal pages cannot prove a configured tenant's identity policy, data locations, retention settings, or negotiated contractual commitments.
When is Peec or Trakkr the stronger enterprise fit?
Choose Peec when German-law B2B terms, its published EU Data Act switching route, and project-level membership suit the procurement model. Its privacy notice publishes useful baseline safeguards, but buyers must treat SOC 2 as in progress and verify SSO protocols, auditability, residency, and customer contract exhibits.
Choose Trakkr when the buying team needs more explicit public identity and access detail: Enterprise SAML or OIDC, SCIM, custom DPA terms, documented roles, brand restrictions, team MFA controls, and named encryption and isolation measures. Trakkr also does not currently claim its own SOC 2 certification.
Yes, Peec lists SSO on Enterprise. Its public pages do not identify the supported protocol or confirm SCIM, so buyers should test their identity provider.
No. Peec's current official product reference says it is pursuing SOC 2 and is not yet certified. Procurement should request current assurance evidence directly.
We did not find an admin audit or activity-log product in current public pricing, settings, or documentation. That does not rule out private or planned support.
Peec names Google Cloud for its application backend and core data, but does not publish customer-selectable core residency and describes several third-country transfer destinations.
Sources and related reading
See how AI talks about your brand
Enter your domain to get a free AI visibility report in under 60 seconds.