Profound enterprise security, SSO, SOC 2 and data residency
A procurement-focused review of Profound SOC 2 Type 2, HIPAA, SAML and OIDC SSO, RBAC, audit logs, backups, DPA terms, subprocessors, hosting, and data-residency uncertainty.
Quick answer
Does Profound meet enterprise security, identity, privacy, and procurement requirements?
Profound has a strong public enterprise-security case. Its Trust Center lists SOC 2 Type 2 and HIPAA, Enterprise supports SAML or OIDC SSO and role-based access, Activity Logs provide an exportable audit trail, and its DPA covers encryption, subprocessors, transfer safeguards, deletion, and 72-hour incident notice. The main open item is data residency: public legal material says United States hosting, but does not document a customer-selectable regional residency option.
Key facts and evidence
- Compliance
- SOC 2 Type 2 and HIPAA listed in the Trust CenterEvidence: Profound Trust Center
- Single sign-on
- SAML and OIDC on EnterpriseEvidence: Profound Enterprise, Profound pricing and plan comparison, Enterprise SSO overview
- Access control
- Fine-grained RBAC plus exportable Activity LogsEvidence: Profound Enterprise, Profound pricing and plan comparison, Enterprise SSO overview, About Activity Logs
- Backups
- Daily, retained for one weekEvidence: Profound Enterprise
- Incident notice
- Within 72 hours under the published DPAEvidence: Profound Data Processing Agreement
- Data residency
- Customer-selectable regional hosting is not publicly documentedEvidence: Profound Privacy Policy, Profound Data Processing Agreement, Profound Enterprise, Profound Trust CenterNot publicly verified. Public legal material describes United States hosting and international-transfer safeguards, not a contractual residency menu. Confirm any regional hosting requirement in writing.
Profound procurement evidence checklist
| Control | Profound public evidence | Trakkr public evidence | Procurement conclusion |
|---|---|---|---|
| SOC 2 | SOC 2 Type 2 listed; report access available through Trust Center | No Trakkr-owned SOC 2 certification currently claimed | Profound is the stronger fit when a vendor Type 2 report is a hard gateEvidence: Profound Trust Center, Security at Trakkr |
| Identity | Enterprise SAML or OIDC SSO with role-based permissions | RBAC and MFA are publicly documented | Profound has the clearer public enterprise SSO caseEvidence: Profound Enterprise, Profound pricing and plan comparison, Enterprise SSO overview, Security at Trakkr |
| Audit trail | User, IP address, event, time, filters, counts, and export | Security controls are published, but no equivalent claim is made here | Profound documents a procurement-ready activity recordEvidence: About Activity Logs, Security at Trakkr |
| Data protection | DPA covers encryption, scanning, subprocessors, SCCs, deletion, and incident notice | TLS 1.3, AES-256, row-level isolation, RBAC, and MFA published | Review legal commitments separately from technical-control pagesEvidence: Profound Data Processing Agreement, Security at Trakkr |
| Data location | Privacy policy says services are hosted in the United States | Certified infrastructure and regional isolation are published | Neither statement alone proves a buyer-selectable residency commitmentEvidence: Profound Privacy Policy, Profound Data Processing Agreement, Profound Enterprise, Profound Trust Center, Security at TrakkrNot publicly verified. Public legal material describes United States hosting and international-transfer safeguards, not a contractual residency menu. Confirm any regional hosting requirement in writing. |
| Resilience | Daily backups retained for one week | Infrastructure-provider controls are published | Ask for recovery objectives, restoration tests, and service termsEvidence: Profound Enterprise, Security at Trakkr |
This is a public-evidence comparison, not a security certification or legal opinion. Sensitive reports in Profound's Trust Center require access approval.
What independent compliance evidence does Profound make available?
Profound's Trust Center lists SOC 2 Type 2 and HIPAA compliance. It offers gated access to the SOC 2 report, penetration-test report, data-flow diagram, HIPAA report, and security policies.
A buyer should request the current report period, bridge letter if needed, scope, exceptions, subservice organizations, and remediation status rather than relying only on the public badge.
Does Profound support SSO, permissions, and audit evidence?
Yes. Profound documents Enterprise SSO using SAML or OIDC and fine-grained role-based permissions. Activity Logs record high-impact organization, login, and membership events with the responsible user, IP address, timestamp, filters, and export.
Public sources do not replace a role-design review. Test category access, administrator boundaries, deprovisioning, service accounts, API keys, and exported log retention against the buyer's control matrix.
What does Profound's DPA commit to?
The published DPA covers encryption using industry-accepted methods, vulnerability scanning, confidentiality, subprocessors, Standard Contractual Clauses, return or deletion after termination, and notice within 72 hours after Profound becomes aware of a security incident.
Its subprocessor annex names processing providers and locations. Procurement should compare the annex with the actual modules being purchased, especially model providers, analytics, support, database, and hosting services.
Can a Profound customer require data to stay in the UK or EU?
No public source checked promises that option. Profound's privacy policy says the services are hosted in the United States and describes transfers from the EEA or United Kingdom under approved safeguards. The DPA lists international-transfer terms and subprocessor locations.
That is not the same as a customer-selectable residency commitment. If residency is mandatory, require the primary database, backups, logs, support access, AI providers, disaster recovery, and onward-transfer rules to be stated in the contract.
Evidence and method
A live Trust Center supports review
Profound lists current compliance badges and provides an access path for reports, diagrams, penetration testing, and policies needed in security review.
Evidence: Profound Trust CenterIdentity and audit controls are productized
SSO, role-based permissions, and Activity Logs are described as operational product controls rather than only contract promises.
Evidence: Profound Enterprise, Profound pricing and plan comparison, Enterprise SSO overview, About Activity LogsThe DPA contains concrete commitments
The public agreement defines incident notice, encryption, vulnerability scanning, subprocessors, transfer safeguards, audit cooperation, and return or deletion.
Evidence: Profound Data Processing AgreementResidency remains an explicit open item
Public material describes United States hosting and international-transfer safeguards but does not expose a regional hosting menu for customers.
Evidence: Profound Privacy Policy, Profound Data Processing Agreement, Profound Enterprise, Profound Trust CenterNot publicly verified. Public legal material describes United States hosting and international-transfer safeguards, not a contractual residency menu. Confirm any regional hosting requirement in writing.How we checked this page
We checked Profound's Trust Center, Enterprise page, pricing, identity documentation, Activity Logs, DPA, and privacy policy, then separated certifications, product controls, and legal commitments.
- 1. Recorded only controls and commitments visible in current official security, documentation, pricing, and legal sources.
- 2. Marked data residency as not publicly documented because transfer safeguards and hosting location do not prove a selectable residency option.
- 3. Compared Trakkr only from its current official security page, without inferring controls that page does not claim.
- Limitation: We did not receive gated reports, complete a vendor questionnaire, test SSO, inspect architecture, or review a negotiated security addendum.
- Limitation: Compliance scope, report exceptions, recovery objectives, and contract amendments can only be confirmed in due diligence.
When is Profound or Trakkr the better procurement fit?
Profound is the stronger documented choice when vendor-level SOC 2 Type 2, HIPAA, SAML or OIDC SSO, and an exportable organization activity trail are hard requirements. Trakkr's own security page explicitly says it does not currently hold its own SOC 2 certification, even though it publishes strong technical controls and certified infrastructure providers.
Trakkr remains a fit when procurement accepts its published TLS, encryption-at-rest, isolation, RBAC, MFA, and infrastructure posture, and the buyer values faster setup or wider standard-plan model coverage more than Profound's certifications. A strict regional data-residency requirement needs written confirmation from either vendor rather than an inference from public hosting language.
Yes. Profound's Trust Center lists SOC 2 Type 2 and provides a gated request path for the report. Buyers should still review its period, scope, exceptions, and bridge coverage.
Yes. Profound documents Enterprise SSO through SAML or OIDC, alongside role-based permissions. The current pricing page does not include SSO on Starter or Growth.
Yes. Activity Logs record selected high-impact organization, login, and membership events with user, IP address, timestamp, filtering, and export for administrators.
Profound's privacy policy says the services are hosted in the United States. Public sources do not document a customer-selectable UK, EU, or other regional residency option.
Sources and related reading
See how AI talks about your brand
Enter your domain to get a free AI visibility report in under 60 seconds.