Profound logo
Profound
Enterprise and security

Profound enterprise security, SSO, SOC 2 and data residency

A procurement-focused review of Profound SOC 2 Type 2, HIPAA, SAML and OIDC SSO, RBAC, audit logs, backups, DPA terms, subprocessors, hosting, and data-residency uncertainty.

Trakkr editorial teamPublished 2026-08-25
9 min read
Last updated: August 25, 2026

Quick answer

Does Profound meet enterprise security, identity, privacy, and procurement requirements?

Profound has a strong public enterprise-security case. Its Trust Center lists SOC 2 Type 2 and HIPAA, Enterprise supports SAML or OIDC SSO and role-based access, Activity Logs provide an exportable audit trail, and its DPA covers encryption, subprocessors, transfer safeguards, deletion, and 72-hour incident notice. The main open item is data residency: public legal material says United States hosting, but does not document a customer-selectable regional residency option.

Published by Trakkr. Sources checked 2026-08-25.
Evidence: Profound Trust Center, Profound Enterprise, Profound pricing and plan comparison, Enterprise SSO overview, About Activity Logs, Profound Data Processing Agreement, Profound Privacy PolicyNot publicly verified. Public legal material describes United States hosting and international-transfer safeguards, not a contractual residency menu. Confirm any regional hosting requirement in writing.
Compliance
SOC 2 Type 2 and HIPAA listed in the Trust CenterEvidence: Profound Trust Center
Single sign-on
SAML and OIDC on EnterpriseEvidence: Profound Enterprise, Profound pricing and plan comparison, Enterprise SSO overview
Access control
Fine-grained RBAC plus exportable Activity LogsEvidence: Profound Enterprise, Profound pricing and plan comparison, Enterprise SSO overview, About Activity Logs
Backups
Daily, retained for one weekEvidence: Profound Enterprise
Incident notice
Within 72 hours under the published DPAEvidence: Profound Data Processing Agreement
Data residency
Customer-selectable regional hosting is not publicly documentedEvidence: Profound Privacy Policy, Profound Data Processing Agreement, Profound Enterprise, Profound Trust CenterNot publicly verified. Public legal material describes United States hosting and international-transfer safeguards, not a contractual residency menu. Confirm any regional hosting requirement in writing.

Profound procurement evidence checklist

Profound procurement evidence checklist
ControlProfound public evidenceTrakkr public evidenceProcurement conclusion
SOC 2SOC 2 Type 2 listed; report access available through Trust CenterNo Trakkr-owned SOC 2 certification currently claimedProfound is the stronger fit when a vendor Type 2 report is a hard gateEvidence: Profound Trust Center, Security at Trakkr
IdentityEnterprise SAML or OIDC SSO with role-based permissionsRBAC and MFA are publicly documentedProfound has the clearer public enterprise SSO caseEvidence: Profound Enterprise, Profound pricing and plan comparison, Enterprise SSO overview, Security at Trakkr
Audit trailUser, IP address, event, time, filters, counts, and exportSecurity controls are published, but no equivalent claim is made hereProfound documents a procurement-ready activity recordEvidence: About Activity Logs, Security at Trakkr
Data protectionDPA covers encryption, scanning, subprocessors, SCCs, deletion, and incident noticeTLS 1.3, AES-256, row-level isolation, RBAC, and MFA publishedReview legal commitments separately from technical-control pagesEvidence: Profound Data Processing Agreement, Security at Trakkr
Data locationPrivacy policy says services are hosted in the United StatesCertified infrastructure and regional isolation are publishedNeither statement alone proves a buyer-selectable residency commitmentEvidence: Profound Privacy Policy, Profound Data Processing Agreement, Profound Enterprise, Profound Trust Center, Security at TrakkrNot publicly verified. Public legal material describes United States hosting and international-transfer safeguards, not a contractual residency menu. Confirm any regional hosting requirement in writing.
ResilienceDaily backups retained for one weekInfrastructure-provider controls are publishedAsk for recovery objectives, restoration tests, and service termsEvidence: Profound Enterprise, Security at Trakkr

This is a public-evidence comparison, not a security certification or legal opinion. Sensitive reports in Profound's Trust Center require access approval.

What independent compliance evidence does Profound make available?

Profound's Trust Center lists SOC 2 Type 2 and HIPAA compliance. It offers gated access to the SOC 2 report, penetration-test report, data-flow diagram, HIPAA report, and security policies.

A buyer should request the current report period, bridge letter if needed, scope, exceptions, subservice organizations, and remediation status rather than relying only on the public badge.

Evidence: Profound Trust Center

Does Profound support SSO, permissions, and audit evidence?

Yes. Profound documents Enterprise SSO using SAML or OIDC and fine-grained role-based permissions. Activity Logs record high-impact organization, login, and membership events with the responsible user, IP address, timestamp, filters, and export.

Public sources do not replace a role-design review. Test category access, administrator boundaries, deprovisioning, service accounts, API keys, and exported log retention against the buyer's control matrix.

Evidence: Profound Enterprise, Profound pricing and plan comparison, Enterprise SSO overview, About Activity Logs

What does Profound's DPA commit to?

Can a Profound customer require data to stay in the UK or EU?

No public source checked promises that option. Profound's privacy policy says the services are hosted in the United States and describes transfers from the EEA or United Kingdom under approved safeguards. The DPA lists international-transfer terms and subprocessor locations.

That is not the same as a customer-selectable residency commitment. If residency is mandatory, require the primary database, backups, logs, support access, AI providers, disaster recovery, and onward-transfer rules to be stated in the contract.

Evidence: Profound Privacy Policy, Profound Data Processing Agreement, Profound Enterprise, Profound Trust CenterNot publicly verified. Public legal material describes United States hosting and international-transfer safeguards, not a contractual residency menu. Confirm any regional hosting requirement in writing.

Evidence and method

A live Trust Center supports review

Profound lists current compliance badges and provides an access path for reports, diagrams, penetration testing, and policies needed in security review.

Evidence: Profound Trust Center

Identity and audit controls are productized

SSO, role-based permissions, and Activity Logs are described as operational product controls rather than only contract promises.

Evidence: Profound Enterprise, Profound pricing and plan comparison, Enterprise SSO overview, About Activity Logs

The DPA contains concrete commitments

The public agreement defines incident notice, encryption, vulnerability scanning, subprocessors, transfer safeguards, audit cooperation, and return or deletion.

Evidence: Profound Data Processing Agreement

Residency remains an explicit open item

Public material describes United States hosting and international-transfer safeguards but does not expose a regional hosting menu for customers.

Evidence: Profound Privacy Policy, Profound Data Processing Agreement, Profound Enterprise, Profound Trust CenterNot publicly verified. Public legal material describes United States hosting and international-transfer safeguards, not a contractual residency menu. Confirm any regional hosting requirement in writing.

How we checked this page

We checked Profound's Trust Center, Enterprise page, pricing, identity documentation, Activity Logs, DPA, and privacy policy, then separated certifications, product controls, and legal commitments.

  1. 1. Recorded only controls and commitments visible in current official security, documentation, pricing, and legal sources.
  2. 2. Marked data residency as not publicly documented because transfer safeguards and hosting location do not prove a selectable residency option.
  3. 3. Compared Trakkr only from its current official security page, without inferring controls that page does not claim.
  • Limitation: We did not receive gated reports, complete a vendor questionnaire, test SSO, inspect architecture, or review a negotiated security addendum.
  • Limitation: Compliance scope, report exceptions, recovery objectives, and contract amendments can only be confirmed in due diligence.

When is Profound or Trakkr the better procurement fit?

Profound is the stronger documented choice when vendor-level SOC 2 Type 2, HIPAA, SAML or OIDC SSO, and an exportable organization activity trail are hard requirements. Trakkr's own security page explicitly says it does not currently hold its own SOC 2 certification, even though it publishes strong technical controls and certified infrastructure providers.

Trakkr remains a fit when procurement accepts its published TLS, encryption-at-rest, isolation, RBAC, MFA, and infrastructure posture, and the buyer values faster setup or wider standard-plan model coverage more than Profound's certifications. A strict regional data-residency requirement needs written confirmation from either vendor rather than an inference from public hosting language.

Evidence: Profound Trust Center, Profound Enterprise, Profound pricing and plan comparison, Enterprise SSO overview, About Activity Logs, Security at Trakkr, Trakkr Quick Start, Trakkr Prompts documentation, Profound Privacy Policy, Profound Data Processing AgreementNot publicly verified. Public legal material describes United States hosting and international-transfer safeguards, not a contractual residency menu. Confirm any regional hosting requirement in writing.

Yes. Profound's Trust Center lists SOC 2 Type 2 and provides a gated request path for the report. Buyers should still review its period, scope, exceptions, and bridge coverage.

See how AI talks about your brand

Enter your domain to get a free AI visibility report in under 60 seconds.

14-day trialCancel anytime60 second setup