Authored by: PlexTrac Author Posted on: December 10, 2024 PlexTrac Achieves ISO/IEC 27001:2022 Certification and Expands SOC 2 Type II Coverage, Cementing Its Commitment to Security and Compliance December 10, 2024 08:00 AM Eastern Standard Time BOISE, Idaho — PlexTrac, the market leader in pentest and vulnerability data management, proudly announces two major milestones in its commitment to safeguarding customer data and ensuring trust in its platform. The company has successfully achieved ISO/IEC 27001:2022 certification and expanded its SOC 2 Type II certification to include additional trust services criteria, demonstrating its unwavering dedication to world-class information security standards. “These achievements are a testament to PlexTrac’s commitment to the highest standards of information security” Achieving ISO/IEC 27001:2022 certification further solidifies PlexTrac’s position as a leader in cybersecurity solutions. Certified by Sensiba LLP, this internationally recognized standard establishes a framework for managing information security risks through an Information Security Management System (ISMS). ISO 27001 certification validates PlexTrac’s robust practices in establishing, implementing, operating, and continually improving its ISMS, offering customers, partners and stakeholders an additional layer of confidence in the platform’s security. PlexTrac first achieved SOC 2 Type II certification in 2022, and the latest audit by Sensiba LLP evaluated PlexTrac’s controls over a specified period, focusing on the trust services criteria categories of security, availability, processing integrity, confidentiality, and privacy. With no noted exceptions, PlexTrac’s “clean” audit opinion underscores the effectiveness of its systems and controls in protecting client data and ensuring operational integrity. “These achievements are a testament to PlexTrac’s commitment to the highest standards of information security,” said Dan DeCloss, CTO, PlexTrac. “Our customers and partners trust us to safeguard their most sensitive data, and these certifications reflect our dedication to earning and maintaining that trust. Achieving ISO/IEC 27001:2022 certifications and expanding our SOC 2 Type II coverage demonstrates our commitment to upholding the highest standards in protecting our clients’ data.” PlexTrac’s platform streamlines cybersecurity workflows by centralizing vulnerability management, automating reporting, and facilitating collaboration between offensive and defensive security teams. By attaining these certifications, PlexTrac not only reinforces its dedication to information security but also enhances its ability to serve as a trusted partner for organizations seeking to improve their cybersecurity posture. About PlexTrac PlexTrac, the market leader in pentest and vulnerability data management, allows MSSP and Enterprise customers to extend beyond pentesting by streamlining critical offensive security workflows as part of a continuous validation strategy. With PlexTrac, security teams can aggregate offensive security data from multiple sources, prioritize risk with the industry’s first fully configurable contextual scoring engine, and close the loop on continuous validation with measurable risk reduction. In February 2022, PlexTrac announced a $70 million Series B round, led by New York-based global venture capital and private equity firm, Insight Partners, with participation from existing investors Madrona Venture Group, Noro-Moseley Partners, and StageDotO Ventures. Visit www.plextrac.com to learn more. Contacts Patricia Tantow CMO PlexTrac ptantow@plextrac.com PlexTrac Author At PlexTrac, we bring together insights from a diverse range of voices. Our blog features contributions from industry experts, ethical hackers, CTOs, influencers, and PlexTrac team members—all sharing valuable perspectives on cybersecurity, pentesting, and risk management.
5 Signs Your Vulnerability Management Program Isn’t Ready for Continuous Threat Exposure Management (CTEM) The buzz around Continuous Threat Exposure Management (CTEM) is everywhere right now, and for good reason. Organizations are realizing that traditional vulnerability management, built around periodic scans and reports, can’t keep up with today’s attack surfaces. READ ARTICLE
From Findings to Fixes: Bridging the Gap Between Pentests and Vulnerability Management Penetration tests are one of the most valuable tools in a security program but also one of the most under-leveraged. Every year, organizations invest in pentests to identify real-world attack paths, validate defenses, and uncover high-impact vulnerabilities. Yet too often, those insights end up trapped in PDF reports, disconnected from the tools and processes that... READ ARTICLE
Master Pentest Reporting: Join the 2025–2026 Penetration Testing Report Writing Bootcamp In July 2025 we kicked off our first Penetration Testing Report Writing Bootcamp at BSIDES Albuquerque after hearing prospects and customers share a common pain point: There just aren’t many opportunities for continuing education in the security reporting space. It’s not that courses on report writing don’t exist, but most are either entry-level refreshers or... READ ARTICLE