Security, compliance, and transparency — all in one place. We are committed to protecting your data and meeting the highest industry standards. Explore our certifications, reports, and security practices.
Download our latest audit reports and certifications. Some documents require a brief form submission to ensure proper handling of sensitive information.
Our SOC 2 Type II audit verifies that Paessler's controls meet rigorous standards for security, availability, and confidentiality over a sustained period.
SO 27001 is the international standard for information security management systems (ISMS). Our certification demonstrates systematic risk management and continuous improvement.
ISO 9001 certification demonstrates our commitment to quality management excellence. Our processes are designed to consistently deliver high-quality products and services while continuously improving.
Paessler complies with the EU General Data Protection Regulation (GDPR), ensuring that your data is processed lawfully, transparently, and securely.
Data privacy isn't just a legal requirement. It's foundational to how we build and operate our products. Here's how we protect your information:
We use industry-standard encryption protocols (TLS 1.2+) to protect data during transmission, and encrypt sensitive data at rest.
Granular permissions ensure that only authorized users can access monitoring data and configuration settings.
Host PRTG on-premises or choose cloud regions that meet your compliance and data residency requirements.
We collect only the data necessary to deliver our services. You retain full control over what gets monitored and how data is stored.
Our infrastructure and processes are audited annually by independent third parties to ensure ongoing compliance.

Chief Information Security Officer
Jay Miller leads Paessler's cybersecurity strategy and compliance program as Chief Information Security Officer. With extensive experience in security operations, risk management, and team leadership, he oversees the company's information security management system (ISMS) and drives continuous improvement of our security posture.
Paessler has a Vulnerability Disclosure Program (VDP) to review questions related to product vulnerabilities. If you have a potential vulnerability or bug to disclose to Paessler, or you have security questions related to our products, please contact us.
Please send an email to [email protected]
A Technical Support representative will get in touch with you very quickly to discuss your question or finding. We will also validate your finding and provide feedback, working with you to ensure responsible and transparent disclosure.
Please send a notification email without encryption to ensure successful receipt to our team.
Paessler does not have a bug bounty program and does not pay a bug bounty for submissions.
SOC 2 Type II is an audit framework developed by the American Institute of CPAs (AICPA) that evaluates a service provider's controls for security, availability, and confidentiality over a sustained period (typically 6-12 months). It provides assurance to customers that our security controls are not only designed effectively but also operate effectively over time.
Yes. Due to the sensitive nature of the report, we require a brief information request form. Once submitted, we'll send you the latest report via email or secure link.
Yes. Paessler complies with GDPR requirements. PRTG can be deployed on-premises (giving you full data control) or in cloud environments that meet GDPR data residency and processing standards. We also provide Data Processing Agreements (DPAs) upon request.
Our SOC 2 and ISO 27001 certifications are audited annually by independent third-party auditors.
We currently operate a coordinated Vulnerability Disclosure Program (VDP). Researchers can report security issues to [email protected]. We're evaluating a formal bug bounty program for the future.
If you're using PRTG on-premises, your data stays on your infrastructure. If you're using Paessler's cloud offerings, you can choose data center regions to meet your compliance and residency requirements.
We have a documented Incident Response Plan that includes detection, containment, investigation, remediation, and communication protocols. In the event of a security incident affecting customer data, we will notify affected customers promptly in accordance with legal and contractual obligations.
Yes. Please contact our Sales or Security team at [email protected], and we'll work with you to provide the documentation you need.
Our Security and Compliance team is here to help with custom documentation requests, security questionnaires, or compliance discussions.