Coalfire

Coalfire

Search the Trust Center...
Ctrl +K

Coalfire | Trust Center

Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence. Our Trust Center is regularly updated to reflect the latest audit results, and subprocessor disclosures.

Quick links

Badges

iso-9001
ISO 9001
iso-27701
ISO 27701
gdpr
GDPR
ccpa
CCPA

Our Philosophy

As a cybersecurity company, we work hard to improve the cybersecurity of our clients. But, we must also lead by example, and we are not immune to cybersecurity threats. Coalfire takes the security of our organization and customer data with the utmost priority and has built a strong information security program to see that our mission is safeguarded against these threats.

Coming Soon

The Coalfire Cybersecurity team and DivHex is finalizing certification to the CyberEssentials Plus standards.

Quick Summary

One or more annual third-party audit(s)

Has a formal mobile device management (MDM) program

Annual third-party penetration testing

Has a disaster recovery plan

Has cyber insurance

Will enter into a DPA

Deletes customer data on request

Has an API available

Uses a centralized IAM solution (SSO) to manage employee access

Has a privacy policy

Documents & Knowledge Base FAQs

Announcements

Coalfire SOC2 Type 2 for 2026

Coalfire has released our newest SOC2 Type 2 report covering the examination period of 3/1/2025 - 2/28/2026.

Coalfire Trust Portal

Coalfire's new trust and assurance portal is live! In this portal you will find a number of resources that demonstrate Coalfire's diligence to organizational governance, compliance, security, and privacy. Please reach out with any questions you might have.

What we offer

Compliance Essentials

Coalfire Compliance Essentials is a SaaS platform enterprises use to manage complex compliance programs and audit
cycles. The platform incorporates over 20 years of compliance advisory and audit expertise, providing compliance teams
with continuous visibility to constantly changing controls and evidence requirements. It enables evidence-based mapping
and coordinated assessments for over 75 frameworks utilizing our proprietary controls mapping. Compliance Essentials
helps companies achieve compliance up to two times faster than competing platforms by aligning efforts across
programs to reduce the duplication of requests and improve evidence collection and workflow.

Typical data access: No direct access to your data, systems, or services is required. Data is provided to Compliance Essentials by your organization's assessment users.

Certifications: ISO 27001:2022, ISO 27701, SOC 2 Type 2

Hexeon

Launched this year, the Hexeon platform enhances the traditional penetration testing model by intertwining high-frequency offensive pen testing with strategic defensive risk management. This dual-focused approach orchestrates a synchronized, continuous exploration and management of vulnerabilities, veering away from the conventional, snapshot-based methodologies that have proven insufficient in the contemporary digital ecosystem.

Hexeon melds a platform-fueled customer experience with advanced analytics into a singular, potent approach to offensive security, translating complex data into actionable insights and facilitating custom risk mitigation for customers.

Typical data access: Hexeon uses data collected by Coalfire offensive security teams, such as penetration testing findings, vulnerability data, and other data concerning technical risk.

Certifications: ISO 27001:2022, ISO 27701, SOC 2 Type 2

General Advisory, Audit, and Assessment Services

Our general Advisory, Audit, and Assessment services cover the professional services layer of Coalfire. These services may or may not leverage the Hexeon or Compliance Essentials products.

Advisory Services
Specializing in GRC, AI cloud engineering, healthcare risk and FedRAMP, our Advisory expertise and governance is trusted throughout even the most complex and highly regulatory environments. We listen, investigate and advise to anticipate, adapt and cut through inefficiency. Creating bespoke solutions that implement security first – across all frameworks – to help you meet and exceed diverse requirements quickly, effectively and with complete and utter confidence.

Audit and Assessment
Our Audit and Assessment services tackle the world’s toughest, most complicated compliance challenges. Analyzing, automating and streamlining them through our mastery of expedited compliance protocols. With expertise across PCI DSS, HITRUST, ISO, FedRAMP and 85+ frameworks, we assess, simplify and provide guidance through rigorous attestations and certifications. All, to empower you with the support and tools needed to meet objectives, simplify and synchronize processes and confirm system readiness.

Security
DivisionHex marks the evolution of Coalfire – going beyond compliance to tackle the threats compliance alone can’t stop. We hand-picked a team of offensive, defensive and managed cybersecurity experts to close the gap between compliance and achieving full security on all sides.

Typical data access: These services typically interact with the aspects of your organization's IT and Information Security Program. These documents include security and HR policies, technology architecture, and written processes/procedures.

Certifications: ISO 27001:2022, ISO 27701, SOC 2 Type 2

Featured Documents

Subprocessors16

Subprocessor
Location of Processing
Usage Details
Atlassian Jira

Atlassian Jira

United States
Customer support and ticketing system for Compliance Essentials and Hexeon.
AWS

AWS

United States
Infrastructure as a service for our Hexeon and Compliance Essentials products, as well as infrastructure for DivisionHex and Cloud Management teams.
B

Box

United States
Document management, document storage, and data retention.
Contrast Security

Contrast Security

United States
Interactive application security testing to identify flaws within code at runtime.
Cyera

Cyera

United States
Data security posture management (DSPM) service that monitors data-at-rest repositories for compliance against organizational security standards.
Ironclad

Ironclad

United States
Contract management and collaboration.
Lumos

Lumos

United States
Identity Governance and Administration, privileged identity management.
Microsoft

Microsoft

United States
Microsoft O365, AzureAD, and Entra SSO/IAM.
MongoDB

MongoDB

United States
Relational database management system (RDBMS) backend for Compliance Essentials.
Netskope

Netskope

United States
Cloud access security broker (CASB) for monitoring user cloud activity.
NetSuite

NetSuite

United States
AP/GL supporting core accounting and finance processes.
PlexTrac

PlexTrac

United States
Aggregation of penetration testing findings and reporting.
Proofpoint

Proofpoint

United States
Email security gateway (ESG) for Coalfire corporate email..
Salesforce

Salesforce

United States
Sales customer relationship management and order processing.
SonarQube

SonarQube

United States
Static analysis security testing for Coalfire application code and product development.
Splunk

Splunk

United States
Security Event Information Management (SEIM) for log aggregation, analysis, and security event alerting.
Last updated . .
View as:
Powered by Conveyor, the first end-to-end customer trust platform.
Learn more