01Trust Score

Perplexity

Conditional Proceed

Week 2026-W22 May 27, 2026 Vendor-Neutral
45 /100 Notable Concerns
3.2/5 (5646)
↓ PDF Report
WHY THIS SCORE

The overall trust score of 60 reflects a balanced assessment. The security and compliance aspects are strong, contributing positively with a score of 25 out of 25 for security and 35 out of 35 for compliance. However, the legal/IP score is 0 out of 25, indicating significant concerns regarding intellectual property and contractual terms. The market score is also 0 out of 15, suggesting a lack of strong positive market signals or a presence of negative ones that offset any positives.

AUDITOR SUMMARY
From a CISO's perspective, Perplexity's Enterprise offerings present a compelling security and compliance profile, boasting SOC 2 Type II, GDPR, and HIPAA certifications, coupled with robust features like SSO, MFA, and audit logs. The commitment to 'no training on customer data' for enterprise tiers is a significant advantage, addressing a primary concern for data-sensitive organizations. The establishment of an EU legal entity further demonstrates a proactive approach to global data protection regulations.
Trust Score 45/100 CONDITIONAL
Est. Annual Cost 58000 100 users / yr
Top Risk MED Operational Reliability for Pro Users Overall: Medium
Priority Action Prioritize investigation and resolution of Pro subscription performance and data loss issues. ↓ PDF  · TCO  · Hardening
Enterprise: DPA: Unknown · Residency: Unknown · Lock-in: Medium (50/100)

Verified Compliance Facts

Cited and timestamped — every claim traceable to an official vendor source.

GDPR
Not yet verified
No citation Checked: May 28, 2026 ⏳ Claimed
HIPAA
Not yet verified
No citation Checked: May 28, 2026 ⏳ Claimed
ISO/IEC 27001
Not yet verified
No citation Checked: May 28, 2026 ⏳ Claimed
SOC 2
Not yet verified
No citation Checked: May 28, 2026 ⏳ Claimed

Enterprise Verdict

! Conditional Approval
Risk: Medium Confidence: medium 50 sources

Conditional Proceed

Perplexity offers robust AI search capabilities with strong enterprise-tier compliance certifications, but community reports indicate significant issues with Pro subscription performance, data loss, and customer support. Addressing these operational and support deficiencies is critical for broader enterprise adoption.
Key Strength

Robust enterprise-grade compliance certifications (SOC 2 Type II, GDPR, HIPAA with BAA).

Top Risk

Critical performance degradation and data loss reported by Pro subscribers.

Priority Action

Prioritize investigation and resolution of Pro subscription performance and data loss issues.

This report updates every week. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
02Top Risks

Risk Assessment

Seven-category enterprise risk analysis derived from community and vendor signals. Each card shows the evidence tier and the underlying finding.

Medium Operational Reliability for Pro Users Community Data

Medium risk posture identified. Derived from aggregated community data.

Medium Customer Support Deficiencies Community Data

Medium risk posture identified. Derived from aggregated community data.

Medium Data Privacy for Individual Tiers Community Data

Medium risk posture identified. Derived from aggregated community data.

Medium Intellectual Property Ambiguity Community Data

Medium risk posture identified. Derived from aggregated community data.

Medium Limited EU Data Residency Community Data

Medium risk posture identified. Derived from aggregated community data.

High Reliability Community Data

Public documentation buyers may want to verify availability of specific uptime commitments or reliability history.

Medium Cost Predictability Community Data

Enterprises should negotiate fixed-rate contracts and monitor pricing changes for overage risks.

High Vendor Lock-in Community Data

Data export status unclear. Integration score: 75/100. Webhooks available, reducing lock-in risk.

Medium Support Quality Community Data

Insufficient public community reviews to verify support quality. Standard support channels (email/documentation) are assumed.

Medium Data Privacy Community Data

Compliance score: 100/100. GDPR status: dpa_available. Encryption at rest: yes.

Low Compliance Posture Community Data

SOC 2: type_ii. ISO 27001: certified. Overall compliance score: 100/100.

Medium AI Transparency Verified

No training on user data detected. Code ownership terms unclear. Legal/ToS risk score: 65/100.

Verified — Confirmed by vendor documentation Community — Derived from community reports

Due Diligence Alerts

Priority reviews, recommended inquiries, and verified strengths — based on 84+ community data points

Recommended Inquiry Critical Critical Data Loss and Support Failure for Pro Subscribers

Multiple community reports highlight instances of Perplexity Pro users losing significant conversation history, coupled with unresponsive and unhelpful customer support that denies compensation. This poses a severe risk to data integrity and user trust.

Sources: Web
Recommended Inquiry High Performance Degradation of Pro Subscriptions

Community discussions indicate a noticeable decline in the performance of Perplexity Pro, with users experiencing shallower responses, prompt interruptions, and general lag, potentially due to resource constraints or server overload from widespread free Pro access.

Sources: Web
Recommended Inquiry Medium Default Data Training for Non-Enterprise Tiers

For Free, Pro, Max, and Education Pro tiers, user data is used for AI training by default, requiring manual opt-out. This default setting may lead to unintended data usage for users unaware of the policy, posing privacy risks.

Sources: Web
Recommended Inquiry Medium Unclear Model Output Copyright and User Indemnification

Perplexity's terms of service do not explicitly assign copyright ownership of AI-generated output, and users are required to indemnify the company for various claims, including those related to user content. This creates legal ambiguity and potential liability for enterprise users.

Sources: Web
03Security & Compliance

Security & Compliance

SOC 2 ~ Active (unverified link) ⚠ Dead link
GDPR ~ DPA (unverified link) ⚠ Dead link
HIPAA ~ BAA (unverified link) ⚠ Dead link
FedRAMP ⏳ In Progress
ISO 27001 ✓ Certified

External Registry Verification

Data Security

Encryption (At Rest): AES-256
Encryption (In Transit): TLS 1.2

Security Features

SSO SAML
MFA TOTP
Audit Logs 90 days

Enterprise Contract Intelligence

DPA availability, data residency, and contract risk signals for procurement teams

DPA: Unknown Residency: Unknown Lock-in: Medium (50/100)
📄 Data Processing Agreement Unknown

A Data Processing Addendum (DPA) is available, and it includes Standard Contractual Clauses (SCCs) for Enterprise tiers, supporting GDPR compliance. However, the deletion timeline for data is undisclosed.

🌐 Data Residency Unknown

Data residency options for Perplexity are not publicly documented. EU-regulated buyers should request written confirmation of data storage location and applicable transfer mechanisms (SCCs/adequacy decision) before signing.

⚠️ Contract Risk Medium Lock-in (50/100)
Notice: 30 days
⚠ 1 contract risk flag — click to review
⚠ Auto-renewal terms and data export rights not publicly documented — verify before signing.

Full contract terms for Perplexity require direct vendor engagement. Ensure data portability on exit, notice period, and pricing lock clauses are negotiated before execution.

Compliance & Document Matrix

🛡️ Security Certifications

Certification Status Auditor Valid Until Source
SOC 2 Type II ✅ Active View

🔒 Data Privacy Documents

Document Status URL AI Assessment
Sub-processors ❌ Not Found Link ❌ Not found
AI/Model Training Policy ❌ Not Found — Unclear
Data Retention Policy ❌ Not Found ❌ Not found
Data Flow Diagram ❌ Not Found
GDPR Compliance Statement ❌ Not Found ❌ Not found
KVKK Compliance Statement ❌ Not Found ❌ Not found
CCPA Compliance Statement ❌ Not Found ❌ Not found

⚖️ Legal Contracts

See Legal & IP Assessment section above for full analysis of ToS, DPA, MSA, SLA, EULA, and AUP.

🔧 Operational Readiness

Document Status URL AI Assessment
Business Continuity Plan (BCP) ❌ Not Found ❌ Not found
Disaster Recovery Plan (DRP) ❌ Not Found ❌ Not found
Incident Response Plan ❌ Not Found ❌ Not found
3rd Party Penetration Test ❌ Not Found ❌ Not found

📋 Technical Transparency

Document Status URL AI Assessment
SBOM ❌ Not Found ❌ Not found
OSS License Inventory ❌ Not Found ❌ Not found
Vulnerability Management Policy ❌ Not Found ❌ Not found
Patch Management Policy ❌ Not Found ❌ Not found
Offboarding / Data Export Guide ❌ Not Found ❌ Not found
SIG Questionnaire ❌ Not Found
CAIQ ❌ Not Found

💰 Financial Resilience

Item Status Details
Cyber Liability Insurance ❌ Not Found ❌ Not mentioned
TCO Disclosed ✅ Available Annual: 58000
New risk signals detected weekly. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
04Community Signals

Community Intelligence

Recurring issues and curated signals from GitHub, Hacker News, Reddit, Stack Overflow, web sources, and enterprise review platforms.

Intelligence Synthesis

Perplexity is gaining traction as an AI-powered search alternative, with Hacker News users praising its ability to cover complex queries and some even replacing Google entirely. However, Reddit discussions reveal significant dissatisfaction among Pro subscribers due to performance degradation, lost conversation history, and unresponsive customer support. Official documentation and third-party reviews confirm strong enterprise-level compliance, including SOC 2 Type II, GDPR, and HIPAA with BAA, alongside a clear pricing structure for various tiers.

Recurring Issues

Pro Subscription Performance Degradation 🟠 Community 1 mentions high ↗ Worsening

Enterprise Impact: For enterprise users considering Pro plans for individual teams, this indicates potential unreliability and reduced productivity, undermining the value proposition of a paid subscription.

Perplexity should investigate and address the resource constraints affecting Pro subscriptions, potentially by scaling infrastructure or adjusting free license distribution to ensure consistent performance for paying customers.

Sources: Reddit
Data Loss and Inadequate Customer Support 🟠 Community 1 mentions critical ↗ Worsening

Enterprise Impact: Loss of critical conversation history and unresponsive support poses a severe risk to data integrity and operational continuity for any enterprise relying on the tool as a 'second brain' or for important research.

Perplexity must implement robust data backup and recovery mechanisms, establish clear data retention policies, and significantly improve customer support responsiveness and compensation policies for data loss incidents.

Sources: Reddit
Opaque Data Retention and Training Policies for Non-Enterprise Tiers 🟠 Community 1 mentions high → Stable

Enterprise Impact: For departments or employees using non-enterprise tiers, the default 'ON' data training and undisclosed retention periods create privacy and compliance risks, especially when handling sensitive information.

Perplexity should make data training opt-out the default for all tiers and clearly publish data retention policies to enhance transparency and user trust.

Sources: Web
User Indemnification and Undisclosed Output Copyright 🟠 Community 1 mentions medium → Stable

Enterprise Impact: The requirement for users to indemnify the company, coupled with unclear ownership of AI-generated output, creates legal exposure for enterprises regarding intellectual property and potential third-party claims.

Perplexity should clarify model output copyright assignment and consider offering IP indemnification to enterprise clients to mitigate legal risks.

Sources: Web
Bug: 'Something went wrong, please try again...Retry' on Android app 🟠 Community 1 mentions medium ↗ Worsening

Enterprise Impact: This bug can disrupt mobile productivity for users relying on the Android app, leading to frustration and potential delays in accessing information or continuing conversations.

Perplexity should prioritize fixing recurring bugs in its mobile applications to ensure a stable and reliable user experience across all platforms.

Sources: Reddit
Perplexity Pro phone number verification issues 🟠 Community 1 mentions medium ↗ Worsening

Enterprise Impact: Users unable to verify their phone numbers for Pro access can experience service interruptions, impacting their ability to utilize paid features and potentially leading to lost productivity.

Perplexity needs to improve its phone number verification system to ensure reliability and provide clear alternative verification methods or direct support for users facing issues.

Sources: Reddit
Security loophole for uploaded images 🟠 Community 1 mentions high → Stable

Enterprise Impact: A security loophole related to uploaded images could expose sensitive enterprise data, leading to privacy breaches and compliance violations.

Perplexity must immediately investigate and patch any identified security loopholes, especially those concerning user-uploaded content, and communicate remediation steps to users.

Sources: Web

Source Signals

05Financial Impact

Financial Impact Panel

Cost intelligence and pricing signals for enterprise procurement decisions

Switching Cost Estimate High, due to potential loss of historical data and the effort required to migrate workflows to an alternative AI search platform, especially for users who rely on Perplexity as a 'second brain'.
Subscription-based per user/seat, with free and individual tiers also available. Free tier available

Free (Standard)

Pro (Individual)

Max (Individual)

Enterprise Pro

Enterprise Max

Education Pro

Pricing data from public sources — enterprise rates differ. Verify with vendor.

TCO Calculator

Calculate the real monthly cost for your team. Adjust seats, usage, and pricing tier below.

Estimated Monthly Cost

Base Subscription $0
AI Credits / Tokens $0
Hidden Costs (onboarding, overages, support) $0
Total Monthly TCO $0
Per User / Month $0
Annual Projection $0

Estimated Annual TCO — 100 Users ±20% confidence band

SMB / Pay-as-you-go
$0 – $0 /yr
Midpoint: $0
Assumptions
  • Free tier used as SMB baseline.
Mid-market / Per-seat
Pricing not disclosed
Assumptions
  • Pricing not publicly disclosed — contact vendor for quote.
Enterprise / Provisioned
Pricing not disclosed
Assumptions
  • Pricing not publicly disclosed — contact vendor for quote.

Estimates from publicly scraped pricing data.

Don't evaluate blind next quarter. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.

Synthesized from 20+ independent public sources: developer forums & repositories, security databases, vendor disclosures, regulatory filings, and community review platforms. Not affiliated with any vendor. Corrections?

Download PDF Report

Create a free account to download the full enterprise audit PDF.

Sign up — it's free →

Already have an account? Log in