Criteo Security – Trust Overview

Our Commitment to Security

At Criteo, security is foundational to how we design, build, and operate our platform. We protect our systems and customer data through a multi-layered defense model that combines industry standards, independent audits, and a robust security culture embedded across the organization.

  • Security is designed into our products and infrastructure.
  • We maintain a proactive vulnerability management and incident response program.
  • Every employee is trained and accountable for security awareness.

Security & Compliance at a Glance

AreaStatusNotes
SOC 2 (Service Organization Control)CompletedIndependent audit validating controls relevant to security and confidentiality.
ISO/IEC 27001CertifiedInformation Security Management System (ISMS) certified, demonstrating systematic risk management.
Penetration TestingRegular AssessmentsConducted by third parties; results available within Trust Center documentation (on request).
Bug Bounty ProgramActiveManaged through private program; encourages ethical reporting of vulnerabilities.
Security Awareness & TrainingOrganization-wideMandatory ongoing security education and threat awareness programs.

Security Trust Center – Central Security Document Hub

What you’ll find

Our Security Trust Center is the central repository for security and compliance documentation, including:

  • SOC 2 Assurance Reports
  • ISO/IEC 27001 Certificate
  • Penetration Test Attestations

Link to Security Trust Center: http://security.criteo.com (hosted via SafeBase)

How to Access Security Documentation

The Trust Center allows you to:

  1. View & download public Assurance Reports
  2. Request access to private confidential artifacts
  3. Ask questions directly to our Security Team

Note: Access may require a signed NDA before private reports are delivered.

Governance & Risk Management

We follow a structured risk management methodology integrated into the product lifecycle and enterprise operations.

Technical Security Controls

Our platform is protected through:

  • Multi-layered perimeter and internal defenses
  • Encryption at rest and in transit
  • Least-privilege access models
  • Continuous monitoring and logging

Audit results for these controls are available on request via the Trust Center.

Vulnerability & Incident Practices

Bug Bounty Program

Criteo runs a private bug bounty program rewarding ethical contributions to our security. Participation is via invitation; contact security@criteo.com.

Vulnerability Disclosure Policy

Criteo maintains a responsible Vulnerability Disclosure Policy that enables security researchers and the public to report potential security vulnerabilities in a safe, ethical, and coordinated manner. Reports are reviewed by our Security Team, with validated vulnerabilities addressed based on their risk and severity. Public disclosure is coordinated only after appropriate remediation.

The complete Vulnerability Disclosure Policy is available through our Criteo Security Trust Center.

Penetration Testing

Regular external assessments are performed and the executive summaries or relevant documentation is published through the Trust Center.

Security Culture & Awareness

We believe that security is everyone’s responsibility:

  • Mandatory Cyber Security training for all employees
  • Awareness campaigns on emerging threats and best practices
  • Internal policies that govern secure development, access control, and operations

Reporting Security Concerns

If you identify a security issue or suspicious activity:

security@criteo.com
Include details, steps to reproduce (if applicable), and your contact information.