Our Commitment to Security
At Criteo, security is foundational to how we design, build, and operate our platform. We protect our systems and customer data through a multi-layered defense model that combines industry standards, independent audits, and a robust security culture embedded across the organization.
- Security is designed into our products and infrastructure.
- We maintain a proactive vulnerability management and incident response program.
- Every employee is trained and accountable for security awareness.
Security & Compliance at a Glance
| Area | Status | Notes |
| SOC 2 (Service Organization Control) | Completed | Independent audit validating controls relevant to security and confidentiality. |
| ISO/IEC 27001 | Certified | Information Security Management System (ISMS) certified, demonstrating systematic risk management. |
| Penetration Testing | Regular Assessments | Conducted by third parties; results available within Trust Center documentation (on request). |
| Bug Bounty Program | Active | Managed through private program; encourages ethical reporting of vulnerabilities. |
| Security Awareness & Training | Organization-wide | Mandatory ongoing security education and threat awareness programs. |
Security Trust Center – Central Security Document Hub
What you’ll find
Our Security Trust Center is the central repository for security and compliance documentation, including:
- SOC 2 Assurance Reports
- ISO/IEC 27001 Certificate
- Penetration Test Attestations
Link to Security Trust Center: http://security.criteo.com (hosted via SafeBase)
How to Access Security Documentation
The Trust Center allows you to:
- View & download public Assurance Reports
- Request access to private confidential artifacts
- Ask questions directly to our Security Team
Note: Access may require a signed NDA before private reports are delivered.
Governance & Risk Management
We follow a structured risk management methodology integrated into the product lifecycle and enterprise operations.
Technical Security Controls
Our platform is protected through:
- Multi-layered perimeter and internal defenses
- Encryption at rest and in transit
- Least-privilege access models
- Continuous monitoring and logging
Audit results for these controls are available on request via the Trust Center.
Vulnerability & Incident Practices
Bug Bounty Program
Criteo runs a private bug bounty program rewarding ethical contributions to our security. Participation is via invitation; contact security@criteo.com.
Vulnerability Disclosure Policy
Criteo maintains a responsible Vulnerability Disclosure Policy that enables security researchers and the public to report potential security vulnerabilities in a safe, ethical, and coordinated manner. Reports are reviewed by our Security Team, with validated vulnerabilities addressed based on their risk and severity. Public disclosure is coordinated only after appropriate remediation.
The complete Vulnerability Disclosure Policy is available through our Criteo Security Trust Center.
Penetration Testing
Regular external assessments are performed and the executive summaries or relevant documentation is published through the Trust Center.
Security Culture & Awareness
We believe that security is everyone’s responsibility:
- Mandatory Cyber Security training for all employees
- Awareness campaigns on emerging threats and best practices
- Internal policies that govern secure development, access control, and operations
Reporting Security Concerns
If you identify a security issue or suspicious activity:
security@criteo.com
Include details, steps to reproduce (if applicable), and your contact information.