Executive Summary
AI-generated analysis for Perplexity
Perplexity (perplexity.ai) is an AI-powered search and research platform assessed at Tier 3 (Moderate Risk), reflecting a vendor with meaningful technical strengths offset by a pattern of legal, compliance, and transparency concerns that require active attention before enterprise deployment. On the positive side, Perplexity presents several credible security signals:
Key Findings
- The domain has been established since 2022 with a clean blacklist status across SURBL, Spamhaus DBL, and Malware detection service
- Infrastructure is protected by Cloudflare CDN with zero known CVEs and a valid TLS 1.3 certificate using AES-256-GCM encryption
- The vendor maintains a dedicated trust portal (trust.perplexity.ai) and claims SOC 2, HIPAA, GDPR, PCI DSS (SAQ A), and FedRAMP 20x compliance
- HTTP security headers earned a grade of B (75/100) from independent scanning, indicating a generally well-configured web environment
- No sanctions matches were identified across OFAC, EU, and UN watchlists However, several concerns and gaps require resolution before this vendor can be approved for medium data access:
- A court order to suspend Perplexity's AI agent for Amazon purchases represents active legal enforcement against its core agentic product capabilities
- Hacker News community discussions surface a high-engagement pattern of legal and compliance issues, including a copyright infringement lawsuit by Yomiuri Shimbun, allegations of stealth web crawlers evading robots.txt directives, and a reported CEO statement about comprehensive user tracking for advertising purposes
- All five compliance certifications (SOC 2, PCI DSS, FedRAMP, HIPAA, GDPR) are vendor-attested only — none could be independently verified through public registries
- No publicly accessible AI data usage policy was found, which is a notable gap for an AI-first vendor with medium data access
- The subprocessor page at trust.perplexity.ai/subprocessors contains placeholder content, preventing supply chain due diligence Overall, Perplexity is an active, well-funded AI platform with real compliance investment, but the volume of unresolved legal actions, data transparency gaps, and unverified certifications collectively justify a conditional approval posture pending resolution of the requirements listed below.
Independence Statement
All evidence in this report was independently sourced from external data providers, public registries, threat intelligence feeds, and archived media without any participation, input, or review by Perplexity or its representatives.