Welcome to Pinecone's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.
Subprocessors
Subprocessors
Security Grades
Security Grades
We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.
ISO
We are thrilled to announce that Pinecone has successfully completed our annual ISO 27001:2022 surveillance audit, ensuring our certification remains fully active! This ongoing milestone underscores our unwavering commitment to providing the highest standards of information security for our valued customers year after year. Passing this audit validates that Pinecone continues to uphold and actively manage rigorous, industry-leading security controls to safeguard your data. For complete transparency, you can verify our active certification status using the certificate number via the IAF CertSearch database.
Axios Supply Chain Attack
Pinecone is aware of the recent supply chain attack targeting the axios NPM package. Following a comprehensive audit of our infrastructure and dependencies, we have confirmed that Pinecone is not affected. We have successfully deployed monitoring capabilities and detection logic specifically designed to identify these compromised versions. We are actively scanning our environments to prevent any potential impact on our services or customers.
SOC2 Update
We are proud to announce the successful completion of our 2025 SOC 2 Type II audit, which confirmed that our security, availability, and confidentiality controls operated with zero deviations. This milestone reinforces our commitment to providing a secure and reliable vector database for your production applications. The full report is now available for review in our safety center.
Shai-Hulud
Pinecone is aware of the ongoing Shai-Hulud and Shai-Hulud 2.0 worm campaigns targeting the NPM ecosystem. Following a comprehensive audit of our infrastructure and dependencies, we have confirmed that Pinecone is not affected.
We have successfully deployed monitoring capabilities and detection logic specifically designed to identify this worm. We are actively scanning for compromised packages to prevent any impact on our services or customers.
Pinecone response to Salesloft/Drift Breach
Pinecone completed an internal investigation and confirmed that we have never installed or used any Salesloft integration.
We will continue to monitor our vendor supply chain to assess any potential indirect impact.


