Vendor AssessmentsPerplexity
Perplexity
Retrieval-augmented · last assessed Q3 2025 · next due —
RestrictedRisk High · 58
Models & services in use
- No model dependency.
Vendor due-diligence questionnaire
Auto-populated from public disclosures · gaps flagged for human input
- Data residency commitments documentedYes — us-east-1, eu-central-1 (Anthropic Workspace)
- EU AI Act provider obligations publishedYes — public Trust Center
- DORA ICT third-party documentationOn file — DPA addendum signed Mar 2026
- FREE-AI BFSI vendor disclosureAuto-collected — no material gaps
- Sub-processor list availableYes — published quarterly
- Model deprecation policy12-month notice; LTS releases identified
- Incident notification SLA≤ 24h for material incidents
- Data isolation guaranteesPer-workspace encryption, no training on customer data
Trust Lab-conducted assessments
- PassPre-approval eval — claude-3-5-sonnetFinanceBench 78.4% · IndicSafe 91.2%
- PassPre-approval eval — claude-3-5-haikuFinanceBench 71.8%
- Pass with mitigationsFrontier red-team — claude-3-5-sonnet (OWASP+ATLAS)12 successful probes; mitigated via prompt + RAG hardening
- In progressCapability evaluation — claude-3-7-sonnet (in eval)Pre-approval policy v4 active
Continuous monitoring
- Apr 9 · Anthropic published updated sub-processor list — auto-diff: no material change.
- Mar 28 · claude-3-7-sonnet released — pre-approval policy v4 auto-triggered.
- Mar 18 · Quarterly assessment refresh — Approved through Q3 2026.