Last updated: July 2026
This Information Security Exhibit (“ISE”) sets forth the administrative and technical safeguards Splunk takes to protect Confidential Information as part of its Information Security Program (“ISP”). Splunk may update this ISE from time to time to reflect changes in Splunk’s ISP, provided such changes do not materially diminish the level of security herein provided.
This ISE is made a part of your Splunk General Terms (“Agreement”) with Splunk, a Cisco company. Any capitalized terms used, but not defined herein, shall have the meaning set forth in the Agreement. In the event of any conflict between the terms of the Agreement and this ISE, the terms of this ISE will apply. This ISE does not apply to Third-Party Content purchased or acquired through Splunk.com, to any Evaluation or Free Software, or to any Extensions.
Splunk’s Hosted Services (including without limitation Splunk’s hybrid services, which are cloud enabled Offerings for On-Premise Products) include their own security provisions as applicable. Please reference the Specific Hosted Services Terms and Splunk Protects for security information regarding Hosted Services. This ISE does not apply to the security of Hosted Offerings.
During the Term of the Agreement, Splunk agrees to maintain an ISP in conformance with the requirements set forth below.
1. Splunk’s Information Security Program and Security Program Office
1.1.Splunk’s ISP is reasonably designed to help protect the confidentiality, integrity, and availability of Confidential Information against any anticipated threats or hazards; unauthorized or unlawful access, use, disclosure, alteration, or destruction; and accidental loss, destruction or damage.
1.2. Splunk’s ISP contains technical and organizational measures that are appropriate to: (i) the nature, size, and complexity of Splunk’s business; (ii) the resources available to Splunk; (iii) the type of information that Splunk stores; and (iv) the need for security and confidentiality of such information.
1.3. Splunk’s Chief Information Security Officer leads Splunk’s ISP and develops, reviews and approves (together with other stakeholders, such as Product Security, Legal and Internal Audit) Splunk Security Policies (as defined below).
2. Security Policies and Procedures
2.1. Splunk maintains information security, use and management policies (collectively “Security Policies”) designed to educate employees and contractors regarding appropriate use, access to and storage of Confidential Information; restrict access to Confidential Information to members of Splunk’s workforce who have a “need to know” such information; prevent terminated employees from accessing Splunk information and information systems post-termination; and imposing disciplinary measures for failure to abide by such policies. Where feasible and as applicable, Splunk endeavors to align its Security Policies to ISO 27001 level standards for information security.
2.2. Splunk Security Policies are available to employees via the corporate intranet. Splunk reviews, updates and approves Security Policies at a minimum of at least once annually to maintain their continuing relevance and accuracy.
3.1. Splunk employs monitoring and logging technology to help detect and prevent unauthorized access attempts to its networks and production systems. Splunk’s monitoring includes a review of changes affecting systems’ handling authentication, authorization, and auditing; and privileged access to Splunk production systems. Splunk uses the principle of “least privilege” (meaning access denied unless specifically granted) for access to customer data.
4. Threat and Vulnerability Management
4.1. As part of its threat and vulnerability management program (“TVM”), Splunk:
4.1.1. monitors for vulnerabilities in supported versions of the Software that are acknowledged by vendors, reported by researchers or discovered internally;
4.1.2. verifies vulnerabilities, rates them according to industry-standard ratings systems, and identifies them for mitigation or fixes based on severity level;
4.1.3. issues mitigations or fixes in minor and major product releases, as part of its maintenance program, which may include cumulative fixes for certain vulnerabilities; and
4.2. Splunk regularly performs vulnerability scans and addresses detected vulnerabilities on a risk basis. Periodically, Splunk performs vulnerability assessments,penetration testing and threat modeling.
5. Incident Response Plan and Breach Notification
5.1. Splunk has an incident response plan and team to assess, respond, contain and remediate (as appropriate) identified security issues, regardless of their nature (e.g. cyber, product). Splunk reviews and updates the IR (Incident Response) plan annually to reflect emerging risks and “lessons learned.”
5.2. For Customers located outside the US, Splunk provides notice without undue delay after becoming aware of a Data Breach. As used in this ISE, Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Personal Data as defined under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) while being transmitted, stored or otherwise processed by Splunk. If Customer reasonably determines notification is required under GDPR, Splunk will provide reasonable assistance to the extent required, including assistance in notifying the relevant supervisory authority and providing a description of the Data Breach.
5.3.For Customers located within the US, Splunk provides notice of a breach of Personal Information, as defined under the California Consumer Privacy Act of 2018 (“CCPA”), as required under California law.
6. Storage and Transmission Security
6.1 Technical security measures to guard against unauthorized access to Customer data that is being transmitted over a public electronic communications network or stored electronically.
7.1 Policies and procedures regarding the disposal of tangible and intangible property containing Customer Confidential Information so that wherever possible, Customer Confidential Information cannot be practicably read or reconstructed.
8. Risk Identification and Assessment
8.1. Splunk employs a risk assessment program to help it reasonably identify foreseeable internal and external risks to Splunk’s information resources and determine if its existing controls, policies, and procedures are adequate to address the identified risks.
9.1. Splunk’s Software Development Life Cycle (“SDLC”) methodology governs the acquisition, development, implementation, configuration, maintenance, modification, and management of software components.
9.2. For major product releases, Splunk uses a risk-based approach when applying its standard SDLC methodology, which may include such things as performing security architecture reviews, open source security scans, dynamic application security testing, network vulnerability scans and external penetration testing in the development environment. Splunk performs security code review for critical features if needed; and performs code review for all features in the development environment.
9.3. Splunk utilizes a code versioning control system to maintain the integrity and security of application source code. Access privileges to the source code repository are reviewed periodically and limited to authorized employees.
9.4 As noted above, this ISA, including its SDLC methodology, does not apply to any Extensions (Customer’s or Splunk’s) or to Third- Party Content, including any made available on splunkbase.com. For information on the inspection process for applications available on splunkbase.com, see AppInspect.
For Cisco terms, please refer to the Cisco Trust Portal.