Effective Date: July 2026

SPLUNK CLOUD PLATFORM SECURITY EXHIBIT

 

This Splunk Cloud Platform Security Exhibit (CSE) sets forth the administrative and technical safeguards Splunk takes to protect Confidential Information, including Customer Content, in Splunk Cloud Platform (Security Program). Splunk may update this CSE from time to time to reflect changes in Splunk’s security posture, provided such changes do not materially diminish the level of security herein provided.

This CSE is made a part of your General Terms (Agreement) with Splunk, a Cisco company, and any capitalized terms used but not defined herein shall have the meaning set forth in the Agreement or Documentation, as applicable. In the event of any conflict between the terms of the Agreement and this CSE, this CSE will control. This CSE does not apply to Splunk Cloud Platform subscriptions purchased or acquired through Splunk.com, including without limitation Trial or Beta Services , or to on-premise component(s) of hybrid offerings.

1. Purpose

1.1 This CSE describes the information security standards that Splunk maintains to protect Confidential Information, including Customer Content, in addition to any requirements set forth in the Agreement.

1.2 The CSE is designed to protect the confidentiality, integrity and availability of Confidential Information, including Customer Content, against anticipated or actual threats or hazards; unauthorized or unlawful access, use, disclosure, alteration or destruction; and accidental loss, destruction or damage in accordance with laws applicable to the provision of the Service.

2. Splunk Security Program

2.1 Scope and Content. Splunk Security Program: (a) complies with industry recognized information security standards; (b) includes administrative, technical safeguards designed to protect the confidentiality, integrity and availability of Confidential Information, including Customer Content; and (c) is appropriate to the nature, size and complexity of Splunk’s business operations.

2.2 Security Policies, Standards and Methods. Splunk maintains security policies, standards and methods (collectively, Security Policies) designed to safeguard the processing of Confidential Information, including Customer Content, by employees and contractors in accordance with this CSE.

2.3 Security Program Office. Splunk’s Chief Information Security Officer (CISO) leads Splunk’s Security Program and the CISO Office develops, reviews and approves, together with appropriate stakeholders, Splunk’s Security Policies.

2.4 Security Program Updates. Splunk Security Program Policies are available to employees via the corporate intranet. Splunk reviews, updates and approves Security Policies annually to maintain their continuing relevance and accuracy. 

3. Risk Management

3.1 Splunk manages cybersecurity risks in accordance with its Risk Assessment Method, which defines how Splunk identifies, prioritizes and manages risks to its information assets and the likelihood and impact of them occurring.

3.2 Splunk management reviews documented risks to understand their potential impact to the business, determine appropriate risk levels and treatment options. Mitigation plans are implemented to address material risks to business operations, including data protection.

4. Change Management

4.1 Splunk deploys changes to the Services during maintenance windows, details of which are posted to the Splunk website or communicated to customers as set forth in the Splunk Cloud Platform Maintenance Policy.

4.2 Splunk follows documented change management policies and procedures for requesting, testing and approving application, infrastructure and product related changes.

4.3 Changes undergo appropriate levels of review and testing, including security and code reviews, regression testing and user acceptance prior to approval for implementation.

4.4 Software development and testing environments are maintained and logically separated from the production environment.

5. Incident Response and Breach Notification

5.1 Splunk notifies Customers without undue delay after becoming aware of a Data Breach. As used herein, Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Content under the applicable Agreement, including Personal Data as defined under the General Data Protection Regulation (EU) 2016/679 (GDPR), while being transmitted, stored or otherwise processed by Splunk.

5.2 In the event of a Data Breach involving Personal Data, if a customer reasonably determines notification is required by law, Splunk will provide reasonable assistance to the extent required for the Customer to comply with applicable data breach notification laws, including assistance in notifying the relevant supervisory authority and providing a description of the Data Breach.

5.3 In the event of a conflict between the breach notification provisions in this CSE and those set forth in an applicable Business Associate Agreement (BAA) with Splunk, the BAA breach notification terms will apply.

6. Governance and Audit

6.1 Splunk conducts internal control assessments on an ongoing basis to validate that controls are designed and operating effectively. Issues identified from assessments are documented, tracked and remediated as appropriate.

6.2 Third party audits are performed as part of our certification process (further below) to validate the ongoing governance of control operations and their effectiveness. Issues identified are documented, tracked, and remediated as appropriate.

7. Access and User Management

7.1 Splunk implements reasonable controls to manage user authentication for employees or contractors with access to Customer Content, including without limitation, assigning each employee or contractor with unique and/or time limited user authorization credentials for access to any system on which Customer Content is accessed and prohibiting employees or contractors from sharing their user authorization credentials.

7.2 Splunk allocates system privileges and permissions to users or groups on a “least privilege” principle and reviews user access lists and permissions to critical systems on a quarterly basis, at minimum.

7.3 New users must be pre-approved before Splunk grants access to Splunk corporate and cloud networks and systems. Pre-approval is also required before changing existing user access rights.

7.4 Splunk promptly disables application, platform and network access for terminated users upon notification of termination.

8. Password Management and Authentication Controls

8.1 Authorized users must identify and authenticate to the network, applications, and platforms using their user ID and password. Splunk’s enterprise password management system requires minimum password parameters.

8.2 Authorized users are required to change passwords at pre-defined intervals consistent with industry standards.

8.3 SSH key authentication and enterprise password management applications are utilized to manage access to the production environment.

8.4 Two-factor authentication (2FA) is required for remote access and privileged account access for Customer Content production systems.

9. Encryption and Key Management

9.1 Splunk uses industry-standard encryption techniques to encrypt Customer Content in transit. The Splunk System is configured by default to encrypt user data files using transport layer security (currently, TLS 1.2+) encryption for web communication sessions.

9.2 Splunk relies on policy controls to help ensure sensitive information is not transmitted over the Internet or other public communications unless it is encrypted in transit.

9.3 Where applicable, Splunk uses encryption at rest with a minimum encryption protocol of Advanced Encryption Standard (AES) 256-bit encryption.

9.4 Splunk uses encryption key management processes to help ensure the secure generation, storage, distribution and destruction of encryption keys.

10. Threat and Vulnerability Management

10.1 Splunk has a Threat and Vulnerability Management (TVM) program to continuously monitor for vulnerabilities that are discovered internally through vulnerability scans, offensive exercises, and employees; or externally reported by vendors, researchers or others.

10.2 Splunk documents vulnerabilities and ranks them based on severity level as determined by the likelihood and impact ratings assigned by TVM. Splunk assigns appropriate team(s) to conduct remediation and track progress to resolution as needed.

10.3 An external vendor conducts security penetration tests on the Splunk Cloud Platform environments annually to detect network and application security vulnerabilities. Findings from these tests are evaluated, documented and assigned to the appropriate teams for remediation based on severity level. In addition, Splunk conducts internal penetration tests quarterly on its Splunk Cloud Platform infrastructure and remediates findings as appropriate.

11. Logging and Monitoring

11.1 Monitoring tools and services are used to monitor systems across Splunk for application, infrastructure, network and storage events, performance and utilization

11.2 Event data is aggregated and stored using appropriate security measures designed to prevent tampering. Logs are stored in accordance with Splunk’s data retention policy.

11.3 Alerts are continuously reviewed and follows up on suspicious events as appropriate.

12. Secure Development

12.1 Splunk’s Software Development Life Cycle (SDLC) methodology governs the acquisition, development, implementation, configuration, maintenance, modification, and management of software components.

12.2 For major and minor product releases, Splunk uses a risk-based approach when applying its standard SDLC methodology, which includes such things as performing security architecture reviews, open source security scans, code review, dynamic application security testing, network vulnerability scans and external penetration testing. Splunk performs security code review for critical features if needed; and performs code review for all features in the development environment. 

12.3 Splunk utilizes a code versioning control system to maintain the integrity and security of application source code. Access privileges to the source code repository are reviewed periodically and limited to authorized employees.

12.4 The SDLC methodology does not apply to free Applications developed by Splunk or to Third Party Content, including any made available on splunkbase.com. For information on the inspection process for applications available on splunkbase.com, see AppInspect.

13. Network Security

13.1 Splunk uses industry standard technologies to prevent unauthorized access or compromise of Splunk’s network, servers or applications, which include such things as logical controls to segment data, systems and networks according to risk. Splunk monitors demarcation points used to restrict access such as firewalls and security group enforcement points.

13.2 Users must authenticate with two-factor authentication prior to accessing Splunk networks containing Customer Content.

14. Disaster Recovery Plan

14.1 Splunk has a written Disaster Recovery Plan to manage significant disruptions to Splunk Cloud Platform operations and infrastructure. Splunk management updates and approves the Plan annually.

14.2 Splunk personnel perform annual disaster recovery tests. Test results are documented and corrective actions are noted.

14.3 Data backup, replication, and recovery systems/technologies are deployed to support resilience and protection of Customer Content.

14.4 Backup systems are configured to encrypt backup media.

15. Asset Management and Disposal

15.1 Splunk maintains and regularly updates an inventory of Splunk Cloud Platform infrastructure assets and reconciles the asset list monthly.

15.2 Documented, standard build procedures are utilized for installation and maintenance of production servers.

15.3 Documented data disposal policies are in place to guide personnel on the procedure for disposal of Confidential Information, including Customer Content.

15.4 Upon expiration or termination of the Agreement, Splunk will return or delete Customer Content in accordance with the terms of the Agreement. If deletion is required, Customer Content will be securely deleted, except that Customer Content stored electronically in Splunk’s backup or email systems may be deleted over time in accordance with Splunk’s records management practices.

15.5 Splunk retains Customer Content stored in its cloud computing services for at least thirty (30) days after the expiration or termination of the Agreement.

16. CSE Proof of Compliance

16.1 Splunk Cloud Platform is routinely audited against multiple industry standards, regulatory requirements, or regional requirements (e.g., System and Organizational Control (SOC 2), Type 2 annually, Payment Card Industry Data Security Standards (PCI-DSS) annually, HIPPA, and more). To inquire about any specific certification go to Compliance at Splunk to see what certification you may request. To request a certification or get evidence of compliance or reassurance visit our Splunk Trust Portal.

 For Cisco terms, please refer to the Cisco Trust Portal.