perplexity.ai

Featured in our Forbes AI 50 security study: see how perplexity.ai compares with the other 49 →
A-
Trust rating
Excellent · 92/100
Procurement snapshot
No critical findings. The 4 remaining items are configuration gaps, not architectural problems.
Strengths
MX Records & Mail Provider
TLS Configuration
Cookie Security
security.txt (RFC 9116)
Questions to ask
Confirm MTA-STS rollout plans for inbound email
Sign in to see 1 more
Estimated remediation effort: 1–4 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change 1 scan · Last scanned September 28, 2026
Score
100 75 50 25 0
A-
perplexity.ai
92/100
Compliance & Certifications
Not yet verified
SOC 2 TYPE II
SOC 2 Type II
Audit report not on file
3rd party · AICPA
ISO 27001
ISO 27001
Certificate not on file
3rd party · accredited body
GDPR
GDPR
DPA not on file
Self-reported
CCPA
CCPA
Privacy policy not on file
Self-reported
Incident History
No public breaches on record
Security Posture
4 items need attention
11 passed
Protect incoming email from downgrade attacks (MTA-STS)
MTA-STS & TLS Reporting
2–4 hours Medium

This allows inbound email to be silently downgraded and intercepted without warning. This is a more advanced setting — skip it if you're not sure, and come back once the items above are handled. perplexity.ai has no MTA-STS policy, which means an attacker positioned on the network path could silently downgrade incoming email from encrypted to unencrypted, with no warning to either side.

How to fix this
1This one usually needs a developer or your hosting provider's support team — it involves publishing a small text file on your website, not just a DNS record.
v=STSv1; id=20260101000000
version: STSv1 mode: testing mx: mail.perplexity.ai max_age: 604800
2Add a TXT record with the name "_mta-sts" in your DNS settings (you're using Google Workspace — see https://knowledge.workspace.google.com/admin/security/set-up-dkim) (id= just needs to be any unique short code you make up, e.g. today's date), with this value:
3Host a small policy file at https://mta-sts.perplexity.ai/.well-known/mta-sts.txt with the content below.
4Start in "testing" mode for a couple of weeks, check the reports, then switch to "enforce".
Report unlocked.
View all 11 passed checks
MX Records & Mail Provider
TLS Configuration
Cookie Security
security.txt (RFC 9116)
HSTS Header
Subprocessors & Tech Stack
CVE Exposure
TLS Protocol Support
Known Breaches
DMARC / Email Security
Certificate Hygiene
Couldn't check: Malware / Phishing Blocklist — the check didn't complete (the site blocked or timed out our scanner, or a data source was unavailable), so this isn't counted in the score.
Company Signals
Operational risk
Last funding
Employees
Trust Resources
Claim profile →
Trust Center
Not detected
Security contact (security.txt)
perplexity.ai/.well-known/security.txt
Privacy Policy
DPA (Data Processing Agreement)
Subprocessors List
Similar companies
Appears in
Vendors graded A
377 companies · LynxRadar ranking
Top 10% by security score
287 companies · LynxRadar ranking