Pure Storage

Security and Compliance Assurance Packet

  • By Pure Storage
  • November 17, 2025

As CISOs assume responsibility for unified, storage-as-a-service platforms, demonstrating absolute data protection is non-negotiable. Pure Storage offers a defense-in-depth program, continuously validated by independent third-party auditors and operating 24/7/365 to shield infrastructure and customer data. Demand assurance that security is embedded: our “Security by Design” principle drives a rigorous Secure SDLC, utilizing threat modeling and continuous testing to establish a risk-based baseline compliant with NIST SP 800-218.

This Assurance Packet details the controls protecting data across on-premises (FlashArray, FlashBlade) and cloud (Pure1, Portworx) environments. Core protection mandates always-on, AES-256 encryption for data at rest and in transit. Our Enterprise Security program secures access using PoLP, RBAC, and MFA/SSO via a robust IAM framework, which, coupled with a proactive Risk Management and Incident Response (IR) Framework, aligns seamlessly with ISO 27001 and NIST CSF.

You will learn:

  • Confidence in secure SDLC: Validation that development adheres to NIST SP 800-218A (SSDF) and holds the required OMB M-22-18 attestation for key products.
  • Proof of cryptographic strength: Documentation confirming all data is protected by always-on AES-256 encryption and how cryptographic modules achieve NIST FIPS 140-3 validation.
  • Robust access governance: Assurance that the IAM framework enforces PoLP, RBAC, and MFA/SSO consistent with current NIST standards.
  • Verified resiliency posture: Confirmation that the IR Framework and Business Continuity align with ISO 27001, NIST CSF, and NIST 800-61.
  • Scope of compliance coverage: Clarity on the scope of the ISO 27001 certification and the SOC 2 Type II reports covering Pure1 Cloud and Portworx.
  • Government-grade security: Evidence that products are NIST FIPS 140-3 validated and hold NIAP Common Criteria certification for rigorous security standards.
  • External risk mitigation: Confirmation that independent third-party vendors across all infrastructure and products conduct continuous penetration testing.
  • GenAI data integrity: Assurance that the GenAI Governance policy prevents training on user prompts and limits outbound data transmission to prevent data leakage.

Fill out the form to get our latest whitepaper

What are your top storage concerns or improvements you'd like to see in your current environment?
By registering for CDOTrends, DigitalWorkforceTrends and our related websites and newsletters, you have read and agreed to the Terms of Use and Privacy & Cookie Policy. You agree to receive updates and related promotions from CDOTrends and potentially our marketing partners who might contact you by email or otherwise.