Security and Compliance Assurance Packet
- By Pure Storage
- November 17, 2025
As CISOs assume responsibility for unified, storage-as-a-service platforms, demonstrating absolute data protection is non-negotiable. Pure Storage offers a defense-in-depth program, continuously validated by independent third-party auditors and operating 24/7/365 to shield infrastructure and customer data. Demand assurance that security is embedded: our “Security by Design” principle drives a rigorous Secure SDLC, utilizing threat modeling and continuous testing to establish a risk-based baseline compliant with NIST SP 800-218.
This Assurance Packet details the controls protecting data across on-premises (FlashArray, FlashBlade) and cloud (Pure1, Portworx) environments. Core protection mandates always-on, AES-256 encryption for data at rest and in transit. Our Enterprise Security program secures access using PoLP, RBAC, and MFA/SSO via a robust IAM framework, which, coupled with a proactive Risk Management and Incident Response (IR) Framework, aligns seamlessly with ISO 27001 and NIST CSF.
You will learn:
- Confidence in secure SDLC: Validation that development adheres to NIST SP 800-218A (SSDF) and holds the required OMB M-22-18 attestation for key products.
- Proof of cryptographic strength: Documentation confirming all data is protected by always-on AES-256 encryption and how cryptographic modules achieve NIST FIPS 140-3 validation.
- Robust access governance: Assurance that the IAM framework enforces PoLP, RBAC, and MFA/SSO consistent with current NIST standards.
- Verified resiliency posture: Confirmation that the IR Framework and Business Continuity align with ISO 27001, NIST CSF, and NIST 800-61.
- Scope of compliance coverage: Clarity on the scope of the ISO 27001 certification and the SOC 2 Type II reports covering Pure1 Cloud and Portworx.
- Government-grade security: Evidence that products are NIST FIPS 140-3 validated and hold NIAP Common Criteria certification for rigorous security standards.
- External risk mitigation: Confirmation that independent third-party vendors across all infrastructure and products conduct continuous penetration testing.
- GenAI data integrity: Assurance that the GenAI Governance policy prevents training on user prompts and limits outbound data transmission to prevent data leakage.