Splunk took background checks out of two security exhibits

Stani Mihov

Founder & CEO

·

TL;DR

What changed:

  • Background checks were removed from the on-premises and Observability Cloud exhibits.

  • The physical security sections are gone from the same two exhibits, and all three now list only "administrative and technical" safeguards.

  • The Cloud Platform and Observability exhibits no longer promise a copy of the annual audit report on request and point to a trust portal instead.

  • Other removals include malware scanning of software packages, faster fixes for critical vulnerabilities, security training, and vendor oversight.

  • The Cloud Platform exhibit still keeps its background check and physical security sections.

What to do: If Splunk is in your vendor review, request its current SOC 2 report through the Customer Trust Portal and ask Splunk to confirm in writing which safeguards still apply to the product you use.

The change

Splunk, now part of Cisco, publishes security exhibits that become part of its customer contracts. Each one lists the safeguards Splunk commits to for a group of products. Around September 23, 2026, Splunk posted new versions of three of them, all labeled July 2026: the Splunk Cloud Platform Security Exhibit, the Splunk Observability Cloud Security Exhibit, and the Information Security Exhibit for on-premises products. The Observability exhibit changed again on September 25.

Much of the rewrite is Cisco branding and cleanup. Inside it, a set of specific safeguards that used to be written into the exhibits are no longer there. The exhibits apply to customers on Splunk's General Terms. They do not cover trials or free licenses, and the two cloud exhibits also exclude subscriptions bought directly on splunk.com.

What changed

Across the three exhibits, these written safeguards were removed or cut back:

  • Background checks. The on-premises exhibit deleted the sentence "Splunk performs background checks of its employees at time of hire, as permitted by law." The Observability exhibit deleted its whole Human Resources Security section, which covered background checks and confidentiality agreements for staff with access to customer content.

  • Physical security. All three exhibits now describe "administrative and technical" safeguards instead of "administrative, technical and physical" ones. The on-premises exhibit deleted its section on facility access, camera surveillance, and power protection for data centers, and the Observability exhibit deleted its Physical Security section.

  • Audit reports. The Cloud Platform and Observability exhibits used to say: "Upon request, Splunk will supply Customer with a summary copy of Splunk's annual audit reports." That sentence is gone from both, and they now point customers to Splunk's trust portal to request certifications and evidence.

  • Security training. The on-premises exhibit deleted its Security Training and Awareness section.

  • Vendor oversight. The Observability exhibit deleted its Vendor Security section, which described due diligence and ongoing monitoring of Splunk's own suppliers.

  • Critical patches. The on-premises exhibit removed the promise to make "reasonable efforts to expedite maintenance releases" for critical, high-impact vulnerabilities.

  • Testing and malware checks. All three exhibits dropped the line that packaged software is scanned for "trojans, viruses, malware and other malicious threats." The on-premises exhibit no longer says third parties perform penetration testing, and the two cloud exhibits no longer include Splunk's corporate environment in the annual external penetration test.

  • Incident response. The Cloud Platform exhibit deleted its paragraph describing Splunk's incident response plan and team, along with the annual review of that plan.

A list that now ends with "and"

A small detail in the on-premises exhibit shows where the text came out. Section 4.1 lists what Splunk does to manage vulnerabilities, and its third item still ends with "; and". The fourth item, the promise to speed up fixes for critical vulnerabilities, was deleted, so the list now stops on a dangling "and" with nothing after it.

What still stands

The rewrite did not empty the exhibits. The Cloud Platform exhibit still has full Physical Security and Human Resources Security sections, including background checks and badge controls. All three still describe access controls, encryption, vulnerability management, and breach notification, and the on-premises exhibit's incident response section now includes an annual review of the plan.

Both cloud exhibits still name an annual SOC 2 Type 2 audit. Splunk's compliance page also says its third-party reports are available to customers under a non-disclosure agreement through the Customer Trust Portal, so the reports themselves have not disappeared. What changed is that the exhibits no longer promise to hand them over on request.

From contract to web page

The exhibits now send customers to Compliance at Splunk to see which certifications they can request. That page says it is solely for informational purposes and carries a disclaimer that none of its information should be treated as a contractual commitment unless the contract itself says so. In the Cloud Platform exhibit, the detailed PCI-DSS Level 1 and HIPAA compliance statements for the premium environment were replaced with a short list of audits and a link to that page.

The new text also adds a pointer to the Cisco Trust Portal for Cisco terms. For customers buying through Cisco, that does not necessarily lead to a longer list. Cisco's own offer description for Splunk Observability Cloud says the Cisco Information Security Exhibit is replaced by the Splunk Observability Security Exhibit, the same document that lost its physical, vendor, and personnel sections. It is the same move from written commitment to supporting material we saw when Perplexity moved three protections out of its privacy policy.

Why this matters

Security exhibits are the part of a vendor contract that a security review leans on. When a questionnaire asks whether a vendor screens its staff, controls physical access, or shares its audit report, the exhibit is where the written answer comes from.

Each of these exhibits also says Splunk may update it only if the changes "do not materially diminish the level of security herein provided." That sentence did not change, while the list of safeguards it refers to got shorter. Whether Splunk's security practices changed is a question only Splunk can answer, but what the contract says has changed for certain. Exhibits that update by web page, with no new signature, are the same pattern we covered when Hotjar's DPA stopped needing your signature to change, and they are exactly the kind of vendor legal change that is easy to miss.

Potential impact

For a SaaS company that uses Splunk, the rewrite raises four practical questions:

  • If your vendor file for Splunk cites its exhibit for background checks or physical security, is that still accurate for the product you use?

  • Do you have a current SOC 2 report for Splunk, and does your team know how to request the next one through the trust portal?

  • If your contract includes the exhibits by link rather than as a signed copy, which version applies to you?

  • Do your own customers' security questionnaires ask about your vendors' personnel and physical controls, so that your answers depend on Splunk's?

Keeping those answers current across every vendor is what continuous vendor contract monitoring is for.

How Venpo detected it

Venpo monitors Splunk's legal pages as part of continuous vendor risk monitoring. It flagged all three rewritten exhibits on September 23 and the further Observability change on September 25, with every inserted and deleted line marked, and each change was checked against the live pages. The redlines are public for the Cloud Platform exhibit, the Observability exhibit, and the on-premises exhibit, and every monitored document is listed on the Splunk vendor profile.

Business outcome

Teams that rely on Splunk got a list of every removed safeguard, with its original wording, within two days of the new versions going live. That leaves time to update the vendor file, request the current SOC 2 report, and ask Splunk for written confirmation before the next security review or customer questionnaire. The alternative is finding out when an auditor or a customer asks why the vendor file quotes a clause that no longer exists.

Key takeaway

Splunk's security exhibits now promise less in writing than they did before September 23, and the lines that came out are the ones security reviews quote most: background checks, physical controls, and access to the audit report. The practices may well continue, but the contract no longer says so, and the only way to see that difference is to compare the text itself every time it changes.

The change

Splunk, now part of Cisco, publishes security exhibits that become part of its customer contracts. Each one lists the safeguards Splunk commits to for a group of products. Around September 23, 2026, Splunk posted new versions of three of them, all labeled July 2026: the Splunk Cloud Platform Security Exhibit, the Splunk Observability Cloud Security Exhibit, and the Information Security Exhibit for on-premises products. The Observability exhibit changed again on September 25.

Much of the rewrite is Cisco branding and cleanup. Inside it, a set of specific safeguards that used to be written into the exhibits are no longer there. The exhibits apply to customers on Splunk's General Terms. They do not cover trials or free licenses, and the two cloud exhibits also exclude subscriptions bought directly on splunk.com.

What changed

Across the three exhibits, these written safeguards were removed or cut back:

  • Background checks. The on-premises exhibit deleted the sentence "Splunk performs background checks of its employees at time of hire, as permitted by law." The Observability exhibit deleted its whole Human Resources Security section, which covered background checks and confidentiality agreements for staff with access to customer content.

  • Physical security. All three exhibits now describe "administrative and technical" safeguards instead of "administrative, technical and physical" ones. The on-premises exhibit deleted its section on facility access, camera surveillance, and power protection for data centers, and the Observability exhibit deleted its Physical Security section.

  • Audit reports. The Cloud Platform and Observability exhibits used to say: "Upon request, Splunk will supply Customer with a summary copy of Splunk's annual audit reports." That sentence is gone from both, and they now point customers to Splunk's trust portal to request certifications and evidence.

  • Security training. The on-premises exhibit deleted its Security Training and Awareness section.

  • Vendor oversight. The Observability exhibit deleted its Vendor Security section, which described due diligence and ongoing monitoring of Splunk's own suppliers.

  • Critical patches. The on-premises exhibit removed the promise to make "reasonable efforts to expedite maintenance releases" for critical, high-impact vulnerabilities.

  • Testing and malware checks. All three exhibits dropped the line that packaged software is scanned for "trojans, viruses, malware and other malicious threats." The on-premises exhibit no longer says third parties perform penetration testing, and the two cloud exhibits no longer include Splunk's corporate environment in the annual external penetration test.

  • Incident response. The Cloud Platform exhibit deleted its paragraph describing Splunk's incident response plan and team, along with the annual review of that plan.

A list that now ends with "and"

A small detail in the on-premises exhibit shows where the text came out. Section 4.1 lists what Splunk does to manage vulnerabilities, and its third item still ends with "; and". The fourth item, the promise to speed up fixes for critical vulnerabilities, was deleted, so the list now stops on a dangling "and" with nothing after it.

What still stands

The rewrite did not empty the exhibits. The Cloud Platform exhibit still has full Physical Security and Human Resources Security sections, including background checks and badge controls. All three still describe access controls, encryption, vulnerability management, and breach notification, and the on-premises exhibit's incident response section now includes an annual review of the plan.

Both cloud exhibits still name an annual SOC 2 Type 2 audit. Splunk's compliance page also says its third-party reports are available to customers under a non-disclosure agreement through the Customer Trust Portal, so the reports themselves have not disappeared. What changed is that the exhibits no longer promise to hand them over on request.

From contract to web page

The exhibits now send customers to Compliance at Splunk to see which certifications they can request. That page says it is solely for informational purposes and carries a disclaimer that none of its information should be treated as a contractual commitment unless the contract itself says so. In the Cloud Platform exhibit, the detailed PCI-DSS Level 1 and HIPAA compliance statements for the premium environment were replaced with a short list of audits and a link to that page.

The new text also adds a pointer to the Cisco Trust Portal for Cisco terms. For customers buying through Cisco, that does not necessarily lead to a longer list. Cisco's own offer description for Splunk Observability Cloud says the Cisco Information Security Exhibit is replaced by the Splunk Observability Security Exhibit, the same document that lost its physical, vendor, and personnel sections. It is the same move from written commitment to supporting material we saw when Perplexity moved three protections out of its privacy policy.

Why this matters

Security exhibits are the part of a vendor contract that a security review leans on. When a questionnaire asks whether a vendor screens its staff, controls physical access, or shares its audit report, the exhibit is where the written answer comes from.

Each of these exhibits also says Splunk may update it only if the changes "do not materially diminish the level of security herein provided." That sentence did not change, while the list of safeguards it refers to got shorter. Whether Splunk's security practices changed is a question only Splunk can answer, but what the contract says has changed for certain. Exhibits that update by web page, with no new signature, are the same pattern we covered when Hotjar's DPA stopped needing your signature to change, and they are exactly the kind of vendor legal change that is easy to miss.

Potential impact

For a SaaS company that uses Splunk, the rewrite raises four practical questions:

  • If your vendor file for Splunk cites its exhibit for background checks or physical security, is that still accurate for the product you use?

  • Do you have a current SOC 2 report for Splunk, and does your team know how to request the next one through the trust portal?

  • If your contract includes the exhibits by link rather than as a signed copy, which version applies to you?

  • Do your own customers' security questionnaires ask about your vendors' personnel and physical controls, so that your answers depend on Splunk's?

Keeping those answers current across every vendor is what continuous vendor contract monitoring is for.

How Venpo detected it

Venpo monitors Splunk's legal pages as part of continuous vendor risk monitoring. It flagged all three rewritten exhibits on September 23 and the further Observability change on September 25, with every inserted and deleted line marked, and each change was checked against the live pages. The redlines are public for the Cloud Platform exhibit, the Observability exhibit, and the on-premises exhibit, and every monitored document is listed on the Splunk vendor profile.

Business outcome

Teams that rely on Splunk got a list of every removed safeguard, with its original wording, within two days of the new versions going live. That leaves time to update the vendor file, request the current SOC 2 report, and ask Splunk for written confirmation before the next security review or customer questionnaire. The alternative is finding out when an auditor or a customer asks why the vendor file quotes a clause that no longer exists.

Key takeaway

Splunk's security exhibits now promise less in writing than they did before September 23, and the lines that came out are the ones security reviews quote most: background checks, physical controls, and access to the audit report. The practices may well continue, but the contract no longer says so, and the only way to see that difference is to compare the text itself every time it changes.

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago