An Aeon AI Risk Management product

Vendor Risk Memo: bloomberg.com

Generated 2026-08-11 · Media/Publisher · Decision support only, not a certification.

INSUFFICIENT DATA Score 22/100 Better than 20% of assessed vendors 2/20 controls verified

Your call:

Collection was partial - bot protection or thin public docs limited verification. Obtain vendor documentation and upload below.

Download PDF Download XLSX Forward to boss Assess another

Executive summary

Bloomberg maintains a mature public-facing security posture, evidenced by active vulnerability disclosure programs and robust email authentication. The primary gap is the lack of publicly available compliance documentation (SOC 2/ISO) for enterprise-grade verification.

Key findings

[POSITIVE] Active Vulnerability Disclosure Program

Demonstrates a commitment to external security research and proactive threat identification.

[POSITIVE] Strong Email Authentication

SPF and DMARC records are present, significantly reducing the risk of domain spoofing and phishing attacks.

[MEDIUM] Lack of Public Compliance Transparency

Absence of readily available SOC 2 or ISO 27001 documentation requires manual verification during procurement.

Risk by domain

Compliance

0/100

6 gaps

Data Security

22/100

4 gaps

Operational

12/100

2 gaps

Contract recommendations

What to request from bloomberg.com

18 unverified controls, prioritized by risk impact:

1. SOC 2 Type II report

Independent verification of security controls over time.

2. Encryption architecture summary

Data-at-rest protection is not publicly documented.

3. Access control / SSO documentation

Access control verification for enterprise onboarding.

4. AI/ML data use policy or DPA with AI clause

AI training on customer data is a top concern in 2026 vendor reviews.

5. ISO 27001 certificate

International security standard verification.

6. MFA policy

Internal access security.

7. Data retention and deletion policy

Data lifecycle compliance.

8. Subprocessor list

Fourth-party risk visibility.

Got their docs?

Upload SOC 2 / security whitepaper / DPA. Report updates in place - same link. Must look like security evidence.

Detailed control assessment

ControlAnswerCitationConf
SOC 2 Type II report UNKNOWN 0.0
Data encrypted at rest UNKNOWN 0.0
Data encrypted in transit (TLS) YES TLS handshake succeeded, cert expires Jan 29 23:59:59 2027 GMT 0.95
Access controls / RBAC / SSO UNKNOWN 0.0
Trains AI models on customer data UNKNOWN 0.0
ISO 27001 certification UNKNOWN 0.0
MFA enforced internally UNKNOWN 0.0
Data retention/deletion policy UNKNOWN 0.0
Subprocessors disclosed UNKNOWN 0.0
Incident response / breach notification UNKNOWN 0.0
Penetration testing performed UNKNOWN 0.0
Data Processing Agreement available UNKNOWN 0.0
GDPR compliance stated UNKNOWN 0.0
Vulnerability disclosure / bug bounty YES security.txt: Vulnerability Disclosure Contact Contact: mailto:reportvuln@bloomberg.net 1.0
Audit logging UNKNOWN 0.0
Uptime SLA published UNKNOWN 0.0
Employee background checks UNKNOWN 0.0
Backups / disaster recovery UNKNOWN 0.0
Vendor's own third-party risk program UNKNOWN 0.0
Data residency / region hosting UNKNOWN 0.0

Are you bloomberg.com?

Claim this profile, upload evidence, get a Verified badge.

Open vendor portal Get badge