Vendor Risk Memo: bloomberg.com
Generated 2026-08-11 · Media/Publisher · Decision support only, not a certification.
Your call:
Executive summary
Bloomberg maintains standard web security hygiene, including active vulnerability disclosure and robust transport encryption. However, the lack of publicly available enterprise-grade security documentation (SOC 2, ISO 27001) necessitates further due diligence before integrating with internal systems.
Key findings
Provides a clear channel for security researchers to report vulnerabilities, reducing the risk of unpatched exploits.
Absence of public SOC 2 or ISO 27001 documentation prevents verification of internal control effectiveness.
Privacy policy explicitly mentions sharing user information with third parties, which may introduce downstream vendor risk.
Risk by domain
Compliance
0/100
6 gaps
Data Security
22/100
4 gaps
Operational
12/100
2 gaps
Contract recommendations
- Include a Right to Audit clause to verify security controls in the absence of a public SOC 2 report.
- Require notification of any material data breach within 48 hours.
- Include a Data Processing Agreement (DPA) that restricts the use of customer data for AI model training.
- Specify data deletion timelines upon contract termination.
What to request from bloomberg.com
18 unverified controls, prioritized by risk impact:
Independent verification of security controls over time.
Data-at-rest protection is not publicly documented.
Access control verification for enterprise onboarding.
AI training on customer data is a top concern in 2026 vendor reviews.
International security standard verification.
Internal access security.
Data lifecycle compliance.
Fourth-party risk visibility.
Got their docs?
Upload SOC 2 / security whitepaper / DPA. Report updates in place - same link. Must look like security evidence.
Detailed control assessment
| Control | Answer | Citation | Conf |
|---|---|---|---|
| SOC 2 Type II report | UNKNOWN | 0.0 | |
| Data encrypted at rest | UNKNOWN | 0.0 | |
| Data encrypted in transit (TLS) | YES | TLS handshake succeeded, cert expires Jan 29 23:59:59 2027 GMT | 0.95 |
| Access controls / RBAC / SSO | UNKNOWN | 0.0 | |
| Trains AI models on customer data | UNKNOWN | 0.0 | |
| ISO 27001 certification | UNKNOWN | 0.0 | |
| MFA enforced internally | UNKNOWN | 0.0 | |
| Data retention/deletion policy | UNKNOWN | 0.0 | |
| Subprocessors disclosed | UNKNOWN | 0.0 | |
| Incident response / breach notification | UNKNOWN | 0.0 | |
| Penetration testing performed | UNKNOWN | 0.0 | |
| Data Processing Agreement available | UNKNOWN | 0.0 | |
| GDPR compliance stated | UNKNOWN | 0.0 | |
| Vulnerability disclosure / bug bounty | YES | bloomberg.com/.well-known/security.txt: Vulnerability Disclosure Contact Contact: mailto:reportvuln@bloomberg.net | 1.0 |
| Audit logging | UNKNOWN | 0.0 | |
| Uptime SLA published | UNKNOWN | 0.0 | |
| Employee background checks | UNKNOWN | 0.0 | |
| Backups / disaster recovery | UNKNOWN | 0.0 | |
| Vendor's own third-party risk program | UNKNOWN | 0.0 | |
| Data residency / region hosting | UNKNOWN | 0.0 |
Are you bloomberg.com?
Claim this profile, upload evidence, get a Verified badge.
Open vendor portal Get badge