close
close
""
The AI Security Playbook
This playbook explores six core security challenges organizations face when adopting AI, along with proven, real-world strategies to address them.
Experience Netskope
Get Hands-on With the Netskope Platform
Here's your chance to experience the Netskope One single-cloud platform first-hand. Sign up for self-paced, hands-on labs, join us for monthly live product demos, take a free test drive of Netskope Private Access, or join us for a live, instructor-led workshops.
A Leader in SSE. Now a Leader in Single-Vendor SASE.
Netskope is recognized as a Leader Furthest in Vision for both SSE and SASE Platforms
2X a Leader in the Gartner® Magic Quadrant for SASE Platforms
One unified platform built for your journey
""
Netskope One AI Security
Organizations need secure AI to move their business forward, but controls and guardrails must not require sacrifices in speed or user experience. Netskope can help you say yes to the AI advantage.
""
Netskope One AI Security
Organizations need secure AI to move their business forward, but controls and guardrails must not require sacrifices in speed or user experience. Netskope can help you say yes to the AI advantage.
Modern data loss prevention (DLP) for Dummies eBook
Modern Data Loss Prevention (DLP) for Dummies
Get tips and tricks for transitioning to a cloud-delivered DLP.
Modern SD-WAN for SASE Dummies Book
Modern SD-WAN for SASE Dummies
Stop playing catch up with your networking architecture
Understanding where the risk lies
Advanced Analytics transforms the way security operations teams apply data-driven insights to implement better policies. With Advanced Analytics, you can identify trends, zero in on areas of concern and use the data to take action.
The Lens
""
Read about the latest news and opinions from the team at Netskope. The Lens combines our blogs, our podcasts and case studies, with new content added every week.
Netskope Technical Support
Netskope Technical Support
Our qualified support engineers are located worldwide and have diverse backgrounds in cloud security, networking, virtualization, content delivery, and software development, ensuring timely and quality technical assistance
""
AI in the Fast Lane
Netskope’s AI in the Fast Lane roadshow brings together security professionals to discuss how organizations are using AI today, and how a comprehensive security strategy can create a smarter, safer, and future-proof model.
Netskope video
Netskope Training
Netskope training will help you become a cloud security expert. We are here to help you secure your digital transformation journey and make the most of your cloud, web, and private applications.
Netskope

CCPA/CPRA Compliance Statement

Introduction

In the performance of Netskope’s cloud security services (“Services”) pursuant to an active master subscription agreement (“Agreement”) executed by Netskope and the end customer (“Customer”), Netskope supports the customer’s compliance for Processing covered by the California Consumer Privacy Act of 2018 (the “CCPA”), as amended by the California Privacy Rights Act of 2020 (the “CPRA”). To confirm applicable aspects of the CCPA and CPRA in connection with Customer’s use of the Services, Netskope is providing this Compliance Statement. Terms not defined below have the meanings given to them in the CCPA and CPRA.

 

Role of Business

Netskope operates as a service provider or processor to our customers. We process personal information solely on behalf of, and at the direction of, our customers. Netskope does not “sell” or “share” any personal information as defined by the CCPA and CPRA. Our processing activities are strictly limited to providing and improving the security services for which we have been engaged, as specified in our contractual agreements.

 

Data Collection and Use

Netskope processes personal information that our customers provide to us as part of their use of our Services. The purpose for this processing is to provide cloud security services, which includes identifying and preventing threats, protecting data, and ensuring compliance with our customers’ policies. The information processed is determined by the customer’s specific deployment of our services and may include data from a variety of sources within their environment.

Deidentification and Aggregation. If the Services involve Processing Deidentified and/or Aggregated information, Netskope will do so only with Personal Information that has been Deidentified and/or Aggregated as those terms are defined below. For Deidentified information, Netskope will implement appropriate safeguards to prevent reidentification.

Data Retention. Netskope retains personal information as long as necessary to fulfill the purposes for which it was collected or as required by our contractual agreements with our customers. The retention periods are defined by the customer’s settings and policies within our platform. Upon the termination of an agreement, Netskope will, at the customer’s request and in accordance with the agreement, delete or return all personal information as required by law.

 

Consumer Rights

Consumer Requests. To the extent that Netskope stores Personal Information subject to the CCPA and CPRA, at Customer’s request, Netskope will assist Customer with Customer’s obligation to respond to consumers’ requests to exercise their rights under the CCPA and CPRA by securely deleting or destroying Personal Information pertaining to a consumer identified by Customer where such Personal Information is within possession or control of Netskope.

 

Security and Data Breach

Information Security. Netskope maintains a written comprehensive data security program and maintains appropriate technical and organizational security procedures and practices designed to protect Personal Information against anticipated threats or hazards to its security, confidentiality or integrity. Netskope’s security program is regularly audited by independent third parties, and we have achieved the following certifications to demonstrate our commitment:

 

    1. ISO/IEC 27001: Demonstrates our commitment to the confidentiality, integrity, and availability of our information assets.
    2. SOC 2 Type 2: Independently verifies that our controls related to security, availability, and confidentiality meet the highest industry standards.
    3. ISO/IEC 27018: Specifically validates our practices for the protection of Personally Identifiable Information (PII) in public clouds. Netskope will ensure that persons authorized to access Personal Information are bound by confidentiality obligations.

 

Security Breach. Netskope will notify Customer without undue delay if Netskope learns that there has been unauthorized access, use, modification, disclosure, loss, or damage to Personal Information in the possession or control of Netskope (“Security Breach”). Netskope will provide reasonable assistance and cooperation in the remediation or investigation of a Security Breach and/or the mitigation of potential damage.

 

Transparency and Resources. Netskope is committed to providing full transparency regarding our security and privacy practices. For a complete and up-to-date overview of our compliance frameworks, policies, and certifications, please visit the Netskope self-service compliance center. This centralized resource provides access to:

  • Security and Compliance and Privacy packages
  • Copies of our security certifications

 

For purposes of the above, the following definitions apply: “Aggregated” information means information that relates to multiple Consumers that fall into the same group or category, from which individual Consumer identities have been removed, that is not linked or reasonably linkable to any Consumer or household, including via a device. “Consumer” means a natural person. “Deidentified” means information that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular Consumer. “Personal Information” means any information provided to Netskope in connection with the Services, in any form, format or media (including paper, electronic and other records) that identifies an individual or relates to an identifiable individual and is subject to the CCPA. “Process” or “Processing” means any operation or set of operations performed on Personal Information or sets of Personal Information, whether or not by automated means. Processing includes the collection, recording, organization, structuring, alteration, use, access, disclosure, copying, transfer, storage, retention, deletion, combination, restriction, adaptation, retrieval, consultation, destruction, disposal, sale, sharing or other use of Personal Information.

 

For more information about the CCPA and CPRA, see California Attorney General’s website on the CCPA located at https://oag.ca.gov/privacy/ccpa and the California Privacy Protection Agency website at https://cppa.ca.gov.