Pantheon Systems, Inc. is a privately held San Francisco-based corporation founded in 2010.
Summary from Wikipedia.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
-
EU-US DPF
Publicly advertised on the organization’s trust center.
-
TX-RAMP
Texas state authorization program for cloud products used by state agencies.
-
PCI DSS
Payment card industry standard for handling cardholder data securely.
Compliance timeline
-
2010
Company founded
-
March 2025
Trust center first observed in public web archives
-
September 8, 2026
Posture last observed by Trust Index
Roughly 15 years elapsed between founding and the earliest archived capture of a public trust center. Archive coverage is incomplete, so the page may have existed earlier.
Security & compliance hiring
Open roles on the organization’s public job board, a signal of active investment in security and compliance.
- Staff Security Engineer - Security Operations
- Staff Security Engineer - Security Operations
Subprocessors
Third parties Pantheon discloses on its trust center. Linked entries have their own profile in the Trust Index.
39% chain trust: 19 of 49 disclosed subprocessors are themselves in the Trust Index.
- Amazon Web Services
- Cloudflare
- Fastly
- Google Cloud Platform
- NewRelic
- Pingdom
- Rackspace
- Sentry
- Splunk
- Tesorio
- Advocately
- Auth0
- Bizible
- Bynder
- Chorus.ai
- CircleCI
- Crometrics
- DocuSign
- G2 Crowd
- GetFeedback
- GitHub
- Grafana
- Heroku
- Hushly
- Intercom
- Ironclad
- Marketo
- Okta
- Olark
- OneTrust
- Optimizely
- NetSuite
- Package Cloud
- PagerDuty
- Pendo
- Quay.io
- RFPIO
- Salesforce
- Segment
- SendGrid
- Slack
- Survey Anyplace
- Traackr
- Workato Inc.
- Wpromote
- YayPay
- Zendesk
- Zoom
- Zuora
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.