Perforce

United States · www.puppet.com · 24 vendors

Perforce Software is a provider of DevOps solutions that help technology teams solve complex challenges across the software development lifecycle. Through its Puppet business unit, it offers infrastructure automation, configuration management, and compliance solutions for cloud, on-premises, and hybrid environments.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 1 category; runs on 24 sub-vendors.

Insights

Last updated 2026-03-06 · revision 7

24 direct vendors, 284 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Perforce exhibits high migration readiness, largely due to its advanced and cloud-native oriented internal technology stack and the significant advantage of having no reported external vendor lock-in. The internal tech stack, featuring AWS, Kubernetes, Docker, Terraform, and self-hosted Puppet Enterprise, is indicative of a highly containerized, infrastructure-as-code driven environment. This modern architecture is ideally suited for seamless migration to new cloud environments or refactoring into microservices. The reported 'Total Vendors: 0' is a substantial strength, implying that Perforce is not constrained by external vendor contracts, proprietary technologies, or complex vendor relationship management during a migration. This provides maximum flexibility and control over their technology roadmap. From a regulatory perspective, Perforce has established frameworks for GDPR compliance, including Standard Contractual Clauses (SCCs) and UK addenda for cross-border data transfers, and provides options for customer identity providers and application-level access control, suggesting adaptability to data residency requirements. SOC 2 Type 2 compliance and an ongoing ISO 27001 program further bolster their security posture, which is crucial for a secure migration. Potential challenges include the pending assessments for NIS2 and HIPAA, which might introduce complexities if not proactively addressed during migration planning. Additionally, the absence of financial stability data (revenue concentration, growth history) means the ability to fund a large-scale migration cannot be fully assessed. Despite these minor areas, the technical foundation and lack of vendor dependencies position Perforce very strongly for any significant migration initiative.

Compliance

4 in-scope frameworks identified; showing 3.

HIPAA (source) — Assessment Required

Perforce serves healthcare industry customers and their products could potentially handle Protected Health Information (PHI) if used in healthcare environments. While they are not primarily a healthcare company, their infrastructure automation and DevOps tools could be used by covered entities or business associates. The risk level is medium because non-compliance could result in significant penalties if they are handling PHI, but their primary business is not healthcare-focused.

Evidence: https://www.perforce.com/solutions/healthcare

GDPR (source) — Assessment Required

As a US-based software company serving global customers including EU/EEA organizations, Perforce likely processes personal data of EU/EEA residents through their products and services. Their privacy policy indicates they process personal information globally and have GDPR-compliant language including data subject rights, lawful bases for processing, and cross-border transfer mechanisms. However, without explicit GDPR compliance certification or DPO appointment evidence, full compliance status requires assessment.

Evidence: https://www.perforce.com/privacy-policy

ISO 27001 (source) — Partially Compliant

Perforce is actively executing their Information Security Management System (ISMS) program and states they will publish certificates for covered business units upon issuance. This indicates they are in the process of achieving ISO 27001 certification but may not have complete coverage across all business units yet. The risk is medium because they are actively working toward compliance but may have gaps during the implementation phase.

Evidence: https://www.perforce.com/company/security-compliance-policies, https://trust.perforce.com

Financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report