Security Grades
Security Grades
We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.
React Server Components (CVE-2025-55182) Vulnerability - Not Impacted
You may be aware of the critical vulnerability (CVE-2025-55182) within the React Server Components Framework that was published on December 3rd, 2025.
Culture Amp confirms that our infrastructure is not impacted by this security issue. We do not utilise the vulnerable React Server Components (RSC) functionality or affected packages.
Ivanti CVE - Not Impacted
You may be aware that Ivanti has issued an important security update addressing recently identified vulnerabilities for Ivanti Connect Security, Policy Secure, and Neurons for ZTA Gateways.
Culture Amp does not use Ivanti and is not impacted by this security issue.
Culture Amp Security Documentation not downloadable - 01/08/2024
Hi all, Culture Amps Security Documentation may be temporarily only available in read only format as we tweak some settings with the underlying platform. For anyone performing due dilligence activities, most documentation should be downloadable (if required) hopefully by Monday US-time.
The exception to this will be our SOC2 report, which will remain available in read only format indefinitely.
Culture Amp SOC2 Type 2 complete. SOC3 Report available.
Culture Amp SOC2 Type 2 complete. SOC3 Report available for download from our security trust centre.
Citrix ADC and Citrix Gateway
Culture Amp is not impacted by the Citrix Vulnerabilities (CVE-2023-3519, CVE-2023-3466, CVE-2023-3467).




