Symantec (Broadcom)
Symantec Enterprise Cloud security portfolio from Broadcom: endpoint security, DLP, cloud SWG, CASB, email security, web isolation and VIP authentication.
Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| ISO/IEC 27001:2022 (certificate also covers ISO/IEC 27017:2015 and ISO/IEC 27018:2019) | Accredited third-party certification body | Broadcom Cloud Services ISMS. Symantec services in scope: Symantec Endpoint Security Complete, Symantec Secure Access Cloud (SAC), Cloud Secure Web Gateway, CloudSOC CASB, Data Loss Prevention Cloud, Email Security.cloud, Threat Intelligence Service, VIP, Web Isolation | — | — | Current |
| SOC 1 and SOC 2 Type II | Independent third-party auditor | Symantec services in scope: Symantec Endpoint Security Complete, Symantec Secure Access Cloud (SAC), Cloud Secure Web Gateway, CloudSOC CASB, Data Loss Prevention Cloud, Email Security.cloud, Threat Intelligence Service, VIP, Web Isolation, Zero Trust Network Access. SOC 3 is not offered for Symantec services | — | — | Current |
| ISO 9001:2015 | Accredited third-party certification body | Quality management system. In-scope entries relevant to Symantec: Cybersecurity, Enterprise Software, Email Security.cloud, VIP | — | — | Current |
| IRAP assessment (ACSC Information Security Manual) | IRAP-registered assessor | Cloud Secure Web Gateway, CloudSOC CASB, Data Loss Prevention Cloud, Symantec Endpoint Security Complete, Symantec Secure Access Cloud (SAC), Web Isolation | — | — | Current |
Compliance Frameworks
Penetration Testing
| Scope | Conducted By | Date | Frequency | Report |
|---|---|---|---|---|
| Broadcom Cloud Services covering the Symantec portfolio - independent testing performed as part of the ISO 27001, SOC 2 and IRAP programmes. Broadcom does not publish standalone penetration test summaries (date shown is the profile capture date) | Independent third-party assessors engaged by Broadcom | Aug. 6, 2026 | Annual | On NDA |
Data Handling
Sub-processors
| Sub-processor | Purpose | Data Location | Trust Portal |
|---|---|---|---|
| Google LLC | Hosting provider and platform services / infrastructure management for the majority of Symantec cloud services (Symantec Endpoint Security Complete and Enterprise, Cloud Secure Web Gateway, Web Isolation, Zero Trust Network Access, Secure Access Cloud, CloudSOC CASB, Data Loss Prevention, Email Security.cloud, VIP, Threat Intelligence Service, WebPulse, Cloud Sandboxing/Cynic) | United States, Germany, Belgium, Netherlands, India, Brazil, Singapore, Japan, Australia, United Kingdom, Finland | — |
| Amazon Web Services (AWS) | Hosting provider and platform services for Email Security.cloud; hosting and one-time password delivery for Cloud Workload Protection for Storage and Industrial Control Systems Protection | United States, Sweden, Ireland, United Kingdom, Europe | View ↗ |
| Microsoft | Hosting provider and platform services for Cloud Secure Web Gateway; Azure cloud hosting for Content Analysis | United States, China | View ↗ |
| Echoworx Corporation | Email encryption service for Email Security.cloud | United States, United Kingdom | — |
| Zix Corporation | Email encryption service for Email Security.cloud | United States | — |
| Pendo.io, Inc. | Product analytics and usage telemetry for Symantec Endpoint Security Complete and Symantec Endpoint Security Enterprise | United States | — |
| SendGrid, Inc. | Email delivery service for Symantec Endpoint Security Enterprise | United States | — |
| TeleSign Corporation | Optional delivery of SMS one-time passwords (applies to all products) | United States | — |
| Payfone, Inc. DBA Prove | One-time password delivery by voice message for Validation & ID Protection (VIP) Service | United States | — |
| AC PM, LLC (ActiveCampaign) dba Postmark | Email delivery for Endpoint Protection Mobile | United States | — |
| Xyleme Inc. | Learning management system and education services (applies to all products) | United States | — |
Incident & Breach History
| Date | Summary | Impact | Resolution | Report |
|---|---|---|---|---|
| Jan. 17, 2012 | Source code for several Symantec products, including Norton Antivirus and pcAnywhere, was published by a third party. Symantec confirmed the code had been taken in a 2006 network intrusion rather than a new breach. | Symantec advised customers to disable pcAnywhere until updates were issued, because exposure of the source code raised the risk of exploit development against that product. Predates Broadcom ownership. | Hotfixes and updated releases were issued and customers were guided through remediation. Symantec subsequently retired pcAnywhere as a product. | — |
| Sept. 11, 2017 | Following investigations into certificate mis-issuance, browser vendors announced a phased plan to distrust TLS certificates issued by Symantec’s certificate authority. Symantec agreed to divest the CA business, which was acquired by DigiCert (completed October 2017). | Customers holding Symantec-issued TLS certificates (including Thawte, GeoTrust and RapidSSL brands) had to replace them to avoid browser trust errors. Reputational impact on Symantec’s assurance practices. Predates Broadcom ownership. | The certificate authority business was transferred to DigiCert, which re-issued affected certificates from its own trusted roots. Symantec exited the public CA market. | — |
Security Policies
| Policy | Availability | Link |
|---|---|---|
| Broadcom Global Privacy Notice and Policy | Public | View ↗ |
| Data Processing and Data Transfers (pre-executed DPA terms and SCCs) | Public | View ↗ |
| Third Party List (sub-processors) with change notification subscription | Public | View ↗ |
| Privacy and Data Protection hub, including per-product Transparency Notices | Public | View ↗ |
| Symantec Vulnerability Response Guidelines | Public | View ↗ |
| Broadcom Product Security Center | Public | View ↗ |
| Broadcom Terms of Use | Public | View ↗ |
| Certification and audit reports (SOC 1/2, ISO 27001/9001, IRAP) via Broadcom Support Portal | On Request | View ↗ |
Legal & Privacy
- Privacy Policy View ↗
- DPA Template View ↗
- Terms of Service View ↗
- GDPR Representative Broadcom publishes pre-executed data processing and transfer terms plus EU/UK representative details in its Global Privacy Notice and Policy. Confirm the contracting Broadcom entity and representative at contract stage.
- Lawful Basis Processor acting on customer instructions under Broadcom’s pre-executed data processing terms (Art. 28 GDPR), with per-product Transparency Notices documenting categories and purposes. Legitimate interests relied on for security telemetry and threat intelligence necessary to deliver the service. International transfers rely on Standard Contractual Clauses.
Contact & Responsible Disclosure
- Security Contact [email protected]
- Responsible Disclosure View policy ↗
- Bug Bounty Platform No public bug bounty programme. Coordinated disclosure via the Symantec PSIRT ([email protected]); PGP key published on the Broadcom Product Security Center.
Trust Portal & Audit Evidence
**Trust portal:** [Broadcom Trust Center](https://www.broadcom.com/support/trust-center) with the compliance index at [/support/trust-center/compliance](https://www.broadcom.com/support/trust-center/compliance). Certificates and scope tables are public and filterable by region and service; SOC 1/SOC 2 reports and bridge letters are downloaded from the Broadcom Support Portal and require an account and NDA.
**Important scoping caveat:** Broadcom certifications are granted per service, not per company. Several standards listed on the Trust Center do **not** cover Symantec services - PCI DSS and PCI 3DS cover the Arcot payment products and VMware Cloud on AWS, HIPAA BAA covers VMware Cloud on AWS and VMware Live Cyber Recovery, Cyber Essentials covers VMware Cloud Foundation, and TISAX covers Broadcom chip manufacturing. Always confirm the specific Symantec service appears in the scope table.
**Sub-processors:** [Third Party List](https://www.broadcom.com/company/legal/privacy/third-party-list) - public, dated (last updated 30 July 2026), with an email subscription for change notifications. This is unusually transparent for an enterprise security vendor and is the best evidence source for onward data flows.
**Transparency Notices:** per-product privacy documentation via [/company/legal/privacy](https://www.broadcom.com/company/legal/privacy).
**TruSight:** Broadcom participates in the TruSight shared assessment programme; reports are obtained directly from TruSight rather than Broadcom.
Risk Assessment Notes
**Corporate structure - check what you are actually buying**
Symantec is not a standalone company. Broadcom acquired the Symantec enterprise security business in November 2019; the consumer business (Norton, LifeLock) was retained separately and is now Gen Digital. This profile covers the Broadcom enterprise portfolio only. Contracts, DPAs and assurance artefacts are all issued by Broadcom entities.
**Inherent risk drivers**
- Endpoint agents and network inspection points (Cloud SWG, Web Isolation, CASB, DLP) sit inline and can affect availability and confidentiality of traffic across the estate.
- TLS interception in Cloud SWG creates a high-value decryption point that needs its own control review.
- DLP and CASB modules by design ingest content, materially raising data classification sensitivity.
**Mitigating factors**
- Per-service ISO 27001/27017/27018 certificates and SOC 1/SOC 2 Type II reports for the main Symantec cloud services.
- IRAP assessment against the ACSC ISM for six Symantec cloud services.
- Public, dated sub-processor list with subscription-based change notification.
**Concerns to track**
- Certification scope is narrower than the marketing surface: no PCI DSS, HIPAA BAA or Cyber Essentials coverage for Symantec services. Do not inherit assurance from other Broadcom or VMware product lines.
- Post-acquisition Broadcom has repositioned toward its largest accounts; assess support model, roadmap and licensing continuity risk, and document an exit plan.
- Encryption and backup specifics are not published - these must be evidenced from the SOC 2 report rather than assumed.
- Heavy reliance on Google Cloud as the underlying hosting provider for most Symantec services creates a fourth-party concentration to record.
- No public bug bounty programme; vulnerability handling is PSIRT-only, which gives less external assurance than peers.
**Suggested review cadence:** annual, with evidence refresh when each SOC 2 report is reissued and re-check of the Third Party List at every review.
Copyright © 2026 SnapGRC