Qualtrics XM

Qualtrics XM

Search the Trust Center...
Ctrl +K

Qualtrics XM | Trust Center

Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence. Our Trust Center is regularly updated to reflect the latest audit results, and subprocessor disclosures.


Announcements

Qualtrics' Customer Trust Team has released new content

Update #1

Qualtrics' Customer Trust team has published Qualtrics' AI Security & Privacy Guide v.1.0 - which is accessible via the "Documents" section of this Trust Center site in the "Arficial Intelligence (AI)" folder.

This document outlines Qualtrics’ comprehensive framework for AI security, privacy and compliance, detailing our policies on ethical data use, model governance, testing and training and AI risk management. It explains how we prioritize transparency and security by ensuring customer control over AI feature access, leverage anonymized data for training and maintain robust oversight to meet reputable industry standards like ISO 42001 and NIST AI Risk Management frameworks. It further features an Appendix which answers the top 20 themes/FAQs we’re seeing from customers globally on AI as it pertains to our services.

It represents both a combination of and extension to details which existed across different documents and blogs posts, etc, which used to exist in our documentation repository, into one centralised artefact.

Update #2

We have subsequently revamped the AI related content in the "Offerings and Highlights" section of our Trust Center to emphasise the insightful and efficient material available to enable an organization to adequately assess Qualtrics, our AI powered features, a customer’s use case(s), and how they may all intertwine in a manner that’s compliant with a customer’s own commitments.

Whether you’re an end user within Qualtrics’ cloud service, performing a vendor risk assessment, asking security questions, seeking legal or privacy approvals within your organization, etc., and have thought something along the lines of;

“I’m interested in Qualtrics’ AI features, but I need to meet my own company’s compliance requirements. Where do I start, what do I do next?”

We recommend flowing down through our updated “3 Tier Waterfall” approach, and the resources alluded to in each tier therein.


The intended audience for both updates is a customer's brand administrator(s) and/or authorised user(s) of Qualtrics product offerings, who are responsible for the platform's feature usage, permissioning, or day to day usage/program management efforts. Additionally, it is useful supporting material for a customer's vendor risk management efforts e.g. third party due diligence assessments or security questionnaires, etc., including AI focused due diligence.


Qualtrics AI Feature Model Update

The following Qualtrics AI feature in Engage is updating its model:

Insights Explorer
Old Model: Claude v3 Haiku
New Model: Claude Haiku 4.5; Claude Sonnet 4.5 (Gov data center)

If you have any questions please reach out to your account team.


Klue Supply Chain Compromise: Qualtrics Response

Executive Summary

At Qualtrics, the trust of our clients is our top priority. Your trust in us to secure your sensitive information is the foundation of our commitment to you, and we pledge to be open about our security practices, methodologies, and incident response protocols.

We were recently made aware of a security incident involving Klue, an application used by Qualtrics that connects to Salesforce to provide support to internal sales teams. Klue experienced a security breach, which resulted in unauthorized access to a subset of data within our Salesforce instance.

Qualtrics Impact

Qualtrics is one of many companies that have been impacted by this incident. We have confirmed the scope was limited to the Salesforce environment.

What was Impacted: Some business-to-business information stored in Salesforce, including names, email addresses, company names, phone numbers, and other business identifiers, were impacted.

What was NOT Impacted: This was not a breach of Qualtrics products, core infrastructure, or services. No customer data hosted within the Qualtrics platform was accessed or compromised.

Our investigation is ongoing and we are actively parsing through the data. Should our investigation reveal that any customer information requires notification, Qualtrics will contact those customers directly and without delay.

Qualtrics Response

The moment we learned of this incident, we took immediate action to protect our clients' data and our systems. Steps taken include:

  • Disabling the connection to the affected Klue application to prevent any further unauthorized access.
  • Launching a comprehensive investigation to determine the full scope of the incident and what data was impacted.
  • Working closely with the vendor to understand the root cause of the breach and ensure they are taking the necessary steps to improve their security.
  • Heightening Monitoring across similar third-party integrations to detect any anomalous activity.

We're Here to Help

We take full responsibility for the security of our data ecosystem, including the third-party tools we choose to utilize. This incident reinforces our commitment to rigorously vetting our vendors and maintaining a defensive security posture.

We are continuously reviewing and updating our security protocols to ensure we are prepared to meet the challenges of an ever-evolving threat landscape at the highest standard.

We understand you may have questions about this incident. Please do not hesitate to reach out to your account team or our support team.


Qualtrics AI Feature Model Updates

The following Qualtrics AI features in Discover are updating their models:

Smart Audit
Old Model: Claude 3.5 Haiku
New Model: Claude Haiku 4.5

Smart Query
Old Model: Claude 3 Haiku
New Models: Claude Haiku 4.5

Topics Recommendation
Old Model: Claude 3 Haiku
New Model: Claude Haiku 4.5

If you have any questions please reach out to your account team.


Qualtrics AI Feature Model Updates

The following Qualtrics AI features in Engage and Discover are updating their models:

Automated Text Analytics
Old Model: OpenAI O1 (US datacenters); GPT-4 (other datacenters)
New Model: Claude Sonnet 4.5; Qualtrics hosted propietary models

Research Hub
Old Model: Claude V3 Haiku (Anthropic)
New Models: Research Hub Summary + Recommendation Agents: Claude Sonnet 4.5
Research Hub Query Summarization: Claude Haiku 4.5
Research Hub Query Summarization (Gov data center): Claude Sonnet 4.5

Topic Hierarchy Generator
Old Model: GPT-4o
New Model: Claude Sonnet 4.5

Video Feedback Automated Summaries
Old Model: GPT-4o
New Model: Claude Sonnet 4.6; Claude Sonnet 4.5 (Gov data center)

If you have any questions please reach out to your account team.


AI Model Updates - AI-Assisted Workflows and AI Response Task

Qualtrics AI features - AI-Assisted Workflows and AI Response Task - are updating their models to the following:

AI-Assisted Workflows
Old Model: Claude 3.5 Sonnet (Anthropic)
New Model: Claude 4.5 Sonnet (Anthropic)

AI Response Task
Old Model: Claude Sonnet (version differs based on region) (Anthropic)
New Model: Claude Sonnet 4.5/4.6 (Anthropic)

If you have any questions please reach out to your account team.


Statement on NGINX Rift: No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2026-42945. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Qualtrics Achieves IL4 Provisional Authorization

Qualtrics has secured Impact Level 4 (IL4) Provisional Authorization from the Defense Information Systems Agency (DISA) for the Qualtrics XM platform. This signifies a critical milestone in our continued commitment to delivering resilient, secure, and trusted experience solutions for the U.S. Department of Defense (DoD) and other government partners.

This authorization confirms that the Qualtrics platform meets the federal requirements for handling Controlled Unclassified Information (CUI) at Impact Level 4. IL4 systems are configured to support mission-critical efforts requiring robust confidentiality and integrity standards, strengthening trust in our environment where operational assurance is vital.

Qualtrics is now positioned to support efforts aligned with higher security baselines, alongside our existing FedRAMP High authorization. Collectively, these qualifications allow Qualtrics to support more comprehensive security postures for the dynamic demands of the defense and federal agencies navigating high-impact missions.

This milestone affirms our ongoing commitment and investment in strengthening platform security and safeguarding customer data.


Axios Supply Chain Compromise Update: Qualtrics Response

At Qualtrics the trust of our clients is our top priority. Your trust in us to secure your sensitive information is the foundation of our commitment to you, and we pledge to be open about our security practices, methodologies, and incident response protocols.

We were recently made aware of a security incident regarding a supply chain compromise associated with the “axios" NPM packages. An unknown attacker hijacked the account of a lead developer for Axios. Axios is a foundational software building block (a JavaScript library) with over 100 million weekly downloads.

The attackers published malicious versions (1.14.1 and 0.30.4) that contained a hidden Remote Access Trojan (RAT), malware designed to grant attackers remote control over a victim's machine and immediately scrape passwords, security tokens, and environment variables. Experts estimate these poisoned versions saw up to 600,000 downloads globally before being removed, making this one of the most impactful software supply chain attacks on record.

Qualtrics Impact

Qualtrics is one of many companies that have been impacted by this incident. As soon as Qualtrics learned of the event we automatically kicked off a targeted threat hunt across our entire environment. This automation allowed us to rapidly identify the specific "Indicators of Compromise" (IOCs) associated with the attacker's infrastructure.
Our investigation identified that a small number of internal testing/build systems downloaded the malicious software package from an external repository. Further network analysis showed that some of these systems successfully communicated with the attacker’s infrastructure and downloaded a small, secondary payload. All identified have all been isolated and subsequently decommissioned.
Through the rapid hunt and identification of the issue Qualtrics security was able to react quickly and drastically reduce the risk of the attackers moving throughout our network.
We can confirm this incident did not result in disruption of Qualtrics services

Qualtrics Response

The attack's nature necessitated an aggressive response, leading Qualtrics to immediately adopt an "assume breach" security posture. We have not, however, found any evidence of customer impact or data exfiltration.

As part of our response Qualtrics:

  • Inventory and Blocking: An inventory of Qualtrics' usage of the compromised axios and plain-crypto-js packages was conducted, and blocks were implemented to prevent further deployment of the affected package versions.
  • Attacker Infrastructure Disruption: All IP addresses and domains associated with the attacker were blocked.
  • Host Containment: Identified hosts containing the affected packages were contained and subsequently decommissioned.
  • Proactive Security Measures: All secrets associated with the compromised servers were aggressively rotated as a precautionary measure.
  • Verification of Non-Exfiltration: Network traffic and data egress logs were analyzed, confirming that no sensitive or meaningful data was exfiltrated from the environment.
  • Ongoing Monitoring: Continuous hunting and alerting capabilities were initiated to proactively identify and respond to any future malicious activity.

We're Here to Help

We take our responsibility to protect our customers’ data very seriously. This incident has reinforced the importance of our ongoing efforts to maintain a robust security posture. We are continuously reviewing and updating our security protocols to ensure we are prepared to meet the challenges of an ever-evolving threat landscape at the highest standard.

We understand you may have questions about this incident. Please do not hesitate to reach out to your account team or our support team.


Update to Research Hub AI Models

Research Hub is adding new AI capabilities to the feature which will leverage GPT-4o. Once released, the "Allow Research Hub Summarization" permission, which is being renamed to "Use Research Hub AI Insights" will use Claude V3 Haiku (already in use) and GPT-4o (new) to power the Research Hub AI capabilities. You can find more details on models in use here.


Statement on GlassWorm FORCEMEMO Campaign: No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified threats associated with the FORCEMEMO campaign. Our findings indicate that the Qualtrics Platform is not affected by these threats.


Statement on pac4j-jwt Authentication Bypass Vulnerability: No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2026-29000. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Qualtrics GovRAMP Authorization

Qualtrics is pleased to announce our GovRAMP Authorized status for FY2026, granted by the GovRAMP Program Management Office (PMO) and the GovRAMP Approvals Committee following their assessment of the Qualtrics XM Platform. The platform is categorized at the High security impact level under GovRAMP.

This designation reflects Qualtrics’ continued commitment to maintaining strong security standards and practices in support of our public sector customers.

For more information, or to request our security package and documentation related to FedRAMP and GovRAMP, please submit a request through our Intake Form.

We appreciate the continued trust our customers place in us and remain committed to maintaining strong security practices and responsible stewardship of customer data.


Qualtrics’ Customer Trust team has released new content

Qualtrics' Customer Trust team has published five new AI Feature Guidebooks for XM Discover:

Our AI Feature Guidebooks aim to supplement the other AI insights and documentation available on our Trust Center and alluded to in the "Spotlight On: Qualtrics’ commitment to secure and private AI" Announcement in this same section of our Trust Center, with feature specific insights on themes and topics which are top of mind for our customers as it pertains to AI features e.g. AI feature category, AI type, feature usage and data involved, customer's control over inputs, prompts and outputs, an overview of the end user experience, privacy considerations for the feature and a data flow diagram with supporting written description.

The intended audience is a customer's brand administrator(s) and/or authorised user(s) of Qualtrics product offerings, who are responsible for the platform's feature usage, permissioning, or day to day usage/program management efforts. Additionally, it is useful supporting material for a customer's vendor risk management efforts e.g. third party due diligence assessments or security questionnaires, etc., including AI focused due diligence.


Qualtrics x CrowdStrike Falcon Integration

At Qualtrics, trust is the foundation of every great customer and employee experience. To further our commitment to data security and privacy, we are excited to announce a new integration between the Qualtrics XM Platform and CrowdStrike Falcon® Shield.

As organizations increasingly leverage AI to power experience programs, securing the underlying data is more critical than ever. This integration provides a new layer of protection by bringing real-time visibility and automated security to your Qualtrics environment.

Key benefits include:

  • Real-Time Visibility: Continuous monitoring of user activity, permissions, and configurations to detect risks instantly.
  • Automated Protection: Proactive identification of misconfigurations, unusual access, or bot activity with policy-based remediation.
  • Unified SaaS Security: A consolidated view of risk across your experience programs within the CrowdStrike ecosystem.

For full details on this partnership, you can read the official announcement here.

Learn More & Get Support
We remain dedicated to maintaining the highest standards of security and ethics. For more information regarding our security protocols, please visit the Qualtrics Trust Center, where you can also find our FAQ to answer questions you may have about this new integration.

Thank you for being part of our journey.


Statement on OpenSSL Buffer Overflow Vulnerabilities: No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2025-15467 and CVE-2025-11187. Our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.


Statement on Oracle WebLogic Proxy Plug-ins Vulnerability: No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2026-21962. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Statement on Kyverno Vulnerability - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2026-22039. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Statement on MongoDB Vulnerability - CVE-2025-14847 Affected - No Customer Impact

Impact Assessment
CVE Identifier: CVE-2025-14847
Affected Products: Engage Platform, Discover Platform

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with "MongoDB" CVE-2025-14847. Our findings indicate that the Qualtrics XM Platform was affected by this vulnerability. However, there is no customer impact.

Remediation
After confirming the issue and identifying the scope of impact, Qualtrics have taken the following actions to remediate the vulnerability:

Immediately began an inventory of Qualtrics' use of MongoDB
Upgraded vulnerable versions of MongoDB
Initiated ongoing hunting and alerting to identify malicious activity

For more details please see the following:
MongoDB Advisory
Ubuntu Advisory
Wiz blog post


Statement on React2Shell - CVE-2025-55182/CVE-2025-66478 Affected - No Customer Impact

Impact Assessment
CVE Identifier: CVE-2025-55182 and CVE-2025-66478
Affected Products: Engage Platform, Discover Platform

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with “React2Shell” CVE-2025-55182 and CVE-2025-66478. Our findings indicate that the Qualtrics XM Platform was affected by this vulnerability and fully remediated. However, there is no customer impact.

Remediation
After confirming the issue and identifying the scope of impact, Qualtrics completed the following actions to remediate the vulnerability and is now no longer impacted:

Immediately began an inventory of Qualtrics’ use of React and Next.js
Upgraded vulnerable versions of React and Next.js
Deployed WAF rules to block malicious requests
Initiated ongoing hunting and alerting to identify malicious activity - using available indicators of compromise we identified no evidence of malicious activity or customer impact.

Remediation Completed: December 5, 2025

CVE Description
On December 3, 2025 React publicly disclosed a critical vulnerability (CVSS 10) in the React Server Components (RSC) "Flight" protocol that impacts the React 19 ecosystem and frameworks that utilize this protocol, with Next.js being the most notable example.

For more details please see the following:

React Advisory
React2Shell
Next.js Advisory
Wiz blog post
Palo Alto Unit 42 blog post


Statement on “Shai-Hulud 2.0” Compromised NPM Packages

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with the “Shai-Hulud 2.0” NPM package versions listed below. As of the date of this publication, our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.

For more details on the Shai-Hulud 2.0 packages see Wiz's blog post.


Gainsight & Salesforce Security Incident: No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the unusual activity associated with the Gainsight integration into Salesforce. While Qualtrics integrates Gainsight into Salesforce, our findings indicate that Qualtrics is not affected by this incident.

Incident Description
Gainsight Incident Advisory
Salesforce Incident Advisory


Statement on Windows Server Update Services Vulnerability: No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-59287. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Statement on F5 Security Incident: No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with the recent F5 Security Incident. Upon learning of the issue on October 15, 2025, Qualtrics immediately updated all devices to the latest version. Following an investigation into the recent third-party vendor security incident, we have confirmed that the impact is isolated to specific software versions previously identified as vulnerable. As of the date of this publication, our findings show that the Qualtrics Platform is not affected by this incident.


Statement on Oracle E-Business Data Theft: No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-61882. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.

For more information, please review Oracle’s security alert advisory.


Statement on the Redis Vulnerability: No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-49844. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Compromised NPM Packages - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with the NPM package versions listed below. Our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.

See CISA’s alert for more details on the Shai-Hulud packages and JFrog’s blog post for more details about the other affected packages.


Chaos Mesh Vulnerabilities - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2025-59358, CVE-2025-59359, CVE-2025-59360, CVE-2025-59361. Our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.


Citrix NetScaler Vulnerability - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-7775. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Salesloft Drift Update: Qualtrics Response

We were recently made aware of a security incident in a Salesloft application used by Qualtrics to automate and integrate workflows in Salesforce. Salesloft experienced a security breach, which led to unauthorized access to Salesforce data.

Qualtrics is one of many companies that have been impacted by this incident. The incident was isolated to the Salesforce environment. Some business information stored in Salesforce, including names and email addresses and in limited cases phone numbers, company names, and other business identifiers, was impacted. In a very limited number of instances potentially sensitive information was accessed, and we have already followed up directly with those impacted.

We can confirm this incident was not a breach of Qualtrics’ products or services. We have validated that no customer data in the Qualtrics platform has been impacted by this incident.

You can view our comprehensive statement here.


ISO 42001 Certification

Qualtrics is pleased to announce that we have officially achieved the ISO 42001 certification for our AI management systems. This is a major milestone for our organization and a testament to our unwavering commitment to developing and deploying AI responsibly and ethically.

ISO 42001 is the international standard for AI management systems. This certification demonstrates that our approach to AI development, deployment, and governance aligns with the highest international benchmarks for managing AI risks and opportunities.

What This Means for You
This achievement is a clear signal of our dedication to trust, transparency, and accountability. By adhering to the principles of ISO 42001, we ensure that:

  • Our AI systems are developed and managed ethically and responsibly.
  • We have robust processes in place to identify and mitigate potential risks.
  • Our AI governance is transparent, auditable, and aligned with international best practices.
  • We are building a future where AI is a force for good, built on a foundation of integrity.

This accomplishment reflects our collective effort to build a culture of responsible AI.

Our certification is available here.

Thank you for being a part of our journey. We look forward to continuing to innovate and lead with responsibility.


SonicWall Vulnerabilities - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2024-40766 and CVE-2023-44221 . Our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.


Microsoft Exchange Vulnerability - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-53786. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


FedRAMP High Authorization

Qualtrics has received FedRAMP High authorization, which gives federal agencies access to new capabilities that improve service delivery and increase organizational efficiency. See here for additional details.


SharePoint Vulnerabilities - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2025-53770 and CVE-2025-49706. Our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.


Citrix NetScaler Vulnerability - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-5777. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


AI Feature Model Update

Relevant Feature:
Comment Summaries

Background:
As part of our ongoing commitment to transparency and to keep customers informed about updates specific to our AI features, we will be updating the underlying model/operation of relevant AI features. Modifications of this nature allow us to fine tune the performance, security, privacy and ongoing evolution of our AI features.

Specifics:
By the end of June 2025, Comment Summaries will transition to a hybrid model. Currently, a third-party model (provided, trained, and hosted by a subprocessor) is used. Moving forward, a first-party model (proprietary Qualtrics fine-tuned and hosted) will be used in combination with the third-party model ChatGPT-4.0 in order to improve feature performance and support multiple languages.

Further Details:
See the "Spotlight On: Qualtrics’ commitment to secure and private AI" Announcement on our Trust Center for Qualtrics' AI resources. The relevant Feature Guidebook in scope for this change will be updated in line with timeline referenced above, such artifacts are accessible via the "Security & Privacy Documentation" section of the Trust Center.


AI Feature Model Update

Relevant Feature:
Insights Explorer

Background:
As part of our ongoing commitment to transparency and to keep customers informed about updates specific to our AI features, we will be updating the underlying model/operation of Insights Explorer. Modifications of this nature allow us to fine tune the performance, security, privacy and ongoing evolution of our AI features.

Specifics:
Previously, Insights Explorer used a combination of first party (Proprietary Qualtrics fine-tuned and hosted) and third party (Provided, trained and hosted by a subprocessor) models. Whilst that general configuration is remaining in place, the extent of first party model involvement is increasing, namely for report generation. The First party model routing posture is based on the combination of language of the input data and the template type selected within the feature, per a customer's use case(s). These changes will be finalised by the end of June '25.

Further Details:
See the "Spotlight On: Qualtrics’ commitment to secure and private AI" Announcement on our Trust Center for Qualtrics' AI resources. The relevant Feature Guidebook in scope for this change will be updated in line with timeline referenced above, such artifacts are accessible via the "Security & Privacy Documentation" section of the Trust Center.


Cisco Identity Services Engine Vulnerability

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-20286. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Versa Concerto Vulnerabilities - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-34025, CVE-2025-34026, CVE-2025-34027. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Qualtrics’ Field Security team has released new content

Update #1

Qualtrics' Field Security team has published 3 new AI resources, including 2 new AI Feature Guidebooks:

Update #2

We have revamped the "Spotlight On: Qualtrics’ commitment to secure and private AI" Announcement on our Trust Center to emphasise the insightful and efficient material available to enable an organization to adequately assess Qualtrics, our AI powered features, a customer’s use case(s), and how they may all intertwine in a manner that’s compliant with a customer’s own commitments.

Whether you’re an end user within Qualtrics’ cloud service, performing a vendor risk assessment, asking security questions, seeking legal or privacy approvals within your organization, etc., and have thought something along the lines of;

“I’m interested in Qualtrics’ AI features, but I need to meet my own company’s compliance requirements. Where do I start, what do I do next?”

We recommend flowing down through our newly published “3 Tier Waterfall” approach, and the resources alluded to in each tier therein, as described in the updated Announcement.


The intended audience for both updates is a customer's brand administrator(s) and/or authorised user(s) of Qualtrics product offerings, who are responsible for the platform's feature usage, permissioning, or day to day usage/program management efforts. Additionally, it is useful supporting material for a customer's vendor risk management efforts e.g. third party due diligence assessments or security questionnaires, etc., including AI focused due diligence.


Fortinet Vulnerability - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-32756. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


LangFlow Vulnerability - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-3248. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


SAP NetWeaver Vulnerabilities - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2025-31324 and CVE-2025-42999. Our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.


Craft CMS Vulnerabilities - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2024-58136 and CVE-2025-32432. Our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.


Commvault Vulnerabilities - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2025-34028 and CVE-2025-3928. Our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.


Erlang/OTP Vulnerability - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-32433. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Kubernetes Vulnerabilities - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2025-1974, CVE-2025-24513, CVE-2025-24514, and CVE-2025-1098. Our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.


SAMLStorm Vulnerability - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2025-29775 and CVE-2025-29774. Our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.


Qualtrics’ Field Security team has released new content

Qualtrics' Field Security team has published Qualtrics' Cloud Security & Privacy Framework v9. This artefact represents a customer facing summary of our internal policies and security practices across recognised control domains i.e. It details our platform, its features and our security posture, along with privacy and compliance considerations. It is an update to our prior edition, which was v8.2.

The intended audience is a customer's brand administrator(s) and/or authorised user(s) of Qualtrics product offerings, who are responsible for the platform's security configurations or day to day usage/program management efforts. Additionally, it is useful supporting material for a customer's vendor risk management efforts e.g. third party due diligence assessments or security questionnaires, etc.

Below are the highlights of some key changes captured in the newest version:

  • Entirely new elements;
    • Artificial Intelligence (AI) & Machine Learning (ML) section
    • 'Useful tips' have been added throughout the document, pointing to additional security documentation or our support pages, per applicable topic, etc.
  • Sections which have been updated to align with updates to internal policies;
    • Asset Management
    • Business Continuity & Disaster Recovery
    • Endpoint Protection
    • Vulnerability Management
  • Sections which have been revamped to align with the current state of the nature of our services;
    • Introduction to the Organization
    • Introduction to the Platform
    • Service Descriptions
    • Backup Management
    • Data Management
    • Identity & Access Management
    • Network Operations (Including a new diagram of the platform)
    • Using the Service
    • Appendix A: Notes for XM Discover
    • Individual niche privacy appendices have been removed
  • General fine-tuning;
    • Language, formatting and consistency has been refreshed througout
    • Common 'buzzwords' or terminology our customers typically look for have been added, as applicable for certain sections

Qualtrics’ Field Security team has released new content

Qualtrics' Field Security team has published four new AI Feature Guidebooks:

Our AI Feature Guidebooks aim to supplement the other AI insights and documentation available on our Trust Center and alluded to in the "Spotlight On: Qualtrics’ commitment to secure and private AI" Announcement in this same section of our Trust Center, with feature specific insights on themes and topics which are top of mind for our customers as it pertains to AI features e.g. AI feature category, AI type, feature usage and data involved, customer's control over inputs, prompts and outputs, an overview of the end user experience, privacy considerations for the feature and a data flow diagram with supporting written description.

The intended audience is a customer's brand administrator(s) and/or authorised user(s) of Qualtrics product offerings, who are responsible for the platform's feature usage, permissioning, or day to day usage/program management efforts. Additionally, it is useful supporting material for a customer's vendor risk management efforts e.g. third party due diligence assessments or security questionnaires, etc., including AI focused due diligence.


Apache Parquet Vulnerability - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-30065. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Next.js Vulnerability - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-29927. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Oracle Cloud Incident - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to reports of Oracle Cloud’s potential security incident. Our findings indicate that the Qualtrics Platform is not affected by this incident.


Qualtrics’ Field Security team has released new content

Qualtrics' Field Security team has published "AI Feature Guidebook - Insights Explorer".

This is the first of our AI Guidebooks, which aim to supplement the other AI insights and documentation available on our Trust Center and alluded to in the "Spotlight On: Qualtrics’ commitment to secure and private AI" Announcement in this same section of our Trust Center, with feature specific insights on themes and topics which are top of mind for our customers as it pertains to AI features e.g. AI feature category, AI type, feature usage and data involved, customer's control over inputs, prompts and outputs, an overview of the end user experience, privacy considerations for the feature and a data flow diagram with supporting written description.

The intended audience is a customer's brand administrator(s) and/or authorised user(s) of Qualtrics product offerings, who are responsible for the platform's feature usage, permissioning, or day to day usage/program management efforts. Additionally, it is useful supporting material for a customer's vendor risk management efforts e.g. third party due diligence assessments or security questionnaires, etc., including AI focused due diligence.


Apache Tomcat Vulnerability - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerability associated with CVE-2025-24813. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


Apache Camel Vulnerabilities - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2025-27636 and CVE-2025-29891. Our findings indicate that the Qualtrics Platform is not affected by this vulnerability.


VMware VMX Vulnerabilities- No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 for VMWare VMX products. Our findings indicate that the Qualtrics Platform is not affected by these vulnerabilities.


Qualtrics’ Field Security team has released new content

Qualtrics' Field Security team has published "Qualtrics - Encryption Practices". This item outlines our encryption practices, standards we target and provides a comparative overview of our base encryption posture, versus our opt-in Data Isolation offering.

The intended audience is a customer's brand administrator(s) and/or authorised user(s) of Qualtrics product offerings, who are responsible for the platform's security configurations or day to day usage/program management efforts. Additionally, it is useful supporting material for a customer's vendor risk management efforts e.g. third party due diligence assessments or security questionnaires, etc.

It is accessible via our Trust Center here.


Ivanti Managed Products Vulnerabilities - No Impact to Qualtrics

Qualtrics Security has conducted a thorough assessment in response to the identified vulnerabilities associated with CVE-2025-0282, CVE-2025-0283, CVE-2025-4427, and CVE-2025-4428 relating to Ivanti Managed Products. The Qualtrics Platform does not use Ivanti Managed Products and is not impacted by these vulnerabilities.


Cleo Managed Products Vulnerability - No Impact to Qualtrics

The Qualtrics Security Operations Center is aware of the following potential vulnerabilities: CVE-CVE-2024-55956 & CVE-2024-50623 relating to Cleo managed file transfer products Harmony, LexiCom, and VLTrader. The Qualtrics Platform does not use Cleo managed file transfer products, and is not impacted by this vulnerability.


New Content: Qualtrics' 2024 SOC 2 Type II Report

As of December 18th, Qualtrics' SOC 2 Type II report for 2024 is now available to approved users within our Trust Center.

The report is available for review here. This document can also be found in the "Documents for All Products" folder.


Qualtrics’ Field Security team has released new content

Qualtrics' Field Security team has published "Recommended Security Practices for Implementing & Operating Qualtrics XM Platform". This item provides an overview of key security control domains, and recommended practices, based on industry recognised frameworks, and how these concepts can be applied to a customer's usage, and preferred settings, within Qualtrics XM platform offerings.

The intended audience is a customer's brand administrator(s) and/or authorised user(s) of Qualtrics product offerings, who are responsible for the platform's security configurations, or, day to day usage/program management efforts. Additionally, it is useful supporting material for a customer's vendor risk management efforts e.g. third party due diligence assessments or security questionnaires, etc.

It is accessible via our Trust Center here.



Offerings and Highlights

AI at Qualtrics: Tier 1 resources

Qualtrics' XM platform offers artificial intelligence (AI) powered functionality to analyze massive datasets, uncover hidden patterns and relationships, and drive innovation and improvement for our customers. Whether you’re an end user within Qualtrics’ cloud service, performing a vendor risk assessment, asking security questions, seeking legal or privacy approvals within your organization, etc., and have thought something along the lines of:

“I’m interested in Qualtrics’ AI features, but I need to meet my own company’s compliance requirements. Where do I start, what do I do next?”

We recommend flowing down through our “3 Tier Waterfall” approach, and the resources alluded to in each tier therein;

These support pages detail the AI features we offer, permissions required to utilise them and the models in use, along with any subprocessors involved.

This was the first internationally recognised certification for AI management systems (AIMS) and it is only held by a small number of Organizations globally at present. It sets out a practical framework for organizations to govern AI responsibly, manage risks and promote ethical and trustworthy AI practices. Qualtrics' assessment against the framework's requirements demonstrates that our approach to AI development, deployment and governance aligns with international benchmarks for managing AI risks and opportunities.

AI at Qualtrics: Tier 2 resources

This document outlines Qualtrics’ comprehensive framework for AI security, privacy and compliance, detailing our policies on ethical data use, model governance, testing and training and AI risk management. It explains how we prioritize transparency and security by ensuring customer control over AI feature access, leverage anonymized data for training and maintain robust oversight to meet reputable industry standards like ISO 42001 and NIST AI Risk Management frameworks.

It further features an Appendix which answers the top 20 themes/FAQs we’re seeing from customers globally on AI as it pertains to our services.

AI at Qualtrics: Tier 3 resources

Engage

Discover

These artifacts are feature specific guidebooks, which dive deeper on insights for assessing, understanding and utilizing the precise AI features we offer E.g. AI feature category, AI type, feature usage and data (Likely to be) involved, customer's control over inputs, prompts and outputs, an overview of the end user experience, privacy considerations for the feature and a data flow diagram, with a supporting written description.

FedRAMP High Authorization

Qualtrics is authorized at the FedRAMP High impact level, supporting federal, state, and local government agencies that handle mission-critical and sensitive data. Qualtrics is committed to transparent security practices and the responsible stewardship of government data.

Access is limited to eligible government agencies and is subject to verification. Public sector customers may request access to the Qualtrics FedRAMP High security package here:

Request Access


Curated Knowledge Base


Certifications & Compliance

gdpr
GDPR
ccpa
CCPA
tx-ramp
TX-RAMP
fedramp-high
FedRAMP High

Security & Privacy Documentation


Highlights & Useful Links

One or more annual third-party audit(s)

Annual third-party penetration testing

Has a disaster recovery plan

Uses a centralized IAM solution (SSO) to manage employee access


Security Statement

At Qualtrics, we understand the profound responsibility of safeguarding your data. Your trust in us to secure your sensitive information is the foundation of our commitment to you. This is why security is embedded in our design, philosophy, and daily operations. Our systems are engineered with resilience, designed to withstand and recover from adverse conditions. We operate under the principle of "secure by design," which means creating an architecture that remains secure even if individual components fail.

Security at Qualtrics is a continually evolving discipline. We subject our systems to rigorous internal and external security assessments and penetration tests. These evaluations are not one-time events but part of an ongoing effort to enhance our security posture. We understand the ever-changing threat landscape and commit to staying ahead through constant vigilance and innovation. Access to sensitive data is strictly controlled under the principle of least privilege. Only individuals with a demonstrated need and bound by confidentiality obligations can access this data. We continuously monitor and audit these permissions to ensure the highest standards of accountability and security.

Data protection is paramount. We ensure your data is encrypted in transit and at rest. We employ advanced encryption protocols to maintain the highest levels of data security. Our trusted data center providers also adhere to rigorous industry standards and have earned globally recognized certifications to guarantee further protection. Transparency is critical to building and maintaining trust. We pledge to be open about our security practices, methodologies, and incident response protocols. Our Cloud Security Framework provides a detailed overview of our platform's security features and is backed by numerous globally recognized certifications, ensuring independent oversight and validation of our security controls.

Security is more than just a practice at Qualtrics, it is ingrained in our culture and ethos. We are committed to not just meeting but exceeding industry standards and ensuring you have peace of mind when entrusting us with your data. Maintaining confidentiality, integrity, and availability of your information is not just our responsibility—it is our dedication. We want you to feel reassured and valued when you choose Qualtrics.

Thank you for placing your trust in Qualtrics. We are honored to protect your data and remain steadfast in our mission to provide the highest standards of security. Your trust is not taken for granted, and we appreciate the opportunity to serve you.

Bill Sole

Qualtrics CSO

Powered by Conveyor, the first end-to-end customer trust platform.
Learn more