The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
Regulatory evidence
Deltek is a leading global provider of enterprise software and information solutions designed to help project-based businesses optimize
For each regulation, how many of the requirements it places on your vendors Deltek’s public evidence reaches. Open one for every item with its date and source.
What the vendor lists, typed; public items can be read now, the rest are available on request.
44 documents listed on Deltek’s trust centre
trust.deltek.comAnswers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Where data is hosted or processed
Where are your data centers located?
“For many Deltek solutions, Deltek stores and processes customer data within cloud environments provided by our cloud providers. A complete list of subprocessors, including their location, is available at: https://www.deltek.com/en/deltek-contracts/general-privacy-terms/subprocessors”
as of 21 Sep 2026Source
International data transfers
How does Deltek handle compliance with international data transfer regulations?
“Deltek ensures compliance with international data transfer regulations by using standard contractual clauses and other legal mechanisms approved by regulatory bodies. This ensures that data transferred between jurisdictions is protected in accordance with applicable data protection laws.”
as of 21 Sep 2026Source
International data transfers
What cross-border data transfer mechanism do you have in place?
“Deltek is an active participant of the EU-US Data Privacy Framework and related extensions. Additionally, Delte is certified under the Asia-Pacific Economic Cooperation (APEC) Privacy Recognition for Processors (PRP) Systems. More information about our cross-border data transfer mechanisms is available on Deltek’s Security and Trust Center at https://www.deltek.com/en/about/security-and-trust/privacy”
Regions named: EU, USas of 21 Sep 2026Source
Encryption
Do you encrypt data at rest?
“Yes, Deltek implements encryption “at rest”. Disk volumes and object stores that are encrypted use industry standard AES-256 ciphers. Database encryption is realized through various technical implementations.”
as of 21 Sep 2026Source
Encryption
Do you encrypt data in transit?
“Yes, Deltek uses strong industry standard encryption technologies to protect Customer Data and communications in transit over the public internet/channels, including 128-bit TLS Certificates and 2048-bit public keys at a minimum. Additionally, during replication, Customer Data is encrypted during transmission between data centers”
as of 21 Sep 2026Source
Penetration testing
Does Deltek allow customers or prospects to conduct independent penetration tests on their system or instance?
“No, Deltek does not allow customers or prospects to conduct independent penetration testing on Deltek systems or customer instances.”
as of 21 Sep 2026Source
Penetration testing
Does Deltek share penetration test results with customers or prospects?
“No, Deltek does not provide full penetration test reports to customers or prospects, as these reports contain confidential and proprietary information about Deltek’s systems, architecture, and security controls. To support customer and prospect due diligence, Deltek may provide alternative assurance artifacts, including a penetration test attestation letter (available upon request through the Deltek Trust Center)...”
as of 21 Sep 2026Source
Penetration testing
Who can customers contact for more information about penetration testing and remediation?
“Customers seeking more information should first visit the Deltek Trust Center to request access to the Penetration Test Attestation Letter, which confirms third-party testing has been conducted. If additional detail is required, such as the Penetration Test Executive Summary or Remediation Timeline, customers should reach out directly to their Customer Success Manager (CSM) who can coordinate the request with the...”
as of 21 Sep 2026Source
Penetration testing
What is penetration testing?
“Penetration testing is a controlled and methodical approach to assessing the security of a production system, network, or application by simulating real-world cyber-attacks. This helps identify vulnerabilities that could be exploited by malicious actors.”
as of 21 Sep 2026Source
Penetration testing
Why does Deltek conduct penetration tests?
“Deltek has a Secure Software Development Lifecycle (SDLC) which implements many security tools, services, and gates throughout an application's development process. A penetration test is one of these services which help identify potential vulnerabilities through a simulated real-world attack. This assessment provides an outside assessment of security posture and identifies potential vulnerabilities which may have...”
as of 21 Sep 2026Source
Penetration testing
How often does Deltek perform penetration testing?
“Penetration testing is performed annually as part of our ongoing security assessment and vulnerability management processes.”
as of 21 Sep 2026Source
Penetration testing
What happens after a penetration test is conducted?
“A report of the penetration test results is provided to Deltek for review. This includes a breakdown of identified findings and corresponding remediation steps. The results are triaged by the Product & Product Security teams to establish validity of the findings, wherein they are put into the specific product backlog where they are prioritized for upcoming interim or major releases. Some findings may be a necessar...”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.