LICENSEWARE
CyberArk Rule

Regulated data restrictions apply to SaaS Products

Catalog row in Vendor License Rules · Cited

Kind
Restriction
Statement
SaaS Terms of Service section 1.2: unless a business associate agreement says otherwise the customer must not store personal health data in the SaaS Products; PCI cardholder data is allowed only in services certified under PCI DSS as listed on the CyberArk Trust Center; ITAR data is excluded. (effective 2026-09-10)
Applies when
Planning data stored in a SaaS service
Applies to
SaaS Products
Esc