Blog

A guide to Perplexity security

WitnessAI | August 4, 2026

Perplexity is increasingly moving from consumer answer engine into enterprise AI workflows, and security leaders now need a practical view of what Perplexity security requires.

If you’re already reviewing AI vendors on tight timelines, you’ve seen this split before: under the shared responsibility model, Perplexity supplies controls through its Enterprise tier. The organization remains responsible for how employees use the tool.

That responsibility split matters most when employees move between approved enterprise use and personal accounts. Consumer and enterprise tiers carry different contractual protections. The Comet agentic browser adds AI-native security considerations such as prompt injection and sensitive information disclosure. Much of this activity also happens outside the view of traditional security tooling built for traffic, files, and static data rather than AI conversations and intent.

Below, you’ll find where Perplexity Enterprise controls end and where AI risk management picks up the work of closing the distance between written policy and actual usage.

Key takeaways

  • Perplexity security is a shared-responsibility problem: Perplexity supplies Enterprise controls, while organizations govern how employees and agents actually use the tool.
  • Enterprise protections depend on verified configuration, including identity controls, admin settings, audit trails, retention terms, and contractual limits on training use.
  • Consumer accounts and Comet sessions create the highest governance gaps because personal usage lacks enterprise oversight and agentic browsing can act inside authenticated sessions.
  • Effective AI governance requires visibility at the interaction layer, where prompts, responses, account type, and agent behavior can be observed and governed in real time.

What is Perplexity security?

Perplexity security combines the protections Perplexity builds into its platform with the enforcement an organization applies to usage. Perplexity provides certifications, retention controls, identity management, and audit trails. Your controls decide whether employees use approved tiers and how prompts or autonomous sessions handle company data.

Enterprise and consumer accounts operate under different contractual and administrative models. The same practical pattern appears in broader Shadow AI research: personal-account submissions typically lack enterprise contractual protection and auditability. An employee’s choice of login therefore determines which control model corporate data falls under.

Perplexity now extends beyond a search-and-answer interface. Its Comet browser adds agentic browsing, where an AI assistant reads pages, follows instructions, and takes actions inside the user’s authenticated web sessions. Evaluating Perplexity security means looking at each layer separately, because assurances at one layer don’t transfer to the others.

What Perplexity Enterprise secures on its side of the line

Perplexity’s enterprise tier addresses the provider half of the responsibility split with retention controls and admin settings. Audit trails give security teams a review path. Enterprise packages can include zero data retention and granular admin controls. The Perplexity enterprise package includes those controls. HIPAA-sensitive workflows may require organizations to execute a BAA before PHI processing.

Before rollout, procurement and security teams should verify how the controls work in practice:

  • Identity management should match the organization’s access model. That includes how users are provisioned, deprovisioned, and assigned to approved Perplexity tiers.
  • Administrative controls should cover file uploads and answer sharing. These settings determine whether sensitive data can move into prompts, uploaded documents, projects, or shared outputs.
  • Audit trails should support tracking user activity. They help security and compliance teams reconstruct how approved accounts were used.

On training, the enterprise agreement should be checked for an explicit prohibition on using customer data to train models.

Data retention is scoped, and enterprise packages can include zero data retention. Validate plan-specific retention and deletion commitments before rollout, especially for uploaded files, projects, repositories, or Comet sessions. You should also confirm third-party model-provider terms, downstream training restrictions, and data-processing commitments for selling or sharing personal data. You should verify whether that data can be combined with other data.

Depending on plan and query, requests may be processed by third-party models. These controls answer the questions a procurement security questionnaire asks. Usage questions still remain: which employees use which tier and what data they paste into prompts. For agentic use, teams also need to know how a session acts inside an authenticated system.

WitnessAI for Compliance
FOR COMPLIANCE

What Does AI Compliance Look Like?

WitnessAI automatically logs every AI interaction, masks sensitive data in real time, and enforces regulatory policies across every region and business line. Audit-ready from day one.

See WitnessAI For Compliance

Where Perplexity security responsibility shifts to the enterprise

Under the shared responsibility model, the provider secures the models and infrastructure while prompt controls and Shadow AI detection remain the customer’s job. Perplexity’s growing workplace footprint makes that customer-side work pressing.

Employee behavior creates most of the control work, especially when personal accounts or agentic features enter the workflow. The three areas below show where that work concentrates.

1. Consumer tiers train on inputs by default

Consumer accounts can operate outside enterprise contractual, retention, and audit conditions. Training use, retention, auditability, and contractual protection are separate controls, so you should validate current terms and opt-out settings before corporate data enters any non-enterprise session.

Enterprise contractual protections don’t follow corporate data into a personal account. When an employee pastes a customer list into a personal session, the data sits outside the enterprise contract, may not be practically recoverable, and typically leaves no enterprise audit trail.

2. Comet turns browsing into an attack surface

Researchers have documented indirect prompt injection against Comet, and in those tests, untrusted content could turn into action:

  • Instructions hidden in content can cause Comet to reach into logged-in email sessions. In tests, those instructions caused Comet to copy one-time passcodes. Other tests showed that when a user asked Comet to summarize an attacker-controlled page, it could follow embedded instructions such as reading emails from a connected account in another tab or extracting data and posting it to an external server.
  • Other tests have shown Comet purchasing fake storefronts. They have also shown Comet being manipulated into extracting account details, retrieving one-time passwords, and posting credentials to an external server. Those examples matter because Comet acts inside an already-authenticated user session.

A formal CVE also exists: CVE-2025-50708 covers sensitive information disclosure through the token in a shared chat URL. These findings point to Comet’s architecture. OWASP ranks prompt injection as the top risk for LLM applications, and Comet executes injected instructions with the user’s authenticated privileges. That can sidestep browser same-origin policy protections. Because Comet can operate across logged-in services, evaluate it as a privileged automation tool.

3. Shadow AI usage outruns security visibility

A Cloud Security Alliance survey of 300 U.S. CISOs found that 67% report limited visibility into how AI is deployed. Not one respondent claimed full visibility in the CSA visibility deficit survey. The same CSA research puts the added cost of a breach related to Shadow AI at $670,000 above a standard incident.

Perplexity fits this pattern because the free tier is a paste away. Tools built to monitor traffic and data movement weren’t designed to distinguish a sanctioned enterprise session from a personal one.

Enforcement has to happen at the interaction layer, at the moment an employee sends a prompt through a given account.

WitnessAI Observe
OBSERVE

Your Employees Use 5x More AI Tools Than You Think

WitnessAI scans your entire network to catalog every AI app, agent, and conversation. No endpoint clients or browser extensions are required.

See How Observe Works

How AI risk management closes the Perplexity governance gap

Those usage gaps require controls at the interaction layer, where prompts, responses, account type, and agent actions can be observed together. AI risk management is broader than governance or compliance programs alone.

It treats AI interactions, human or autonomous, as behavior to observe and control at runtime based on intent. WitnessAI is a unified AI security and governance platform for observing and controlling enterprise AI use. It helps Global 2000 organizations protect AI activity routed through the platform by observing usage and enforcing controls across human employees and autonomous AI agents.

Applied to Perplexity, the same control framework covers sanctioned enterprise deployments as well as personal-account use or Comet sessions routed through the platform. The three modules below map to the gaps described above.

1. Discover usage across every tier and surface

WitnessAI’s Observe capability provides network-level discovery of AI activity routed through the platform without endpoint clients, browser extensions, or SDK changes.

It catalogs more than 4,000 AI applications and continuously discovers which are in use across the enterprise. Coverage includes native applications and embedded copilots, with developer IDE activity included as well. Roughly 80% of AI activity occurs outside the browser. For agentic tools in the Comet mold, agent and MCP server discovery identifies agentic sessions and maps external tool connections back to a human identity.

This lets teams attribute agent actions to the right user. Visibility at this layer surfaces the personal-account usage that browser-extension approaches weren’t designed to see.

2. Enforce intent-based policies instead of binary blocks

WitnessAI classifies the intent behind interactions routed through the platform using custom ML models. These models analyze conversational context rather than keywords or regex patterns. It then applies one of four actions:

  • Allow permits the interaction to proceed without modification. This keeps approved work moving when the prompt, destination, and user context fit policy.
  • Warn gives the user guidance before the interaction continues. A warning can correct behavior without turning policy into a blunt block.
  • Block prevents the interaction from proceeding. This is appropriate for clear policy violations, prompt injection attempts, or sensitive data exfiltration.
  • Route redirects a sensitive query to an approved internal model instead of a third-party one. The workflow continues while sensitive work stays in an approved environment.

Real-time data tokenization substitutes sensitive values before a prompt leaves the environment, then restores the originals within the secure organizational perimeter so the workflow completes intact. The platform records intelligent policy actions in immutable audit trails. Compliance teams can use those records as evidence that policy was enforced.

3. Defend against prompt injection at runtime

WitnessAI’s Protect module delivers bidirectional runtime defense for protected AI workflows. It scans prompts before processing and responses before delivery. That addresses the same class of attack the Comet research demonstrated: injected instructions arriving through web content with hidden text or manipulated pages.

Guardrails detect prompt injection and jailbreak attacks with 99.3% true positive guardrail efficacy, benchmarked against competitor guardrails and validated in production environments, with standardized protection across more than 100 LLM types. Runtime guardrails complement existing network security controls because they inspect the conversational layer those controls weren’t designed to parse.

WitnessAI Protect
PROTECT

Runtime AI Threats Need Runtime Defense.

WitnessAI’s enterprise AI firewall delivers bidirectional runtime defense, blocking prompt injections, jailbreaks, and data exfiltration before they reach your models or your customers.

Explore Protect

Enabling secure enterprise Perplexity adoption

Perplexity Enterprise handles its half of the split: enterprise contracts, administrative controls, and scoped retention commitments. The organization’s half takes shape when it can see who uses which tier, what data enters prompts, and what agentic sessions do with authenticated access.

For CISOs proving AI control to boards and regulators, and for AI leaders moving Perplexity deployments past risk review, WitnessAI supplies that half through network-level visibility and runtime guardrails backed by intelligent policies for the human and digital workforce.

Schedule a demo to see how WitnessAI supports secure AI adoption across your organization.

FAQs about Perplexity security