Comparison Overview

Pepsi Bottling Ventures

VS

GoTo Foods

Pepsi Bottling Ventures

4141 Parklake Ave, Raleigh, NC, US, 27612
Last Update: 2025-12-10

Who We Are We are jointly owned by Suntory and PepsiCo. Suntory is a family-owned business founded in Japan more than 125 years ago that is known globally for their beverages and innovative spirit. PepsiCo has a 125-year plus legacy as a global leader in convenient foods and beverages. We represent Suntory’s non-alcoholic beverage industry in the United States and have an 80-year plus legacy of providing PepsiCo products to the Carolinas and beyond. What We Do We make, sell, and distribute PepsiCo and more beverages. We have the exclusive rights to make, sell, and distribute directly to stores in our territory the world-renowned PepsiCo and Keurig Dr. Pepper beverages. These exclusive rights make up the vast majority of our business and cover certain counties across five states. We also create our own beverages, producing and distributing them to our customers’ warehouses nationally. And we make, sell, and distribute to our customers’ warehouses a growing portfolio of beverages nationally. These beverages make up a small, but growing part of our business. What Makes Us Unique We bring you the beverages you love. We bring PepsiCo’s and Keurig Dr. Pepper’s beloved beverages and more to you and our customers. As a part of Suntory, we believe in dreaming big and boldly pursuing our dreams, growing for good, and giving back to society. We innovate to create new beverages, like our Nature’s Twist refreshing lemonade line, and we continuously expand our beverage portfolio to bring you and our customers joy.

NAICS: 722
NAICS Definition: Food Services and Drinking Places
Employees: 4,436
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
1

GoTo Foods

5620 Glenridge Drive, Atlanta, GA, 30342, US
Last Update: 2025-12-09
Between 750 and 799

Atlanta-based GoTo Foods (formerly known as Focus Brands) is a leading developer of global multi-channel foodservice brands. As of December 31, 2023, GoTo Foods, through its affiliate brands, is the franchisor and operator of more than 6,700 restaurants, cafes, ice cream shoppes, and bakeries in all 50 states and over 60 countries and territories under the Auntie Anne’s®, Carvel®, Cinnabon®, Jamba®, Moe’s Southwest Grill®, McAlister’s Deli®, and Schlotzsky’s® brand names, as well as the Seattle’s Best Coffee® brand on certain military bases and in certain international markets. GoTo Foods is proud to be Certified™ by Great Place To Work®, the most definitive “employer-of-choice” recognition and the only recognition based entirely on what employees report about their workplace experience. Please visit www.gotofoods.com to learn more. As a leading developer of iconic food-service brands around the globe, we know our company is only as strong as our people. And that’s why we’re committed to providing our associates with a work environment that encourages and supports innovation, collaboration, and fun! From our unique family culture to our focus on personal development, a career with GoTo Foods is anything but ordinary. We rely on the unique attributes and experiences each of our associates has to offer, we remain focused on providing every individual with continuous opportunities to grow their skills, develop their talents, and unlock their potential as part of a collaborative and supportive team. We’re unleashing the power of our brands with the passion of our people – and we want you to join us!

NAICS: 722
NAICS Definition: Food Services and Drinking Places
Employees: 17,535
Subsidiaries: 8
12-month incidents
0
Known data breaches
1
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/pbvllc.jpeg
Pepsi Bottling Ventures
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/focus-brands.jpeg
GoTo Foods
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Pepsi Bottling Ventures
100%
Compliance Rate
0/4 Standards Verified
GoTo Foods
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Food and Beverage Services Industry Average (This Year)

No incidents recorded for Pepsi Bottling Ventures in 2025.

Incidents vs Food and Beverage Services Industry Average (This Year)

No incidents recorded for GoTo Foods in 2025.

Incident History — Pepsi Bottling Ventures (X = Date, Y = Severity)

Pepsi Bottling Ventures cyber incidents detection timeline including parent company and subsidiaries

Incident History — GoTo Foods (X = Date, Y = Severity)

GoTo Foods cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/pbvllc.jpeg
Pepsi Bottling Ventures
Incidents

Date Detected: 12/2022
Type:Cyber Attack
Attack Vector: External Hacking
Blog: Blog
https://images.rankiteo.com/companyimages/focus-brands.jpeg
GoTo Foods
Incidents

Date Detected: 4/2019
Type:Breach
Attack Vector: Unauthorized code (likely malware or skimming)
Motivation: Financial gain (payment card data theft)
Blog: Blog

FAQ

GoTo Foods company demonstrates a stronger AI Cybersecurity Score compared to Pepsi Bottling Ventures company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Pepsi Bottling Ventures and GoTo Foods have experienced a similar number of publicly disclosed cyber incidents.

In the current year, GoTo Foods company and Pepsi Bottling Ventures company have not reported any cyber incidents.

Neither GoTo Foods company nor Pepsi Bottling Ventures company has reported experiencing a ransomware attack publicly.

GoTo Foods company has disclosed at least one data breach, while Pepsi Bottling Ventures company has not reported such incidents publicly.

Pepsi Bottling Ventures company has reported targeted cyberattacks, while GoTo Foods company has not reported such incidents publicly.

Neither Pepsi Bottling Ventures company nor GoTo Foods company has reported experiencing or disclosing vulnerabilities publicly.

Neither Pepsi Bottling Ventures nor GoTo Foods holds any compliance certifications.

Neither company holds any compliance certifications.

GoTo Foods company has more subsidiaries worldwide compared to Pepsi Bottling Ventures company.

GoTo Foods company employs more people globally than Pepsi Bottling Ventures company, reflecting its scale as a Food and Beverage Services.

Neither Pepsi Bottling Ventures nor GoTo Foods holds SOC 2 Type 1 certification.

Neither Pepsi Bottling Ventures nor GoTo Foods holds SOC 2 Type 2 certification.

Neither Pepsi Bottling Ventures nor GoTo Foods holds ISO 27001 certification.

Neither Pepsi Bottling Ventures nor GoTo Foods holds PCI DSS certification.

Neither Pepsi Bottling Ventures nor GoTo Foods holds HIPAA certification.

Neither Pepsi Bottling Ventures nor GoTo Foods holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

Risk Information
cvss3
Base: 8.1
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Risk Information
cvss3
Base: 2.9
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.10.2 is sufficient to fix this issue. You should upgrade the affected component. The vendor confirms that this is "[f]ixed in version 4.10.2". Furthermore, that "[b]ackports for older versions in process and will be out as soon as their respective CI pipelines complete."

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

Risk Information
cvss3
Base: 4.5
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L
Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Risk Information
cvss3
Base: 5.8
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N