Comparison Overview

SUNPAN

VS

JOHN POMP

SUNPAN

875 Middlefield Road, Toronto, M1V 4Z5, CA
Last Update: 2025-11-21
Between 750 and 799

SUNPAN is a fast-growing global furniture company specializing in the design and manufacturing of modern and transitional furnishings. At SUNPAN we are committed to understanding fashion and design in order to offer a diverse selection of high-end looks at affordable prices. Our products are thoughtfully designed and crafted with renowned international designers to create modern and transitional styles across hard goods, dining, upholstery and art. The use of various mixed materials creates a unique and versatile line of products suitable for both contract and residential settings. SUNPAN is a recognized Great Place to Work®, as certified by Great Place to Work Institute® Canada. Mission: To design and distribute innovative and affordable on-trend furniture for inspired spaces around the world. Vision: Continuously strive to grow our business in a profitable and healthy way for long term stability and success. Values: PASSION: Anticipate change and shape it to improve what we do. INNOVATION: Take initiative and ownership in what we do. ACCOUNTABILITY: Be honest and ethical in everything we do. INTEGRITY: Work collectively and provide support in all that we do. TEAMWORK: Achieve results and celebrate when we do. Sunpan welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process.

NAICS: 337
NAICS Definition: Furniture and Related Product Manufacturing
Employees: 115
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

JOHN POMP

2135 E Westmoreland St, Philadelphia, Pennsylvania, 19134, US
Last Update: 2025-11-27
Between 750 and 799

John Pomp is a design-driven artisan manufacturer focused on creating abstracted organic works of furniture and lighting. Inspired by elemental materials in transitory states and informed by almost otherworldly natural phenomena, John Pomp’s work combines molten glass, warped metal, and refracted light to create imaginative, organic forms. Led by designer, artist, and glassblower John Pomp with his partner Anne, a team of over 50 creatives design and make each piece from concept to completion in-house. With a sculptural, experimental approach to design, the work develops through a non-linear process explored through various methods, including abstract glass studies, organic form generating, and process discovery. This approach leads to a designed process rather than a product. Each piece is made from scratch in their 65,000 sqft Philadelphia studio using a combination of modern techniques and old-world craftsmanship. Working out of his studio in Philadelphia, John together with his wife, Anne, and their team of over 40 creatives, design and create each and every piece from concept to completion in-house, providing a proprietary look and feel that can only be achieved by owning the processes that combine to make the studio’s sculptural work. Using these processes as a source of inspiration, rather than a means to an end, the studio explores the relationship between fluid materials. By owning all their manufacturing processes in their Philadelphia studio, they are able to create and customize any piece for their clients.

NAICS: 337
NAICS Definition:
Employees: 28
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/sunpan.jpeg
SUNPAN
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/john-pomp-studios.jpeg
JOHN POMP
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
SUNPAN
100%
Compliance Rate
0/4 Standards Verified
JOHN POMP
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Furniture and Home Furnishings Manufacturing Industry Average (This Year)

No incidents recorded for SUNPAN in 2025.

Incidents vs Furniture and Home Furnishings Manufacturing Industry Average (This Year)

No incidents recorded for JOHN POMP in 2025.

Incident History — SUNPAN (X = Date, Y = Severity)

SUNPAN cyber incidents detection timeline including parent company and subsidiaries

Incident History — JOHN POMP (X = Date, Y = Severity)

JOHN POMP cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/sunpan.jpeg
SUNPAN
Incidents

No Incident

https://images.rankiteo.com/companyimages/john-pomp-studios.jpeg
JOHN POMP
Incidents

No Incident

FAQ

SUNPAN company demonstrates a stronger AI Cybersecurity Score compared to JOHN POMP company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, JOHN POMP company has disclosed a higher number of cyber incidents compared to SUNPAN company.

In the current year, JOHN POMP company and SUNPAN company have not reported any cyber incidents.

Neither JOHN POMP company nor SUNPAN company has reported experiencing a ransomware attack publicly.

Neither JOHN POMP company nor SUNPAN company has reported experiencing a data breach publicly.

Neither JOHN POMP company nor SUNPAN company has reported experiencing targeted cyberattacks publicly.

Neither SUNPAN company nor JOHN POMP company has reported experiencing or disclosing vulnerabilities publicly.

Neither SUNPAN nor JOHN POMP holds any compliance certifications.

Neither company holds any compliance certifications.

Neither SUNPAN company nor JOHN POMP company has publicly disclosed detailed information about the number of their subsidiaries.

SUNPAN company employs more people globally than JOHN POMP company, reflecting its scale as a Furniture and Home Furnishings Manufacturing.

Neither SUNPAN nor JOHN POMP holds SOC 2 Type 1 certification.

Neither SUNPAN nor JOHN POMP holds SOC 2 Type 2 certification.

Neither SUNPAN nor JOHN POMP holds ISO 27001 certification.

Neither SUNPAN nor JOHN POMP holds PCI DSS certification.

Neither SUNPAN nor JOHN POMP holds HIPAA certification.

Neither SUNPAN nor JOHN POMP holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.

Risk Information
cvss4
Base: 6.2
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).

Risk Information
cvss3
Base: 9.9
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

Description

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.