AdRoll · Trust Center

Adroll Trust Center

Trust center

AdRoll maintains a public trust center documenting SOC 2, SOC 3, ISO 27001, PCI DSS, GDPR, and CCPA compliance.

AdvertisingDisplay AdvertisingRetargetingMarketingAdTechProgrammatic
Trust center: https://security.nextroll.com/

Certifications & Compliance

SOC 2SOC 3ISO 27001PCI DSSGDPRCCPA

Source

Trust Center

adroll-trust-center.yml Raw ↑
generated: '2026-08-13'
method: searched
probe: true
url: https://security.nextroll.com/
platform: SafeBase
parent_page: https://www.nextroll.com/trust-center
note: >-
  NextRoll runs a real, populated SafeBase trust portal for AdRoll and AdRoll
  ABM. The automated probe in probe-security-programs.py missed it because it
  checks trust.<domain> and <domain>/trust — NextRoll uses security.nextroll.com,
  linked from https://www.nextroll.com/trust-center. Reports themselves are
  request-gated behind SafeBase's NDA flow; the certification inventory below is
  what the portal states publicly.

certifications:
- name: SOC 2
  detail: SOC 2 Type 2 Report
  auditor: Sensiba
  document_available: on request via SafeBase
- name: SOC 3
  detail: SOC 3 Report
  auditor: Sensiba
- name: ISO 27001
  detail: ISO 27001 - 2013
- name: PCI DSS
  auditor: Security Metrics
- name: GDPR
- name: CCPA

assessments:
- {name: CAIQ v4.0.2, kind: self-assessment}
- {name: SIG Lite, kind: self-assessment}
- {name: VSA Full, kind: self-assessment}
- {name: Pentest Report, auditor: HackerOne}

security_ratings_published:
- BitSight
- Black Kite
- CyberVadis
- ImmuniWeb
- RiskRecon
- SecurityScorecard
- UpGuard
- Qualys SSL Labs
- MDN Observatory
- CryptCheck
- CIS Score

program_areas_documented:
- Access Control
- App Security
- Audit Logging
- BC/DR
- Change Management
- Code Analysis
- Corporate Security
- Data Security (encryption at rest and in transit, disk encryption, data classification)
- Endpoint Security (EDR, MDM)
- Incident Response
- Infrastructure (AWS, VPC, WAF, anti-DDoS, IDS/IPS, separate production environment, zero trust)
- Network Security
- Physical Security
- Product Security
- Risk Management
- Software Development Lifecycle
- Subprocessors
- Vulnerability & Patch Management
- AI

policies_listed:
- Acceptable Use Policy
- Access Control Policy
- Backup Policy
- Data Classification Policy
- Encryption Policy
- Incident Response Policy
- Information Security Policy
- Physical Security Policy
- Risk Assessment/Management Policy
- Software Development Lifecycle Policy

privacy:
  privacy_portal: https://nextroll-privacy.relyance.ai/
  dpo_contact: dpo@nextroll.com
  gdpr_page: https://www.nextroll.com/trust-center/gdpr
  privacy_policy: https://www.nextroll.com/privacy
  your_privacy_choices: https://www.nextroll.com/your-privacy-choices

evidence:
- source: https://security.nextroll.com/
  http_status: 200
  keywords: [SOC 2, SOC 3, ISO 27001, PCI DSS, GDPR, CCPA, Pentest Report, Responsible Disclosure, SafeBase]
- source: https://www.nextroll.com/trust-center
  http_status: 200
  keywords: [Trust Center, Security portal, GDPR, CCPA]

x-evidence:
  checked: '2026-08-13'