CB Insights · Trust Center

Cb Insights Trust Center

Trust center

CB Insights maintains a public trust center documenting SOC 2 Type II, GDPR, CCPA, and EU AI Act (deployer obligations) compliance.

Companymarket-intelligenceprivate-company-dataventure-capitalfunding-datainvestor-datacompany-datapeople-databusiness-relationshipspredictive-scoringmcpagent-nativedata-enrichmentsnowflake
Trust center:

Certifications & Compliance

SOC 2 Type IIGDPRCCPAEU AI Act (deployer obligations)

Source

Trust Center

Raw ↑
generated: '2026-08-09'
method: searched
source: https://trust.cbinsights.com/
docs:
- https://trust.cbinsights.com/
- https://www.cbinsights.com/security-and-privacy/
- https://www.cbinsights.com/security/
trust_center:
  url: https://trust.cbinsights.com/
  platform: Vanta
  http_status: 200
  page_title: CB Insights Trust Center
  machine_readable: false
  readability_note: >-
    The trust center is a Vanta-hosted single-page app. It serves the same HTML shell with HTTP 200
    for EVERY path on the host — /api/*, /trpc/*, invented paths — so a 200 there is not evidence
    that any particular document exists, and the certification list, control set and document
    requests all render client-side and could not be read without a browser. Certifications below
    are therefore taken from CB Insights' own server-rendered security page, not from the trust
    center.
  access: >-
    Reports appear to be gated behind a document request (an app.vanta.com/doc?s=... link is present
    in the page shell); no report is downloadable anonymously.
certifications:
- name: SOC 2 Type II
  status: certified
  evidence: '"Our infrastructure is audited and certified to meet the most rigorous standards for data security."'
  source: https://www.cbinsights.com/security-and-privacy/
- name: GDPR
  status: compliant
  evidence: '"We meet the strict requirements of the General Data Protection Regulation for data privacy and protection."'
  source: https://www.cbinsights.com/security-and-privacy/
- name: CCPA
  status: in-progress
  evidence: '"We''re actively preparing to meet CCPA standards."'
  source: https://www.cbinsights.com/security-and-privacy/
- name: EU AI Act (deployer obligations)
  status: in-progress
  evidence: '"...and the EU AI Act for deployers."'
  source: https://www.cbinsights.com/security-and-privacy/
not_claimed:
- ISO 27001
- HIPAA
- PCI DSS
- FedRAMP
security_controls_published:
- AES 256-bit encryption at rest
- TLS 1.2 in transit
- full audit trail of activity
- granular administrative controls on AI features
- SSO, MFA and role-based access control
- AI hallucination testing and observability
ai_data_use:
  statement: '"Your data is never used to train the AI models we use. Period."'
  source: https://www.cbinsights.com/security-and-privacy/
vulnerability_disclosure:
  published: false
  probed:
  - url: https://www.cbinsights.com/.well-known/security.txt
    status: 404
  - url: https://api-docs.cbinsights.com/.well-known/security.txt
    status: 404
  - url: https://mcp.cbinsights.com/.well-known/security.txt
    status: 404
  - url: https://api.cbinsights.com/.well-known/security.txt
    status: 401
  note: >-
    No security.txt, no responsible-disclosure page, and no bug-bounty program (HackerOne, Bugcrowd
    or Intigriti) was found. The published security page names no security contact address; the only
    documented contact anywhere in the estate is the general info@cbinsights.com.
cross_links:
  conformance: conformance/cb-insights-conformance.yml
  domain_security: security/cb-insights-domain-security.yml