Clay · Trust Center

Clay Com Trust Center

Trust center

Clay maintains a public trust center documenting SOC 2 Type II, ISO 27001, GDPR, and CCPA compliance.

ProspectingGo-To-MarketSalesEnrichmentAutomationArtificial IntelligenceWebhook
Trust center: https://trust.clay.com

Certifications & Compliance

SOC 2 Type IIISO 27001GDPRCCPA

Source

Trust Center

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
url: https://trust.clay.com
platform: Vanta
certifications:
- name: SOC 2 Type II
  status: certified
  first_completed: '2024-09-09'
  evidence:
  - url: https://www.clay.com/enterprise
    quote: 'We are SOC 2 Type II compliant. Request our SOC 2 in our Trust Center.'
  - url: https://www.clay.com/blog/clay-is-soc-2-type-2-compliant
    quote: 'Clay has completed our SOC 2 Type 2 audit'
- name: ISO 27001
  status: named
  evidence:
  - url: https://www.clay.com/enterprise
    note: Named in Clay's own enterprise security section.
- name: GDPR
  status: named
  evidence:
  - url: https://www.clay.com/enterprise
    quote: 'Go to market anywhere in the world — let us handle compliance with local laws.'
- name: CCPA
  status: named
  evidence:
  - url: https://www.clay.com/enterprise
    quote: 'Support your customer base with opt out and DNC support.'
report_access: on request via the trust center
privacy_center: https://privacy.clay.com
evidence:
- source: https://www.clay.com/.well-known/security.txt
  kind: security.txt
  http_status: 200
  note: 'Names https://trust.clay.com as both a Contact and the Policy URL — the trust center is the published disclosure destination.'
- source: https://trust.clay.com
  kind: trust-center
  http_status: 200
  keywords: [vanta]
- source: https://www.clay.com/enterprise
  kind: enterprise-security-page
  http_status: 200
  keywords: [soc 2 type ii, iso 27001, gdpr, ccpa]
caveat: >-
  trust.clay.com returns HTTP 200 but is a fully client-rendered Vanta trust page — the
  served HTML contains only the Vanta loader, so the certification list could NOT be read
  out of the response body. The certifications above are therefore recorded from pages
  Clay renders server-side (its enterprise page and its own announcement post), not from
  the trust center itself. The trust center's existence and its role as the security.txt
  Policy target are directly verified; its contents are not machine-readable. That is a
  provider-side gap: an agent evaluating Clay's compliance posture cannot read it.
subprocessors:
  published: true
  location: https://trust.clay.com
  note: Clay states a full list of AI subprocessors is available in the trust center.