Constructor.io · Trust Center

Constructorio Trust Center

Trust center

Constructor.io maintains a public trust center documenting SOC 2 Type 2, ISO 27001, CCPA, and MACH Certified compliance.

CompanySearchEcommerceProduct DiscoveryRecommendationsPersonalizationRetailRetail MediaArtificial IntelligenceMerchandisingCatalog ManagementAgentic Commerce
Trust center: https://constructor.com/security-and-compliance

Certifications & Compliance

SOC 2 Type 2ISO 27001CCPAMACH Certified

Source

Trust Center

Raw ↑
generated: '2026-08-01'
method: searched
probe: true
url: https://constructor.com/security-and-compliance
kind: published security & compliance page (not a gated trust-center portal — there
  is no trust.constructor.com or security.constructor.com; both fail to resolve)
certifications:
- SOC 2 Type 2
- ISO 27001
- CCPA
- MACH Certified
frameworks_referenced:
- OWASP Top 10
- NIST-compliant coding practices
- GDPR
report_access: Reports are released on request through an account executive or customer
  success manager, under a signed non-disclosure agreement. No self-serve document
  portal is published.
practices_published:
- Multi-factor authentication, device trust and strict role-based access management
  for user accounts
- Static application security testing (SAST) and dynamic application security testing
  (DAST) in the SDLC
- Continuous vulnerability scanning of environments and products
- External penetration tests at least once per year
- Routine chaos testing
- DDoS protection
- Data minimization by design — anonymous IDs, last-octet IP truncation, hashed identifiers
evidence:
- source: https://constructor.com/security-and-compliance
  keywords: [soc 2 type 2, iso 27001, ccpa, owasp top 10, penetration test, sast, dast,
    mach certified]
  fetched: '2026-08-01'
gaps_observed:
- No published vulnerability disclosure or responsible-disclosure policy — /security,
  /responsible-disclosure, /vulnerability-disclosure and /security/responsible-disclosure
  all return 404, and no bug-bounty program (HackerOne / Bugcrowd / Intigriti) was found
- No /.well-known/security.txt (RFC 9116) on any Constructor host
- No published security contact address; the only published addresses are support@constructor.io,
  emergency-response@constructor.io and privacy@constructor.io
- No published SLA/uptime figure (SLA terms are contractual only)