Cordial · Trust Center

Cordial Trust Center

Trust center

Cordial maintains a public trust center documenting SOC 2 Type II compliance.

CompanyMarketingMarketing AutomationMessagingEmailSMSPush NotificationsCustomer Data PlatformPersonalizationCustomer EngagementArtificial IntelligenceRetailE-Commerce
Trust center: https://cordial.com/security/

Certifications & Compliance

SOC 2 Type II

Source

Trust Center

Raw ↑
generated: '2026-08-04'
method: searched
probe: true
url: https://cordial.com/security/
title: Security & Compliance

note: >-
  probe-security-programs.py returned trust=none because Cordial operates no trust.<domain> subdomain
  and no dedicated trust portal. A manual fetch of https://cordial.com/security/ (HTTP 200) confirmed a
  real published compliance page naming specific frameworks, so this artifact is recorded as searched
  with the page body as evidence. Only frameworks Cordial names on its own page are listed.

certifications:
- name: SOC 2 Type II
  status: compliant
  claim: 'Demands rigorous security policy creation, adherence and auditing. Cordial is SOC 2 Type II compliant.'
  report_available: unknown
  note: No public report request flow or automated NDA-gated portal was found.

regulatory_alignment:
- name: GDPR
  status: compliant
  claim: 'Cordial is GDPR and CCPA compliant.'
- name: CCPA
  status: compliant
  claim: 'Cordial is GDPR and CCPA compliant.'
- name: EU-U.S. Privacy Shield / Swiss-U.S. Privacy Shield
  status: claimed
  claim: 'Cordial complies with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce.'
  caveat: >-
    A live-site accuracy issue worth flagging to the provider: the EU-U.S. Privacy Shield was invalidated
    by the CJEU in July 2020 (Schrems II) and the Swiss-U.S. framework was likewise superseded. The
    successor is the EU-U.S. Data Privacy Framework. Cordial's own privacy policy at
    legal.cordial.com does reference dataprivacyframework.gov, so the security page appears to be stale
    rather than the underlying posture being wrong.

channel_compliance:
  note: >-
    Cordial's messaging-channel documentation additionally cites compliance tooling for TCPA, CTIA,
    HIPAA and GDPR in the SMS/MMS channel. These are described as compliance FEATURES of the product
    (consent capture, quiet hours, opt-out handling), not as certifications Cordial holds.
  frameworks: [TCPA, CTIA, HIPAA, GDPR]
  source: https://cordial.com/platform/messaging-channels/sms-marketing/

privacy:
  policy: https://legal.cordial.com/privacy-policy/
  sub_processors: https://legal.cordial.com/sub-processor-list/
  note: >-
    A published sub-processor list is a meaningful enterprise-diligence artifact and is more than many
    peers publish. Global Privacy Control is referenced in the privacy policy.

not_found:
  iso_27001: 'Not claimed anywhere on the public site.'
  pci_dss: 'Not claimed. Cordial is not a payments processor.'
  fedramp: 'Not claimed.'
  hitrust: 'Not claimed.'
  csa_star: 'Not claimed.'
  trust_portal: 'No trust.cordial.com (DNS does not resolve); no Vanta/Drata/SafeBase-style portal.'
  status_of_reports: 'No self-serve mechanism to request the SOC 2 report.'

x-evidence:
  fetched: '2026-08-04'
  probes:
  - {url: 'https://cordial.com/security/', http_status: 200, keywords: ['SOC 2 Type II', 'GDPR', 'CCPA', 'Privacy Shield']}
  - {url: 'https://legal.cordial.com/privacy-policy/', http_status: 200}
  - {url: 'https://legal.cordial.com/sub-processor-list/', http_status: 200}
  - {url: 'https://trust.cordial.com', result: 'DNS does not resolve'}
  - {url: 'https://cordial.com/compliance/', http_status: 404}