DocSend · Trust Center

Docsend Trust Center

Trust center

DocSend maintains a public trust center documenting SOC 1, SOC 2, SOC 3, ISO/IEC 27001, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 27701, ISO 22301, PCI DSS, HIPAA, CSA STAR Level 2, GDPR, CCPA, EU Cloud CoC, EU-US DPF, and ISMAP compliance.

CompanyEnterpriseDocument SharingSales EnablementAnalyticsData RoomE-SignatureMCPDropbox
Trust center: https://www.docsend.com/trust-center/

Certifications & Compliance

SOC 1SOC 2SOC 3ISO/IEC 27001ISO/IEC 27017:2015ISO/IEC 27018:2019ISO/IEC 27701ISO 22301PCI DSSHIPAACSA STAR Level 2GDPRCCPAEU Cloud CoCEU-US DPFISMAP

Source

Trust Center

docsend-trust-center.yml Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.docsend.com/trust-center/
url: https://www.docsend.com/trust-center/
sub_pages:
- https://www.docsend.com/trust-center/security
- https://www.docsend.com/trust-center/compliance
upstream: https://trust.dropbox.com/?product=docsend
ownership_note: >-
  DocSend's trust center is served from DocSend's own domain (www.docsend.com/trust-center/)
  but its security and compliance sub-pages render the Dropbox Security & Compliance Trust
  Center, and the page links out to trust.dropbox.com with a `product=docsend` filter.
  That is the correct read, not a mismatch: DocSend has been a Dropbox product since the
  2021 acquisition, and the certifications below are the ones DocSend itself publishes as
  covering the service. The DocSend page states it directly — "Compliance and certification
  documents can be accessed in DocSend's Trust Center" — and the compliance copy on
  docsend.com reads "We comply with standards and regulations like SOC 2. On an annual
  basis our independent third-party auditors test our controls and provide their reports
  and opinions which we can provide to you upon request."
certifications:
- SOC 1
- SOC 2
- SOC 3
- ISO/IEC 27001
- ISO/IEC 27017:2015
- ISO/IEC 27018:2019
- ISO/IEC 27701
- ISO 22301
- PCI DSS
- HIPAA
- CSA STAR Level 2
- GDPR
- CCPA
- EU Cloud CoC
- EU-US DPF
- ISMAP
documents:
  access: request
  note: >-
    Reports (SOC 2, ISO/IEC 27001, Dropbox Security White Paper, pentest reports, CAIQ and
    HECVAT self-assessments) are listed publicly but gated behind a "Get access" request
    flow; only the document index is anonymous.
evidence:
- source: https://www.docsend.com/trust-center/
  status: 200
  keywords: [trust center, compliance, soc 2, security, privacy]
- source: https://www.docsend.com/trust-center/compliance
  status: 200
  keywords: [soc 1, soc 2, soc 3, iso/iec 27001, iso/iec 27017, iso/iec 27018, pci dss, hipaa, csa star level 2, gdpr, ccpa, ismap]
- source: https://www.docsend.com/pricing/
  status: 200
  keywords: ['gdpr logo', 'ccpa logo', 'pci dss compliant certification logo']
  note: The DocSend site footer carries GDPR, CCPA and PCI DSS compliance badges on every page.
fetch_note: >-
  www.docsend.com sits behind a Cloudflare bot challenge and returns HTTP 403 to curl and
  to most fetchers. All pages above were read on 2026-08-14 with a plain urllib client
  sending a descriptive bot User-Agent, which the edge served HTTP 200.