Fullenrich Trust Center
FullEnrich's Privacy & Legal Center doubles as its trust center, publishing compliance badges, an Article 32 security-measures summary, a public DPA, a sub-processor list, and a request path to the SOC 2 Type II report through a hosted trust portal.
FullEnrich maintains a public trust center documenting SOC 2 Type II, GDPR, and CCPA compliance.
Certifications & Compliance
Source
Trust Center
generated: '2026-08-14'
method: searched
probe: false
probe_note: >-
DO NOT let probe-security-programs.py overwrite this file. Its keyword matcher
credits FullEnrich with ISO 27001 because the string appears once on the trust
page — describing DigitalOcean, the hosting sub-processor. This file is the
human-verified reading and is the stronger artifact.
source: https://fullenrich.com/trust
url: https://fullenrich.com/trust
description: >-
FullEnrich's Privacy & Legal Center doubles as its trust center, publishing
compliance badges, an Article 32 security-measures summary, a public DPA, a
sub-processor list, and a request path to the SOC 2 Type II report through a
hosted trust portal.
certifications:
- SOC 2 Type II
- GDPR
- CCPA
corrections:
- previously_recorded: ISO 27001
status: removed
reason: >-
MISATTRIBUTION. An automated keyword pass matched "ISO 27001" on this page and
credited it to FullEnrich. The only occurrence describes the hosting
sub-processor: "data hosting provider (DigitalOcean) is compliant with SOC 2
and ISO 27001 standards". FullEnrich holds no ISO 27001 certification of its
own and claims none anywhere on the site.
verified: '2026-08-14'
verification_method: >-
Fetched https://fullenrich.com/trust and inspected every occurrence of
"iso 27001" in context (1 occurrence, sub-processor clause).
documents_published:
- name: Data Processing Agreement (DPA)
public: true
detail: Publicly available, covers GDPR Article 28 obligations, signable as part of the commercial relationship.
- name: Terms and Conditions of Use and Sale
public: true
url: https://fullenrich.com/tos
last_updated: '2026-08-11'
- name: Privacy Policy
public: true
url: https://fullenrich.com/privacy-policy
- name: List of Sub-processors
public: true
- name: Cookie Policy
public: true
- name: Do Not Sell My Information
public: true
- name: Security Documentation
public: false
detail: Available on request through the trust center.
- name: SOC 2 Type II Compliance Report
public: false
detail: Access requested through the hosted trust portal.
hosted_trust_portal:
url: https://trust.delve.co/fullenrich
vendor: Delve
probe_status: 429
probe_note: >-
The portal answered with a Vercel Security Checkpoint bot challenge rather than
the page. We do not evade challenges, so its contents were not read; its
existence and purpose are taken from the link and description on
https://fullenrich.com/trust and https://fullenrich.com/pricing.md.
security_measures_published:
standard: GDPR Article 32
measures:
- Regular testing, assessment and evaluation of technical and organizational measures
- 'Identification and authorization: session cookies (JWT) signed with HMAC-SHA256, plus RBAC'
- Data at rest protected by AES encryption
- Event logging retained 1 year, encrypted at rest
- Data minimization
- Limited data retention (enrichment data kept 3 months)
- Contractual measures flowed down to sub-processors
pentesting: Regular penetration tests
data_handling:
hosting_provider: DigitalOcean
hosting_region: European Union
hosting_provider_certifications:
- SOC 2
- ISO 27001
hosting_provider_note: >-
These belong to DigitalOcean, not FullEnrich. Recorded here so the distinction
stays explicit and the misattribution does not recur.
international_transfers: Standard Contractual Clauses
processing_role: Processor for Waterfall Enrichment
database_claim: >-
FullEnrich states the Waterfall Enrichment service does not rely on a database
and does not create one from customer results — enrichment is real-time.
breach_process: >-
When acting as controller, FullEnrich states it will directly inform data
subjects where necessary.
evidence:
- source: https://fullenrich.com/trust
http_status: 200
keywords: [soc 2 type 2 certified, gdpr compliant, ccpa compliant, trust center, dpa, sub-processors, pentest]
- source: https://fullenrich.com/pricing.md
http_status: 200
keywords: [soc 2 type ii, gdpr, ccpa]
- source: https://trust.delve.co/fullenrich
http_status: 429
note: bot challenge, not read
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/security/fullenrich-trust-center"
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.