FullEnrich · Trust Center

Fullenrich Trust Center

Trust center

FullEnrich's Privacy & Legal Center doubles as its trust center, publishing compliance badges, an Article 32 security-measures summary, a public DPA, a sub-processor list, and a request path to the SOC 2 Type II report through a hosted trust portal.

FullEnrich maintains a public trust center documenting SOC 2 Type II, GDPR, and CCPA compliance.

B2B DataContact EnrichmentEmail FinderPhone FinderWaterfall EnrichmentSales IntelligencePeople SearchCompany SearchReverse Email LookupAgent Ready
Trust center: https://fullenrich.com/trust

Certifications & Compliance

SOC 2 Type IIGDPRCCPA

Source

Trust Center

Raw ↑
generated: '2026-08-14'
method: searched
probe: false
probe_note: >-
  DO NOT let probe-security-programs.py overwrite this file. Its keyword matcher
  credits FullEnrich with ISO 27001 because the string appears once on the trust
  page — describing DigitalOcean, the hosting sub-processor. This file is the
  human-verified reading and is the stronger artifact.
source: https://fullenrich.com/trust
url: https://fullenrich.com/trust
description: >-
  FullEnrich's Privacy & Legal Center doubles as its trust center, publishing
  compliance badges, an Article 32 security-measures summary, a public DPA, a
  sub-processor list, and a request path to the SOC 2 Type II report through a
  hosted trust portal.

certifications:
- SOC 2 Type II
- GDPR
- CCPA

corrections:
- previously_recorded: ISO 27001
  status: removed
  reason: >-
    MISATTRIBUTION. An automated keyword pass matched "ISO 27001" on this page and
    credited it to FullEnrich. The only occurrence describes the hosting
    sub-processor: "data hosting provider (DigitalOcean) is compliant with SOC 2
    and ISO 27001 standards". FullEnrich holds no ISO 27001 certification of its
    own and claims none anywhere on the site.
  verified: '2026-08-14'
  verification_method: >-
    Fetched https://fullenrich.com/trust and inspected every occurrence of
    "iso 27001" in context (1 occurrence, sub-processor clause).

documents_published:
- name: Data Processing Agreement (DPA)
  public: true
  detail: Publicly available, covers GDPR Article 28 obligations, signable as part of the commercial relationship.
- name: Terms and Conditions of Use and Sale
  public: true
  url: https://fullenrich.com/tos
  last_updated: '2026-08-11'
- name: Privacy Policy
  public: true
  url: https://fullenrich.com/privacy-policy
- name: List of Sub-processors
  public: true
- name: Cookie Policy
  public: true
- name: Do Not Sell My Information
  public: true
- name: Security Documentation
  public: false
  detail: Available on request through the trust center.
- name: SOC 2 Type II Compliance Report
  public: false
  detail: Access requested through the hosted trust portal.

hosted_trust_portal:
  url: https://trust.delve.co/fullenrich
  vendor: Delve
  probe_status: 429
  probe_note: >-
    The portal answered with a Vercel Security Checkpoint bot challenge rather than
    the page. We do not evade challenges, so its contents were not read; its
    existence and purpose are taken from the link and description on
    https://fullenrich.com/trust and https://fullenrich.com/pricing.md.

security_measures_published:
  standard: GDPR Article 32
  measures:
  - Regular testing, assessment and evaluation of technical and organizational measures
  - 'Identification and authorization: session cookies (JWT) signed with HMAC-SHA256, plus RBAC'
  - Data at rest protected by AES encryption
  - Event logging retained 1 year, encrypted at rest
  - Data minimization
  - Limited data retention (enrichment data kept 3 months)
  - Contractual measures flowed down to sub-processors
  pentesting: Regular penetration tests

data_handling:
  hosting_provider: DigitalOcean
  hosting_region: European Union
  hosting_provider_certifications:
  - SOC 2
  - ISO 27001
  hosting_provider_note: >-
    These belong to DigitalOcean, not FullEnrich. Recorded here so the distinction
    stays explicit and the misattribution does not recur.
  international_transfers: Standard Contractual Clauses
  processing_role: Processor for Waterfall Enrichment
  database_claim: >-
    FullEnrich states the Waterfall Enrichment service does not rely on a database
    and does not create one from customer results — enrichment is real-time.
  breach_process: >-
    When acting as controller, FullEnrich states it will directly inform data
    subjects where necessary.

evidence:
- source: https://fullenrich.com/trust
  http_status: 200
  keywords: [soc 2 type 2 certified, gdpr compliant, ccpa compliant, trust center, dpa, sub-processors, pentest]
- source: https://fullenrich.com/pricing.md
  http_status: 200
  keywords: [soc 2 type ii, gdpr, ccpa]
- source: https://trust.delve.co/fullenrich
  http_status: 429
  note: bot challenge, not read

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/fullenrich-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.