Immutable · Trust Center

Immutable Trust Center

Trust center

Immutable maintains a public trust center documenting named and note compliance.

CompanyGamingBlockchainNFTWeb3WalletsMarketplaceAnalyticsAttributionCustomer Data PlatformAuthenticationDeveloper Platform
Trust center:

Certifications & Compliance

namednote

Source

Trust Center

Raw ↑
generated: '2026-08-23'
method: searched
source: https://www.immutable.com/trust
trust_center:
  url: https://www.immutable.com/trust
  http_status: 200
  hosted: first-party page on immutable.com
  note: >-
    Immutable publishes a Trust & Security page, not a hosted trust portal
    (no Vanta/Drata/SafeBase/Conveyor instance was found). It is narrative rather
    than evidentiary: it describes a control set but does NOT name a single
    third-party certification or audit report, and offers no document-request
    flow. Recorded honestly below — the absence of named certifications is the
    finding, and it is why conformance/immutable-conformance.yml records
    soc2/iso27001/pci/hipaa as conforms: false rather than unknown.
certifications:
  named: []
  note: >-
    No SOC 2, ISO 27001, ISO 27701, PCI DSS, HIPAA or FedRAMP claim appears
    anywhere on the Trust page. Searched the rendered text for each term; zero
    matches. The only compliance regime named is the GDPR, as a benchmark the
    company says it builds against.
regimes_claimed:
- name: GDPR
  claim: >-
    "We benchmark against the GDPR and the highest security standards." Products
    (Passport, Audience) are described as built on a privacy-by-design framework,
    with mapped data flows, vetted sub-processors, a collection statement shown
    at sign-in, and controller/processor roles defined in commercial agreements.
  evidence: https://www.immutable.com/trust
  supporting_api_surface:
  - operation: deleteAudienceData
    detail: >-
      DELETE /v1/audience/data in the Audience API accepts an erasure request for
      an identity, resolves linked identities via alias mappings, and queues an
      async erasure event — a machine-callable GDPR right-to-erasure path.
  - operation: getTrackingConsent / updateTrackingConsent
    detail: >-
      GET and PUT /v1/audience/tracking-consent expose per-identity consent state
      as an API, so consent is enforceable at ingestion rather than only in a UI.
controls_published:
- Enterprise-grade infrastructure on AWS, defence-in-depth, high availability and redundancy
- Encryption of sensitive data at rest and in transit
- Tested incident response protocol with regulatory reporting commitments
- Principle of least privilege with strong authentication for internal data access
- User-facing processes to manage, export or delete personal data
- 24/7 security operations centre with automated intrusion detection and threat intelligence
- Third-party vendor and sub-processor security review
- Public bug bounty programmes (Bugcrowd, Immunefi) and security@immutable.com
legal:
  privacy_policy: https://www.immutable.com/legal/privacy-policy
  terms_of_service: https://www.immutable.com/legal/terms-of-service
  acceptable_use: https://www.immutable.com/legal/acceptable-use
  collection_statement: https://www.immutable.com/legal/collection-statement
x-evidence:
  fetched: '2026-08-23'
  url: https://www.immutable.com/trust
  http_status: 200

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/immutable-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.