Kickbox · Trust Center
Kickbox Trust Center
Trust center
Kickbox maintains a public trust center documenting SOC 2, GDPR, and CCPA compliance.
Email VerificationEmail ValidationDeliverabilityData QualityEmail
Trust center: https://trust.kickbox.com/
Certifications & Compliance
SOC 2GDPRCCPA
Source
Trust Center
generated: '2026-08-13'
method: searched
probe: false
source: https://docs.kickbox.com/docs/security-and-compliance
url: https://trust.kickbox.com/
http_status: 200
verified: '2026-08-13'
summary: >-
Kickbox operates a trust center at trust.kickbox.com, linked from its own Security and Compliance
documentation page with deep links into five control categories. The page itself is a JavaScript
single-page application and renders no server-side text, so the certification list below is taken
from Kickbox's documentation and pricing page rather than scraped from the trust center — the
mechanical probe (0-working/probe-security-programs.py) returned no hit for exactly that reason.
control_categories:
- {name: Infrastructure security, url: 'https://trust.kickbox.com/controls#infrastructure-security'}
- {name: Organizational security, url: 'https://trust.kickbox.com/controls#organizational-security'}
- {name: Product security, url: 'https://trust.kickbox.com/controls#product-security'}
- {name: Internal security procedures, url: 'https://trust.kickbox.com/controls#internal-security-procedures'}
- {name: Data and privacy, url: 'https://trust.kickbox.com/controls#data-and-privacy'}
certifications:
- name: SOC 2
status: claimed
note: >-
Kickbox makes two different claims about SOC 2 and both are recorded here rather than
reconciled. The docs page (Security and Compliance) invites readers to "view our current
progress towards SOC2 compliance" on the trust center, which reads as in-progress. The pricing
page states Kickbox "is fully GDPR-compliant and SOC II certified". No audit report or
attestation date is published on either page, so the status is recorded as claimed.
sources:
- https://docs.kickbox.com/docs/security-and-compliance
- https://kickbox.com/pricing
- name: GDPR
status: claimed-compliant
note: >-
"We are GDPR compliant, following all of the EU's regulations for data protection for our EU
customers." Kickbox operates dedicated EU verification servers and a separate EU application
(app.eu.kickbox.com / api.eu.kickbox.com).
docs: https://docs.kickbox.com/docs/gdpr
sources: [https://docs.kickbox.com/docs/security-and-compliance]
- name: CCPA
status: claimed-ready
note: Documented as "CCPA and GDPR ready".
sources: [https://docs.kickbox.com/docs/security-and-compliance]
memberships:
- name: M3AAWG
note: >-
Documented as membership in anti-abuse organizations "like M3WAGG" (the provider's own spelling
of M3AAWG, the Messaging, Malware and Mobile Anti-Abuse Working Group). Recorded verbatim from
the source with the intended organization noted.
sources: [https://docs.kickbox.com/docs/security-and-compliance]
data_handling:
- >-
Kickbox states it does not send email to verify addresses and does not accept customers who use
their lists for spam.
- >-
EU customers can have verifications processed on dedicated EU servers.
account_security:
- {feature: Sign in with Google, docs: 'https://docs.kickbox.com/docs/authentication-methods'}
- {feature: Two-factor authentication, docs: 'https://docs.kickbox.com/docs/authentication-methods'}
- {feature: Okta SSO, docs: 'https://docs.kickbox.com/docs/okta-authentication'}
privacy:
privacy_policy: https://docs.kickbox.com/docs/privacy-policy
subprocessors: https://docs.kickbox.com/docs/subprocessors
anti_spam_policy: https://docs.kickbox.com/docs/anti-spam-policy
list_security: https://docs.kickbox.com/docs/list-security-and-privacy
dsar_portal: https://privacyportal.onetrust.com/webform/f73513a8-7a10-4a9d-939a-703f8d994839/262761ab-edc4-440a-8e56-e6348b131382
vulnerability_disclosure:
published: false
note: >-
Separately searched and not found. No /.well-known/security.txt on any Kickbox host, no
responsible-disclosure or bug-bounty page, and no HackerOne/Bugcrowd/Intigriti program. The
mechanical probe returned vdp=none. No security/kickbox-vulnerability-disclosure.yml artifact and
no Security pointer are emitted — an honest absence.
evidence:
- {url: 'https://kickbox.com/.well-known/security.txt', status: 404}
- {url: 'https://kickbox.com/security.txt', status: 404}
- {url: 'https://api.kickbox.com/.well-known/security.txt', status: 404}
evidence:
- {source: 'https://docs.kickbox.com/docs/security-and-compliance', status: 200, kind: provider-documentation}
- {source: 'https://trust.kickbox.com/', status: 200, kind: trust-center, note: JS-rendered; no server-side text}
- {source: 'https://kickbox.com/pricing', status: 200, kind: marketing-claim}
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/kickbox-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.