Lob.com · Trust Center

Lobcom Trust Center

Trust center

Lob.com maintains a public trust center documenting SOC 2 Type 2, HIPAA, GDPR, and CCPA/CPRA compliance.

CompanyDirect MailPrintAddress VerificationMailPostcardsLettersChecksCampaignsUSPSDeliverability
Trust center:

Certifications & Compliance

SOC 2 Type 2HIPAAGDPRCCPA/CPRA

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
source: https://trust.lob.com + https://www.lob.com/security
trust_center:
  url: https://trust.lob.com
  platform: Vanta
  title: Lob.com, Inc. Trust Center
  access: >
    Landing page and metadata are public; the underlying document set (SOC 2 report,
    subprocessor list, policies) is served through Vanta and typically requires requesting
    access with an NDA.
  probe:
    url: https://trust.lob.com
    status: 200
    content_type: text/html
    checked: '2026-08-13'
    note: >
      A Vanta-hosted single-page app. The shell carries a real canonical link, page title and
      description for Lob specifically, so it is a genuine trust center rather than an SPA
      catch-all — but the certification list itself renders client-side and is not readable
      from the served HTML. The certifications recorded below were therefore taken from Lob's
      own security page, not from the trust center DOM.
certifications:
  - name: SOC 2 Type 2
    status: certified
    scope: all five Trust Services Criteria
    cadence: annual audit
    evidence: >-
      "annual SOC 2 Type 2 audits across all five Trust Services Criteria" —
      https://www.lob.com/security
  - name: HIPAA
    status: supported
    scope: dedicated infrastructure + Business Associate Agreement (BAA)
    evidence: https://www.lob.com/security
  - name: GDPR
    status: aligned
    evidence: https://www.lob.com/security
  - name: CCPA/CPRA
    status: aligned
    evidence: https://www.lob.com/security
not_claimed:
  - ISO 27001
  - PCI DSS
  - FedRAMP
  - HITRUST
not_claimed_note: >
  Checked and absent from both www.lob.com/security and the trust center metadata as of
  2026-08-13. Recorded explicitly so a later pass does not read silence as an unchecked gap.
security_controls:
  encryption_in_transit: TLS 1.2+
  encryption_at_rest: AES-256
  sso: SAML 2.0 (Enterprise only)
  rbac: true (Enterprise only)
  audit_logs: programmatic access to audit and API request logs
  hosting: Amazon Web Services
  penetration_testing: regular, by independent third parties
  appsec: >
    Automated testing, static security analysis, dependency vulnerability scanning, mandatory
    code review, infrastructure-as-code deployment.
  source: https://www.lob.com/security
vulnerability_disclosure:
  published: false
  checked: '2026-08-13'
  evidence:
    - url: https://www.lob.com/.well-known/security.txt
      status: 404
    - url: https://api.lob.com/.well-known/security.txt
      status: 404
    - url: https://hackerone.com/lob
      status: 404
    - url: https://www.lob.com/legal/bug-bounty
      status: 200
      note: >
        Soft-200. www.lob.com/legal/<anything> returns the Terms of Service page byte-for-byte
        (verified: /legal/bug-bounty, /legal/responsible-disclosure and a nonsense path all
        hash identically). Not a disclosure policy — recorded so the 200 is never mistaken for
        one.
  note: >
    Third-party aggregators still list a Lob HackerOne program, but hackerone.com/lob now
    returns 404 and the HackerOne GraphQL API answers "Team does not exist". No security.txt is
    served on any Lob host and no disclosure page exists on lob.com. The only machine-readable
    security contact Lob publishes is the DNS CAA iodef record on lob.com
    (an iodef mailto: address — see security/lobcom-domain-security.yml). Because no
    vulnerability disclosure policy is published, NO `Security` pointer is emitted in apis.yml.
subprocessors:
  url: https://trust.lob.com
  note: Lob's trust center description directs readers to its subprocessor page.
legal:
  terms: https://www.lob.com/legal/terms
  privacy: https://www.lob.com/privacy