Mailchimp · Trust Center

Mailchimp Trust Center

Trust center

Mailchimp does not run a branded trust portal at trust.mailchimp.com (no such host) — its public security, compliance and privacy posture is published on one page, https://mailchimp.com/about/security/, which names the certifications, the audit cadence, the responsible-disclosure program and the privacy frameworks. Certification documents themselves are distributed through the Intuit compliance portal, since Mailchimp is an Intuit company.

Mailchimp maintains a public trust center documenting SOC 2, ISO 27001, EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF), GDPR, and VPAT (Section 508 accessibility) compliance.

CampaignsEmail MarketingMarketing AutomationNewslettersTransactional EmailAudience ManagementSMSE-CommerceWebhookMarketing Analytics
Trust center: https://mailchimp.com/about/security/

Certifications & Compliance

SOC 2ISO 27001EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF)GDPRVPAT (Section 508 accessibility)

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
url: https://mailchimp.com/about/security/
source: https://mailchimp.com/about/security/
checked: '2026-08-13'
http_status: 200
description: >-
  Mailchimp does not run a branded trust portal at trust.mailchimp.com (no such
  host) — its public security, compliance and privacy posture is published on one
  page, https://mailchimp.com/about/security/, which names the certifications, the
  audit cadence, the responsible-disclosure program and the privacy frameworks.
  Certification documents themselves are distributed through the Intuit compliance
  portal, since Mailchimp is an Intuit company.
certifications:
  - name: SOC 2
    evidence: >-
      "Our SOC 2 reports cover controls around security, availability, and process
      integrity of customer data."
  - name: ISO 27001
    evidence: >-
      "The International Organization for Standardization 27001 Standard (ISO
      27001) is an information security standard that ensures office sites,
      development centers, support centers, and data centers are securely managed."
  - name: EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF)
    evidence: >-
      "We undergo annual verification with a U.S. based third party-outside
      compliance reviewer under the EU-U.S. Data Privacy Framework (EU-U.S. DPF),
      the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy
      Framework (Swiss-U.S. DPF)."
  - name: GDPR
    evidence: Dedicated compliance page at https://mailchimp.com/gdpr/ (HTTP 200, fetched 2026-08-13).
  - name: VPAT (Section 508 accessibility)
    evidence: >-
      "Mailchimp also maintains a VPAT, or Voluntary Product Accessibility
      Template (VPAT®)."
audit_cadence: >-
  "These certifications run for 3 years (renewal audits) and have annual
  touchpoint audits (surveillance audits)."
not_claimed:
  - PCI DSS
  - HIPAA
  - FedRAMP
  - ISO 27017
  - ISO 27018
  - CSA STAR
notes_on_pci: >-
  The page describes card-association compliance (Visa CISP, Mastercard SDP,
  Discover DISC) held by Mailchimp's PAYMENT PROCESSING VENDOR, not by Mailchimp.
  Recorded here so it is not misread as a Mailchimp certification.
security_program:
  penetration_testing: >-
    Regular external and internal penetration tests throughout the year using
    different vendors, plus social engineering drills; results kept confidential.
  transport: Entire application and API encrypted with TLS 1.2 or higher.
  account_controls: [two-factor authentication, tiered account access, brute-force protection on API logins]
  data_residency: Owned and operated servers in United States data centers.
  memberships: [ESPC, M3AAWG, ISC2, ISACA, ISSA, SANS, IAPP]
related:
  vulnerability_disclosure: security/mailchimp-vulnerability-disclosure.yml
  domain_security: security/mailchimp-domain-security.yml
  conformance: conformance/mailchimp-conformance.yml
evidence:
  - source: https://mailchimp.com/about/security/
    http_status: 200
    keywords: [SOC 2, ISO 27001, responsible disclosure, penetration testing, Data Privacy Framework, VPAT]
  - source: https://mailchimp.com/gdpr/
    http_status: 200
    keywords: [GDPR, Data Privacy Framework]
  - source: https://mailchimp.com/legal/data-processing-addendum/
    http_status: 200
    keywords: [GDPR, data processing addendum]
  - source: https://trust.intuit.com/
    http_status: 200
    note: Resolves but returns a "404 | Page not found" body — no usable Intuit trust portal at that host.