Mailchimp · Trust Center

Mailchimp Trust Center

Trust center

Mailchimp does not run a branded trust portal at trust.mailchimp.com (no such host) — its public security, compliance and privacy posture is published on one page, https://mailchimp.com/about/security/, which names the certifications, the audit cadence, the responsible-disclosure program and the privacy frameworks. Certification documents themselves are distributed through the Intuit compliance portal, since Mailchimp is an Intuit company.

Mailchimp maintains a public trust center documenting SOC 2, ISO 27001, EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF), GDPR, and VPAT (Section 508 accessibility) compliance.

CampaignsEmail MarketingMarketing AutomationNewslettersTransactional EmailAudience ManagementSMSE-CommerceWebhookMarketing Analytics
Trust center: https://mailchimp.com/about/security/

Certifications & Compliance

SOC 2ISO 27001EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF)GDPRVPAT (Section 508 accessibility)

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
url: https://mailchimp.com/about/security/
source: https://mailchimp.com/about/security/
checked: '2026-08-13'
http_status: 200
description: >-
  Mailchimp does not run a branded trust portal at trust.mailchimp.com (no such
  host) — its public security, compliance and privacy posture is published on one
  page, https://mailchimp.com/about/security/, which names the certifications, the
  audit cadence, the responsible-disclosure program and the privacy frameworks.
  Certification documents themselves are distributed through the Intuit compliance
  portal, since Mailchimp is an Intuit company.
certifications:
  - name: SOC 2
    evidence: >-
      "Our SOC 2 reports cover controls around security, availability, and process
      integrity of customer data."
  - name: ISO 27001
    evidence: >-
      "The International Organization for Standardization 27001 Standard (ISO
      27001) is an information security standard that ensures office sites,
      development centers, support centers, and data centers are securely managed."
  - name: EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF)
    evidence: >-
      "We undergo annual verification with a U.S. based third party-outside
      compliance reviewer under the EU-U.S. Data Privacy Framework (EU-U.S. DPF),
      the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy
      Framework (Swiss-U.S. DPF)."
  - name: GDPR
    evidence: Dedicated compliance page at https://mailchimp.com/gdpr/ (HTTP 200, fetched 2026-08-13).
  - name: VPAT (Section 508 accessibility)
    evidence: >-
      "Mailchimp also maintains a VPAT, or Voluntary Product Accessibility
      Template (VPAT®)."
audit_cadence: >-
  "These certifications run for 3 years (renewal audits) and have annual
  touchpoint audits (surveillance audits)."
not_claimed:
  - PCI DSS
  - HIPAA
  - FedRAMP
  - ISO 27017
  - ISO 27018
  - CSA STAR
notes_on_pci: >-
  The page describes card-association compliance (Visa CISP, Mastercard SDP,
  Discover DISC) held by Mailchimp's PAYMENT PROCESSING VENDOR, not by Mailchimp.
  Recorded here so it is not misread as a Mailchimp certification.
security_program:
  penetration_testing: >-
    Regular external and internal penetration tests throughout the year using
    different vendors, plus social engineering drills; results kept confidential.
  transport: Entire application and API encrypted with TLS 1.2 or higher.
  account_controls: [two-factor authentication, tiered account access, brute-force protection on API logins]
  data_residency: Owned and operated servers in United States data centers.
  memberships: [ESPC, M3AAWG, ISC2, ISACA, ISSA, SANS, IAPP]
related:
  vulnerability_disclosure: security/mailchimp-vulnerability-disclosure.yml
  domain_security: security/mailchimp-domain-security.yml
  conformance: conformance/mailchimp-conformance.yml
evidence:
  - source: https://mailchimp.com/about/security/
    http_status: 200
    keywords: [SOC 2, ISO 27001, responsible disclosure, penetration testing, Data Privacy Framework, VPAT]
  - source: https://mailchimp.com/gdpr/
    http_status: 200
    keywords: [GDPR, Data Privacy Framework]
  - source: https://mailchimp.com/legal/data-processing-addendum/
    http_status: 200
    keywords: [GDPR, data processing addendum]
  - source: https://trust.intuit.com/
    http_status: 200
    note: Resolves but returns a "404 | Page not found" body — no usable Intuit trust portal at that host.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/mailchimp-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.