Nylas · Trust Center

Nylas Trust Center

Trust center

Compliance posture as published on the Nylas security page and the Nylas Trust Center. Corrects a previous keyword-derived list that recorded "PCI DSS" without qualification and omitted ISO 27701, CCPA, CPRA, the Data Privacy Framework and the GLBA Privacy Rule. Nylas holds PCI-DSS SAQ A, a self-assessment questionnaire, not a PCI DSS certification, and the CSA STAR entry is Level 1.

Nylas maintains a public trust center documenting SOC 2 Type II, ISO 27001, ISO 27701, HIPAA, GDPR, CCPA, CPRA, CSA STAR Level 1, PCI-DSS SAQ A, Data Privacy Framework, GLBA Privacy Rule, and ADA Tier 2 CASA Verified compliance.

CalendarCommunicationsContactsEmailMessagingScheduling
Trust center: https://trust.nylas.com/public

Certifications & Compliance

SOC 2 Type IIISO 27001ISO 27701HIPAAGDPRCCPACPRACSA STAR Level 1PCI-DSS SAQ AData Privacy FrameworkGLBA Privacy RuleADA Tier 2 CASA Verified

Source

Trust Center

Raw ↑
generated: '2026-08-20'
method: provider-published
authored_by: Nylas
url: https://trust.nylas.com/public
source: https://www.nylas.com/security/
sources:
- https://www.nylas.com/security/
- https://trust.nylas.com/public
description: >-
  Compliance posture as published on the Nylas security page and the Nylas Trust
  Center. Corrects a previous keyword-derived list that recorded "PCI DSS"
  without qualification and omitted ISO 27701, CCPA, CPRA, the Data Privacy
  Framework and the GLBA Privacy Rule. Nylas holds PCI-DSS SAQ A, a
  self-assessment questionnaire, not a PCI DSS certification, and the CSA STAR
  entry is Level 1.
certifications:
- name: SOC 2 Type II
  status: report available
  access: under NDA via the Trust Center
- name: ISO 27001
  status: certified
  access: certificate available on request via the Trust Center
- name: ISO 27701
  status: certified
  access: certificate available on request via the Trust Center
- name: HIPAA
  status: compliant
- name: GDPR
  status: compliant
- name: CCPA
  status: compliant
- name: CPRA
  status: compliant
- name: CSA STAR Level 1
  status: listed
- name: PCI-DSS SAQ A
  status: self-assessment questionnaire
  note: >-
    A SAQ A self-assessment, not a PCI DSS Level 1 Service Provider
    certification.
- name: Data Privacy Framework
  status: participant
- name: GLBA Privacy Rule
  status: compliant
- name: ADA Tier 2 CASA Verified
  status: verified
questionnaires:
- CAIQ
- SIG Lite
- SIG Core
- VSA
assurance:
- type: External penetration test
  cadence: annual
  reports_available: true
  access: via the Trust Center
controls:
  encryption_at_rest: AES-256 or equivalent
  encryption_in_transit: TLS 1.2+
  access_control: fine-grained access controls with SSO and multi-factor authentication
  notes: >-
    Application security is integrated through the development lifecycle, with
    infrastructure monitoring in place.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/nylas-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.