PebblePost · Trust Center

Pebblepost Trust Center

Trust center

PebblePost maintains a public trust center documenting SOC 2 compliance.

CompanyMarketingAdvertisingDirect MailConnected TVRetailCommerceIdentityAnalytics
Trust center: https://trust.pebblepost.com/

Certifications & Compliance

SOC 2

Source

Trust Center

pebblepost-trust-center.yml Raw ↑
generated: '2026-08-04'
method: searched
probe: true
source: https://trust.pebblepost.com/
url: https://trust.pebblepost.com/
platform: Vanta Trust Center
title: PebblePost Trust Center
# Certifications could NOT be enumerated anonymously. The trust report is a Vanta
# single-page app; its content is served from a signed GraphQL endpoint that rejects
# unsigned requests ("Missing `signature` or `signedAt`", HTTP 400), so no certification
# list is machine-readable from the public page. The one certification claim PebblePost
# publishes in plain HTML is the SOC 2 statement in its privacy policy, recorded below.
certifications:
- SOC 2
certification_evidence:
- certification: SOC 2
  source: https://www.pebblepost.com/privacy-policy/
  quote: 'PebblePost maintains and has placed controls within its Services that upholds
    commitments and system requirements for SOC 2 compliance.'
  note: A compliance claim in the privacy policy, not an audit report or a certificate
    number. PebblePost links to the AICPA SOC suite overview page rather than to its
    own report.
  reference: https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
evidence:
- source: https://trust.pebblepost.com/
  http_status: 200
  content_type: text/html
  observed: 'Vanta-hosted trust center; page <title> is "PebblePost Trust Center";
    assets served from assets.vanta.com; canonical https://trust.pebblepost.com'
- source: https://trust.pebblepost.com/graphql
  http_status: 400
  observed: 'GraphQL rejects unsigned requests: {"errors":[{"message":"Missing `signature`
    or `signedAt`"}]} — report contents are not anonymously readable'
- source: https://www.pebblepost.com/privacy-policy/
  http_status: 200
  observed: SOC 2 compliance statement in the Security section
x-gap:
  - The trust center exists but publishes nothing a machine can read anonymously.
    Named certifications, audit dates and subprocessors are all behind Vanta's signed
    report. Publishing the certification list in the page's static HTML (or an
    accompanying /.well-known/security.txt) would make the posture verifiable.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pebblepost-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.