PebblePost · Trust Center
Pebblepost Trust Center
Trust center
PebblePost maintains a public trust center documenting SOC 2 compliance.
CompanyMarketingAdvertisingDirect MailConnected TVRetailCommerceIdentityAnalytics
Trust center: https://trust.pebblepost.com/
Certifications & Compliance
SOC 2
Source
Trust Center
generated: '2026-08-04'
method: searched
probe: true
source: https://trust.pebblepost.com/
url: https://trust.pebblepost.com/
platform: Vanta Trust Center
title: PebblePost Trust Center
# Certifications could NOT be enumerated anonymously. The trust report is a Vanta
# single-page app; its content is served from a signed GraphQL endpoint that rejects
# unsigned requests ("Missing `signature` or `signedAt`", HTTP 400), so no certification
# list is machine-readable from the public page. The one certification claim PebblePost
# publishes in plain HTML is the SOC 2 statement in its privacy policy, recorded below.
certifications:
- SOC 2
certification_evidence:
- certification: SOC 2
source: https://www.pebblepost.com/privacy-policy/
quote: 'PebblePost maintains and has placed controls within its Services that upholds
commitments and system requirements for SOC 2 compliance.'
note: A compliance claim in the privacy policy, not an audit report or a certificate
number. PebblePost links to the AICPA SOC suite overview page rather than to its
own report.
reference: https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
evidence:
- source: https://trust.pebblepost.com/
http_status: 200
content_type: text/html
observed: 'Vanta-hosted trust center; page <title> is "PebblePost Trust Center";
assets served from assets.vanta.com; canonical https://trust.pebblepost.com'
- source: https://trust.pebblepost.com/graphql
http_status: 400
observed: 'GraphQL rejects unsigned requests: {"errors":[{"message":"Missing `signature`
or `signedAt`"}]} — report contents are not anonymously readable'
- source: https://www.pebblepost.com/privacy-policy/
http_status: 200
observed: SOC 2 compliance statement in the Security section
x-gap:
- The trust center exists but publishes nothing a machine can read anonymously.
Named certifications, audit dates and subprocessors are all behind Vanta's signed
report. Publishing the certification list in the page's static HTML (or an
accompanying /.well-known/security.txt) would make the posture verifiable.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pebblepost-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.