Poptin · Trust Center
Poptin Trust Center
Trust center
Poptin maintains a public trust center documenting ISO/IEC 27001:2013 and ISO 27001 compliant infrastructure compliance.
CompanyMarketingEmail MarketingMarketing AutomationLead GenerationConversion OptimizationFormsPopupsContact ManagementWebhookE-CommerceSoftware-as-a-Service
Certifications & Compliance
ISO/IEC 27001:2013ISO 27001 compliant infrastructure
Source
Trust Center
generated: '2026-08-12'
method: searched
source: https://headwayapp.co/poptin-com-updates/poptin-is-is0-27001-compliant-279473
sources:
- https://headwayapp.co/poptin-com-updates/poptin-is-is0-27001-compliant-279473
- https://www.poptin.com/llms.txt
- https://www.poptin.com/gdpr/
- https://www.poptin.com/privacy-policy/
trust_center_url: null
note: >-
Poptin operates NO trust center or trust portal — there is no trust.poptin.com, no
security page, and no request-a-report flow. (https://www.poptin.com/security/ returns
200 but is a marketing landing page selling popups to security-industry websites, not
a security posture page; it is deliberately not cited as evidence here.) What Poptin
does publish is a named, numbered ISO 27001 certification announcement in its own
changelog, restated in its own llms.txt, plus a GDPR program page. That is a real
first-party compliance claim, so it is recorded — but no certificate document, audit
report, subprocessor list, pen-test summary or SLA is published anywhere.
certifications:
- name: ISO/IEC 27001:2013
status: claimed-certified
certificate_number: '1122094'
announced: '2023-11-20'
evidence: https://headwayapp.co/poptin-com-updates/poptin-is-is0-27001-compliant-279473
auditor_named: false
certificate_document_published: false
quote: 'We are proud to announce that Poptin is now ISO 27001 certified — ISO/IEC 27001:2013, Certificate number: 1122094'
- name: ISO 27001 compliant infrastructure
status: claimed
evidence: https://www.poptin.com/llms.txt
note: restated by the provider in its own llms.txt under "Security & Compliance"
regulatory_programs:
- name: GDPR
status: program-published
url: https://www.poptin.com/gdpr/
capabilities:
- consent checkboxes
- double opt-in
- subscriber preference management
- unsubscribe management
- contact deletion (manual and bulk)
- automated data retention settings
- contact export
evidence: https://www.poptin.com/llms.txt
not_claimed:
- SOC 2
- PCI DSS
- HIPAA
- FedRAMP
- ISO 27017
- ISO 27018
security_practices_claimed:
source: https://www.poptin.com/llms.txt
items:
- encrypted data transmission
- account management controls
- access management controls
- secure authentication systems
- continuous monitoring and maintenance
email_authentication_claimed:
source: https://www.poptin.com/llms.txt
items:
- SPF support
- DKIM support
- DMARC support
cross_check: >-
Independently confirmed at the DNS layer for poptin.com — SPF present, DMARC present
with p=quarantine. See security/poptin-domain-security.yml.
gaps:
- no trust center or trust portal
- no published certificate document or audit report
- no subprocessor list
- no penetration-test summary
- no uptime SLA
- no security contact and no /.well-known/security.txt (all 404 — see well-known/)
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/poptin-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.