RB2B · Trust Center

Rb2B Trust Center

Trust center

RB2B publishes its security posture on its own site and points at a SecurityPal-hosted assurance profile for verification. The trust centre is on the retention.securitypal.com subdomain rather than an rb2b one: RB2B and Retention.com are sibling products of the same company, which is also why www.rb2b.com/apis 301-redirects to retention.com/apis and the database opt-out is operated at app.retention.com/optout. Confirmed by the link being published on RB2B's own /security page.

RB2B maintains a public trust center documenting SOC 2 Type 2, CCPA, and GDPR compliance.

Identity ResolutionVisitor IdentificationB2B DataLead GenerationSales IntelligenceMarketingData EnrichmentLinkedIn EnrichmentHashed EmailMobile Ad IDFirmographicsWebhookPixelAdTechIdentity GraphMCP
Trust center: https://retention.securitypal.com

Certifications & Compliance

SOC 2 Type 2CCPAGDPR

Source

Trust Center

rb2b-trust-center.yml Raw ↑
generated: '2026-08-12'
method: searched
probe: true
source: https://www.rb2b.com/security
url: https://retention.securitypal.com
description: >-
  RB2B publishes its security posture on its own site and points at a
  SecurityPal-hosted assurance profile for verification. The trust centre is on
  the retention.securitypal.com subdomain rather than an rb2b one: RB2B and
  Retention.com are sibling products of the same company, which is also why
  www.rb2b.com/apis 301-redirects to retention.com/apis and the database opt-out
  is operated at app.retention.com/optout. Confirmed by the link being published
  on RB2B's own /security page.
trust_center:
  url: https://retention.securitypal.com
  platform: SecurityPal
  status: 200
  probed: '2026-08-12'
certifications:
  - name: SOC 2 Type 2
    status: certified
    evidence: '"RB2B is SOC2 Type 2 Certified and CCPA Compliant" — https://www.rb2b.com/security'
  - name: CCPA
    status: compliant
    evidence: https://www.rb2b.com/security
  - name: GDPR
    status: program published
    evidence: https://www.rb2b.com/gdpr (HTTP 200)
not_claimed:
  - ISO 27001
  - HIPAA
  - PCI DSS
  - FedRAMP
practices:
  vulnerability_management: Amazon Inspector for automated, continual vulnerability management
  monitoring: 24/7
  data_position: "We do not repackage or resell your data"
privacy:
  privacy_policy: https://www.rb2b.com/privacy-policy
  terms: https://www.rb2b.com/terms-conditions
  gdpr: https://www.rb2b.com/gdpr
  compliance: https://www.rb2b.com/compliance
  privacy_choices: https://www.rb2b.com/your-privacy-choices
  database_opt_out: https://app.retention.com/optout/
  compliance_faqs: https://support.rb2b.com/en/articles/15589545-compliance-faqs
  security_faqs: https://support.rb2b.com/en/articles/8999958-security-faqs
  vendor_review_policy: https://support.rb2b.com/en/articles/12861177-vendor-reviews-and-security-assessments-policy-for-trials-and-self-serve-plans
vulnerability_disclosure:
  program: none
  evidence: >-
    No RB2B security.txt, no bug bounty, and no disclosure page. The only
    /.well-known/security.txt reachable on an rb2b.com host is Intercom's
    platform document served by the hosted help centre — see
    well-known/rb2b-well-known.yml. No VulnerabilityDisclosure or Security
    pointer is emitted for RB2B.
  security_contact: support@rb2b.com (general support address; no dedicated security address published)
evidence:
  - source: https://www.rb2b.com/security
    keywords: [soc2, soc 2 type 2, ccpa, amazon inspector, 24/7 monitoring]
  - source: https://retention.securitypal.com
    keywords: [trust center, assurance profile]
  - source: https://www.rb2b.com/gdpr
    keywords: [gdpr]