RudderStack · Trust Center

Rudderstack Trust Center

Trust center

RudderStack publishes a security and compliance overview page rather than a hosted trust center — there is no trust.rudderstack.com (DNS does not resolve) and no Vanta/Drata/SafeBase portal was found. The page names three compliance programs and the enterprise security controls that back them. The architectural claim it leads with is material to how the compliance posture works: RudderStack is warehouse-native and states it does not store customer data, so much of the data-at-rest control surface belongs to the customer's own warehouse.

RudderStack maintains a public trust center documenting SOC 2, HIPAA, and GDPR compliance.

Customer Data PlatformCDPData PipelineOpen-SourceEvent StreamingReverse ETLAnalyticsIdentity Resolution
Trust center: https://www.rudderstack.com/security/

Certifications & Compliance

SOC 2HIPAAGDPR

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.rudderstack.com/security/
url: https://www.rudderstack.com/security/
http_status: 200
description: >-
  RudderStack publishes a security and compliance overview page rather than a
  hosted trust center — there is no trust.rudderstack.com (DNS does not resolve)
  and no Vanta/Drata/SafeBase portal was found. The page names three compliance
  programs and the enterprise security controls that back them. The architectural
  claim it leads with is material to how the compliance posture works:
  RudderStack is warehouse-native and states it does not store customer data, so
  much of the data-at-rest control surface belongs to the customer's own warehouse.
trust_center_hosted: false
probed:
  - {url: 'https://trust.rudderstack.com/', status: 'DNS did not resolve'}
  - {url: 'https://security.rudderstack.com/', status: 'DNS did not resolve'}
  - {url: 'https://www.rudderstack.com/security/', status: 200}
certifications:
  - name: SOC 2
    level: Type 2
    status: obtained
    evidence: >-
      "SOC 2 - We have obtained SOC 2 Type 2 compliance and regularly audit our
      policies and procedures to ensure continued compliance."
  - name: HIPAA
    status: compliant, BAA available
    plan_gate: Enterprise
    evidence: >-
      "HIPAA - We comply with HIPAA requirements for PHI and can sign a BAA."
      The pricing comparison table lists HIPAA / BAA under Enterprise only.
  - name: GDPR
    status: compliant
    evidence: >-
      "GDPR - We compliant with GDPR and are constantly adding features to enable
      you to meet your EU data protection requirements." EU data residency is
      backed by a separate control-plane host, https://api.eu.rudderstack.com.
not_claimed:
  certifications:
    - ISO 27001
    - PCI DSS
    - FedRAMP
    - CSA STAR
  note: >-
    These were not claimed on the security page. That records the absence of a
    published claim, not a finding about RudderStack's controls.
security_controls_published:
  - {name: SSO, detail: 'Okta, OneLogin', plan_gate: Enterprise}
  - {name: SSH Tunnel, detail: Encryption for in-flight data to warehouses/databases, plan_gate: Enterprise}
  - {name: Permissions management, detail: Limit access to features exposing PHI or PII}
  - {name: Audit logs, detail: 'Track user activity in the workspace; exposed programmatically via the Audit Logs API (/v2/audit-logs)'}
  - {name: MFA, detail: 'TOTP authenticator app or SMS, with single-use backup codes', since: '2026-08-05'}
  - {name: VPC deployment, detail: Available on Enterprise (talk to sales)}
  - {name: PII masking, detail: Data Compliance Toolkit; also applied automatically by Rudder AI}
  - {name: User suppression and deletion, detail: 'User Suppression API (/v2/regulations)', plan_gate: 'Growth, Enterprise'}
architecture_claim: >-
  "We do not store your data, giving you complete ownership, control and
  transparency. We build on your warehouse."
related:
  vulnerability_disclosure: security/rudderstack-vulnerability-disclosure.yml
  domain_security: security/rudderstack-domain-security.yml
  legal:
    master_service_agreement: https://www.rudderstack.com/master-service-agreement/
    privacy_policy: https://www.rudderstack.com/privacy-policy/
    terms_of_service: https://www.rudderstack.com/terms-of-service/
evidence:
  - source: https://www.rudderstack.com/security/
    http_status: 200
    keywords:
      - soc 2
      - soc 2 type 2
      - hipaa
      - baa
      - gdpr
      - sso
      - audit logs