RudderStack · Trust Center

Rudderstack Trust Center

Trust center

RudderStack publishes a security and compliance overview page rather than a hosted trust center — there is no trust.rudderstack.com (DNS does not resolve) and no Vanta/Drata/SafeBase portal was found. The page names three compliance programs and the enterprise security controls that back them. The architectural claim it leads with is material to how the compliance posture works: RudderStack is warehouse-native and states it does not store customer data, so much of the data-at-rest control surface belongs to the customer's own warehouse.

RudderStack maintains a public trust center documenting SOC 2, HIPAA, and GDPR compliance.

Customer Data PlatformCDPData PipelineOpen-SourceEvent StreamingReverse ETLAnalyticsIdentity Resolution
Trust center: https://www.rudderstack.com/security/

Certifications & Compliance

SOC 2HIPAAGDPR

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.rudderstack.com/security/
url: https://www.rudderstack.com/security/
http_status: 200
description: >-
  RudderStack publishes a security and compliance overview page rather than a
  hosted trust center — there is no trust.rudderstack.com (DNS does not resolve)
  and no Vanta/Drata/SafeBase portal was found. The page names three compliance
  programs and the enterprise security controls that back them. The architectural
  claim it leads with is material to how the compliance posture works:
  RudderStack is warehouse-native and states it does not store customer data, so
  much of the data-at-rest control surface belongs to the customer's own warehouse.
trust_center_hosted: false
probed:
  - {url: 'https://trust.rudderstack.com/', status: 'DNS did not resolve'}
  - {url: 'https://security.rudderstack.com/', status: 'DNS did not resolve'}
  - {url: 'https://www.rudderstack.com/security/', status: 200}
certifications:
  - name: SOC 2
    level: Type 2
    status: obtained
    evidence: >-
      "SOC 2 - We have obtained SOC 2 Type 2 compliance and regularly audit our
      policies and procedures to ensure continued compliance."
  - name: HIPAA
    status: compliant, BAA available
    plan_gate: Enterprise
    evidence: >-
      "HIPAA - We comply with HIPAA requirements for PHI and can sign a BAA."
      The pricing comparison table lists HIPAA / BAA under Enterprise only.
  - name: GDPR
    status: compliant
    evidence: >-
      "GDPR - We compliant with GDPR and are constantly adding features to enable
      you to meet your EU data protection requirements." EU data residency is
      backed by a separate control-plane host, https://api.eu.rudderstack.com.
not_claimed:
  certifications:
    - ISO 27001
    - PCI DSS
    - FedRAMP
    - CSA STAR
  note: >-
    These were not claimed on the security page. That records the absence of a
    published claim, not a finding about RudderStack's controls.
security_controls_published:
  - {name: SSO, detail: 'Okta, OneLogin', plan_gate: Enterprise}
  - {name: SSH Tunnel, detail: Encryption for in-flight data to warehouses/databases, plan_gate: Enterprise}
  - {name: Permissions management, detail: Limit access to features exposing PHI or PII}
  - {name: Audit logs, detail: 'Track user activity in the workspace; exposed programmatically via the Audit Logs API (/v2/audit-logs)'}
  - {name: MFA, detail: 'TOTP authenticator app or SMS, with single-use backup codes', since: '2026-08-05'}
  - {name: VPC deployment, detail: Available on Enterprise (talk to sales)}
  - {name: PII masking, detail: Data Compliance Toolkit; also applied automatically by Rudder AI}
  - {name: User suppression and deletion, detail: 'User Suppression API (/v2/regulations)', plan_gate: 'Growth, Enterprise'}
architecture_claim: >-
  "We do not store your data, giving you complete ownership, control and
  transparency. We build on your warehouse."
related:
  vulnerability_disclosure: security/rudderstack-vulnerability-disclosure.yml
  domain_security: security/rudderstack-domain-security.yml
  legal:
    master_service_agreement: https://www.rudderstack.com/master-service-agreement/
    privacy_policy: https://www.rudderstack.com/privacy-policy/
    terms_of_service: https://www.rudderstack.com/terms-of-service/
evidence:
  - source: https://www.rudderstack.com/security/
    http_status: 200
    keywords:
      - soc 2
      - soc 2 type 2
      - hipaa
      - baa
      - gdpr
      - sso
      - audit logs

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/rudderstack-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.