Sumble · Trust Center

Sumble Trust Center

Trust center

Sumble maintains a public trust center documenting SOC 2 and GDPR compliance.

CompanyAccount IntelligenceSales IntelligenceData EnrichmentGo-To-MarketTechnographicsPeople DataJob PostsSignalsMCP
Trust center: https://trust.sumble.com/

Certifications & Compliance

SOC 2GDPR

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
url: https://trust.sumble.com/
platform: Vanta Trust Center
http_status: 200
rendering: >-
  JS-rendered Vanta shell — the certification list and report requests are
  loaded client-side, so the certifications below are taken from Sumble's own
  documentation rather than scraped from the trust center HTML.
docs: https://docs.sumble.com/trust-and-security/trust-and-security
certifications:
  - SOC 2
  - GDPR
programs:
  - name: SOC 2
    detail: Sumble maintains SOC 2 compliance; reports are requestable through the trust center.
  - name: GDPR
    detail: >-
      Processes data in accordance with GDPR; people data sourced from public
      professional profiles is handled per applicable data protection
      regulations.
infrastructure:
  provider: Google Cloud Platform (GCP)
  encryption_in_transit: TLS for client traffic and internal service-to-service traffic
  encryption_at_rest: GCP default encryption at rest for all databases and storage
  network_isolation: Production databases are not reachable from the public internet; access restricted to authorized services in the GCP project
  access_controls: Least-privilege internal access; administrative actions logged to an audit trail
data_handling:
  customer_isolation: Each customer's CRM data (accounts, contacts, enrichments) is logically isolated to authorized users in that customer's org
  retention: Retained for the duration of the customer relationship; deletion on request
  resale: 'CRM data shared for enrichment is used only to provide enrichment back to that customer — not shared with other customers and not sold'
responsible_ai:
  own_models: Entity extraction, relationship classification and job-function classification over job-market data; no personal communications, private documents or sensitive personal information processed
  llm_subprocessors:
    - {vendor: Google, models: Gemini, use: 'user-facing intelligence briefs (web app, REST API, MCP)'}
    - {vendor: OpenAI, models: GPT, use: 'entity disambiguation, signal title generation'}
    - {vendor: Anthropic, models: Claude, use: 'entity disambiguation, signal title generation'}
  controls: Only structured business data and the prompt context required for the task are sent; LLM outputs are validated against structured data
external_resources:
  - {name: Trust center, url: 'https://trust.sumble.com/', status: 200}
  - {name: System status, url: 'https://status.sumble.com/', status: 200}
evidence:
  - {source: 'https://trust.sumble.com/', status: 200, keywords: [vanta, trust center]}
  - {source: 'https://docs.sumble.com/trust-and-security/trust-and-security.md', status: 200, keywords: [soc 2, gdpr, encryption, access controls, trust center]}
checked: '2026-08-13'