Syft Data · Trust Center
Syft Data Trust Center
Trust center
Syft Data maintains a public trust center documenting SOC 2 Type I, SOC 2 Type II, Penetration Testing, and ISO 27001 compliance.
CompanyLead IntelligenceIntent DataWebsite Visitor IdentificationSales IntelligenceGo-To-MarketAnalyticsMCP
Certifications & Compliance
SOC 2 Type ISOC 2 Type IIPenetration TestingISO 27001
Source
Trust Center
generated: '2026-08-13'
method: searched
source: https://trust.syftdata.com (probed) and https://www.syftdata.com/dpa (contractual commitments)
summary: >-
Syft Data operates a trust center at trust.syftdata.com ("Trust Vault"), named
in its DPA as both the Security Policy location and the list of Approved
Subprocessors. The page returns HTTP 200 but is a JS-rendered Next.js app that
serves no readable content to an anonymous client, so the certifications below
are read from the DPA's own text rather than from the trust center itself.
trust_center:
url: https://trust.syftdata.com
status: 200
readable_anonymously: false
platform: unknown (Next.js "Trust Vault"; no vendor attribution in the served HTML)
checked: '2026-08-13'
note: >-
Content is rendered client-side; a curl of the page yields only the heading
"Trust Vault". Document access almost certainly requires a request/NDA flow.
certifications:
- name: SOC 2 Type I
status: committed
evidence: >-
DPA Cover Page — "Provider will maintain annually updated reports or annual
certifications of compliance with the following: SOC 2 Type I".
source: https://www.syftdata.com/dpa
- name: SOC 2 Type II
status: committed
evidence: >-
DPA Cover Page — same clause names SOC 2 Type II among the annually
maintained reports/certifications.
source: https://www.syftdata.com/dpa
- name: Penetration Testing
status: committed
evidence: DPA Cover Page lists annual penetration testing alongside the SOC 2 reports.
source: https://www.syftdata.com/dpa
- name: ISO 27001
status: not-claimed
evidence: Not named anywhere in the DPA, terms, or public site.
note_on_status: >-
"committed" means the provider contractually undertakes to maintain the report
or certification; it is NOT the same as a published, dated attestation. No SOC 2
report date, auditor, or certificate number is published anywhere public, and
the trust center does not expose one anonymously.
compliance:
- regime: GDPR
posture: DPA published with EEA Standard Contractual Clauses and the UK Addendum for international transfers.
source: https://www.syftdata.com/dpa
- regime: CCPA / CPRA
posture: >-
Syft Data, Inc. is designated a "service provider" under Cal. Civ. Code
§ 1798.100 et seq; DPA restricts use of personal data to the business purpose.
source: https://www.syftdata.com/dpa
- regime: Fair Credit Reporting Act
posture: DPA disclaims use of the service as a consumer report / for FCRA-regulated purposes.
source: https://www.syftdata.com/dpa
- regime: IAB TCF v2
posture: >-
Tracking tag reads and respects the TCF v2 consent string when a TCF-enabled
CMP is present; documented opt-out initialization for custom banners.
source: https://docs.syftdata.com/implementation/devguide
subprocessors:
url: https://trust.syftdata.com
published_anonymously: false
note: DPA names trust.syftdata.com as the Approved Subprocessors list; not readable without JS/registration.
documents:
- name: Data Processing Addendum
url: https://www.syftdata.com/dpa
last_updated: '2026-05-07'
- name: DPA Addendums
url: https://www.syftdata.com/dpa/addendums
- name: RB2B Addendum
url: https://www.syftdata.com/dpa/rb2b-addendum
- name: Terms of Service
url: https://www.syftdata.com/terms
- name: Privacy Policy
url: https://www.syftdata.com/privacy.html
legal_entity:
name: Syft Data, Inc.
address: 4101 Dublin Blvd Ste F #3123, Dublin, California 94568, United States
officer: Imran Patel, CEO
source: https://www.syftdata.com/dpa