Tealium · Trust Center

Tealium Trust Center

Trust center

Tealium maintains a public trust center documenting SSAE18 SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27018, ISO/IEC 27701:2019, HIPAA & HITECH, TISAX, TX-RAMP, Cloud Security Alliance (CSA), GDPR, and CCPA compliance.

Customer Data PlatformCDPTag ManagementAudienceStreamReal-Time EventsVisitor ProfilesAudience SegmentationData CollectionPrivacy CompliancePersonalization
Trust center: https://trust.tealium.com/

Certifications & Compliance

SSAE18 SOC 2 Type IIISO/IEC 27001ISO/IEC 27018ISO/IEC 27701:2019HIPAA & HITECHTISAXTX-RAMPCloud Security Alliance (CSA)GDPRCCPA

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://trust.tealium.com/, https://tealium.com/security/
url: https://trust.tealium.com/
compliance_page: https://tealium.com/security/
certifications:
- SSAE18 SOC 2 Type II
- ISO/IEC 27001
- ISO/IEC 27018
- ISO/IEC 27701:2019
- HIPAA & HITECH
- TISAX
- TX-RAMP
- Cloud Security Alliance (CSA)
- GDPR
- CCPA
evidence:
- source: https://trust.tealium.com/
  keywords:
  - soc 2
  - iso 27001
  - hipaa
  - trust center
  - gdpr
- source: https://tealium.com/security/
  http_status: 200
  certifications_named:
  - HIPAA & HITECH
  - ISO/IEC 27001
  - ISO/IEC 27701:2019
  - ISO/IEC 27018
  - SSAE18 SOC2 Type II
  - TISAX
  - TX-RAMP
  - Cloud Security Alliance (CSA)
  note: >-
    The public Security & Compliance page names four certifications the trust center capture
    missed — ISO/IEC 27701:2019 (privacy information management), TISAX (automotive sector
    assessment), TX-RAMP (Texas state cloud authorization) and CSA membership. Added here on the
    2026-08-13 pass.

vulnerability_disclosure:
  program: false
  policy_url: null
  security_contact: null
  bug_bounty: false
  security_txt: false
  probed:
    - url: https://tealium.com/security/
      status: 200
      finding: >-
        Names certifications but publishes no disclosure policy, no security contact address and no
        reporting instructions. The only related sentence is "Tealium strives to keep ahead of
        attackers by working with security researchers, industry experts, and our customers" —
        an assertion of intent with no channel attached.
    - url: https://tealium.com/vulnerability-disclosure/
      status: 404
    - url: https://tealium.com/responsible-disclosure/
      status: 404
    - url: https://hackerone.com/tealium
      status: 404
    - url: https://bugcrowd.com/tealium
      status: 404
    - url: https://tealium.com/.well-known/security.txt
      status: 404
    - url: https://docs.tealium.com/.well-known/security.txt
      status: 404
    - url: https://platform.tealiumapis.com/.well-known/security.txt
      status: 404
  finding: >-
    NO published vulnerability disclosure route. A researcher who finds a flaw in Tealium has no
    documented address to send it to — no security.txt, no policy page, no bug bounty platform
    listing. This is the clearest single remediation available to Tealium: an RFC 9116
    /.well-known/security.txt naming a contact would close it in an afternoon. Because there is no
    program, no VulnerabilityDisclosure artifact and no `Security` pointer are emitted.

x-evidence:
  checked: '2026-08-13'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tealium-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.