TPS Engage · Trust Center
Tps Engage Trust Center
Trust center
TPS Engage maintains a public trust center covering its security and compliance posture.
CompanyAdvertisingDOOHDigital BillboardsProgrammatic AdvertisingMedia BuyingOut-of-Home
Certifications & Compliance
Source
Trust Center
generated: '2026-08-13'
method: searched
source: https://seeblindspot.com/trust-and-security/
docs: https://seeblindspot.com/legal/
summary: >-
Blindspot publishes a genuine, self-hosted trust page at /trust-and-security/,
backed by a full legal hub at /legal/ with twelve policy documents including a
maintained subprocessor list and an accessibility conformance statement. It holds
no third-party security certifications and says so plainly rather than implying
otherwise: "Formal third-party certifications, where pursued, will be listed here
as they are obtained." The compliance posture that IS published is privacy- and
accessibility-shaped (GDPR-style DPA, named DPO, 30-day subprocessor notice, WCAG
2.2 AA), not audit-shaped. There is no third-party trust portal (Vanta/Drata/
SafeBase) and no downloadable evidence pack.
trust_center:
present: true
self_hosted: true
url: https://seeblindspot.com/trust-and-security/
provider: none (own site)
requires_nda: false
requires_login: false
certifications: []
certifications_note: >-
No SOC 2, ISO 27001, ISO 27701, PCI DSS, HIPAA or FedRAMP claim is made. The page
states certifications "where pursued, will be listed here as they are obtained",
which is an honest null rather than an unverifiable badge — worth noting because
unbacked cert claims are common in this sector.
compliance_program:
published: true
regimes:
- regime: GDPR / EU data protection
evidence: >-
"A Data Processing Addendum is available to customers" (obtainable from
dpo@seeblindspot.com). Named Data Protection Officer contact published.
EEA customer data is hosted in EU data centres. EEA contracting entity is
SC FREEDOM MASK SRL (Bucharest, Romania).
- regime: Subprocessor transparency
evidence: >-
Maintained public subprocessor list at https://seeblindspot.com/subprocessors/
with service and processing location per vendor, plus a commitment to "at least
30 days' notice before adding or replacing a subprocessor that processes
customer personal data, so they can review or object on reasonable
data-protection grounds."
- regime: US state privacy / opt-out
evidence: >-
Dedicated "Your Privacy Choices" page (https://seeblindspot.com/your-privacy-choices/)
alongside a cookie policy and a mobile-advertising-ID explainer
(https://seeblindspot.com/mobile-advertising-ids/).
- regime: WCAG 2.2 AA accessibility
evidence: >-
Published accessibility statement at
https://seeblindspot.com/accessibility-statement/ claiming WCAG 2.2 AA
conformance with a barrier-reporting route.
- regime: Advertising content standards
evidence: >-
Published advertising policy (allowed/prohibited creative, restricted
categories, review process) at https://seeblindspot.com/advertising-policy/ and
an acceptable use & enforcement policy at
https://seeblindspot.com/acceptable-use-policy/.
security_practices:
source: https://seeblindspot.com/trust-and-security/
encryption_in_transit: 'TLS 1.2+ ("Encryption of data in transit (TLS 1.2+) and of stored personal data at rest")'
encryption_at_rest: true
access_control: >-
"Access control on a least-privilege basis, with multi-factor authentication for
administrative and remote access"
logging: '"Logging, monitoring, and alerting across key systems"'
vulnerability_management: '"Vulnerability and patch management and secure software-development practices"'
backups: '"Backups and tested restoration for resilience"'
hosting: >-
"The Platform runs on Amazon Web Services (AWS)" — EU data centres for EEA
customer data, US data centres otherwise. AWS is resold via DoiT International
per the subprocessor list.
penetration_testing: not published
data_retention: not published
subprocessors:
url: https://seeblindspot.com/subprocessors/
notice_period: 30 days
count: 13
vendors:
- {name: DoiT International / AWS, service: Cloud hosting, location: EU and US}
- {name: Pipedrive, service: CRM, location: EU / US}
- {name: Cookiebot (Usercentrics), service: Cookie consent, location: EU}
- {name: SendGrid (Twilio), service: Transactional email, location: US / EU}
- {name: MailerLite, service: Marketing email, location: EU}
- {name: PostHog, service: Product analytics, location: EU / US}
- {name: Google Analytics, service: Analytics, location: US / EU}
- {name: LogRocket, service: Session analytics, location: US}
- {name: Mapbox, service: Maps, location: US}
- {name: Gleap, service: Support widget, location: EU / US}
- {name: Usermaven, service: Analytics, location: EU / US}
- {name: Narrative, service: Audience/attribution data, location: US}
- {name: Accretive, service: Measurement, location: US}
contacts:
security: security@seeblindspot.com
privacy: dpo@seeblindspot.com
support: support@seeblindspot.com
billing: billing@seeblindspot.com
legal_documents:
url: https://seeblindspot.com/legal/
documents:
- {name: Terms of Service, url: https://seeblindspot.com/terms-of-service/}
- {name: Privacy Policy, url: https://seeblindspot.com/privacy-policy/}
- {name: Cookie Policy, url: https://seeblindspot.com/cookie-policy/}
- {name: Your Privacy Choices, url: https://seeblindspot.com/your-privacy-choices/}
- {name: Accessibility Statement, url: https://seeblindspot.com/accessibility-statement/}
- {name: Advertising Policy, url: https://seeblindspot.com/advertising-policy/}
- {name: Refund & Credits Policy, url: https://seeblindspot.com/refund-and-credits-policy/}
- {name: Support & Disputes Policy, url: https://seeblindspot.com/support-and-disputes-policy/}
- {name: Acceptable Use & Enforcement Policy, url: https://seeblindspot.com/acceptable-use-policy/}
- {name: Subprocessors, url: https://seeblindspot.com/subprocessors/}
- {name: Trust & Security, url: https://seeblindspot.com/trust-and-security/}
- {name: Agency Addendum, url: https://seeblindspot.com/agency-addendum/}
observed:
- url: https://seeblindspot.com/trust-and-security/
status: 200
checked: '2026-08-13'
- url: https://seeblindspot.com/legal/
status: 200
checked: '2026-08-13'
- url: https://seeblindspot.com/subprocessors/
status: 200
checked: '2026-08-13'
- url: https://seeblindspot.com/trust/
status: 404
checked: '2026-08-13'
gaps:
- No third-party audit or certification of any kind.
- No published penetration-test cadence or summary letter.
- No published data-retention schedule.
- No machine-readable security.txt pointing at the trust page (see security/tps-engage-vulnerability-disclosure.yml).
- No uptime/availability commitment (see lifecycle/tps-engage-lifecycle.yml).