TPS Engage · Trust Center

Tps Engage Trust Center

Trust center

TPS Engage maintains a public trust center covering its security and compliance posture.

CompanyAdvertisingDOOHDigital BillboardsProgrammatic AdvertisingMedia BuyingOut-of-Home
Trust center:

Certifications & Compliance

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
source: https://seeblindspot.com/trust-and-security/
docs: https://seeblindspot.com/legal/
summary: >-
  Blindspot publishes a genuine, self-hosted trust page at /trust-and-security/,
  backed by a full legal hub at /legal/ with twelve policy documents including a
  maintained subprocessor list and an accessibility conformance statement. It holds
  no third-party security certifications and says so plainly rather than implying
  otherwise: "Formal third-party certifications, where pursued, will be listed here
  as they are obtained." The compliance posture that IS published is privacy- and
  accessibility-shaped (GDPR-style DPA, named DPO, 30-day subprocessor notice, WCAG
  2.2 AA), not audit-shaped. There is no third-party trust portal (Vanta/Drata/
  SafeBase) and no downloadable evidence pack.
trust_center:
  present: true
  self_hosted: true
  url: https://seeblindspot.com/trust-and-security/
  provider: none (own site)
  requires_nda: false
  requires_login: false
certifications: []
certifications_note: >-
  No SOC 2, ISO 27001, ISO 27701, PCI DSS, HIPAA or FedRAMP claim is made. The page
  states certifications "where pursued, will be listed here as they are obtained",
  which is an honest null rather than an unverifiable badge — worth noting because
  unbacked cert claims are common in this sector.
compliance_program:
  published: true
  regimes:
  - regime: GDPR / EU data protection
    evidence: >-
      "A Data Processing Addendum is available to customers" (obtainable from
      dpo@seeblindspot.com). Named Data Protection Officer contact published.
      EEA customer data is hosted in EU data centres. EEA contracting entity is
      SC FREEDOM MASK SRL (Bucharest, Romania).
  - regime: Subprocessor transparency
    evidence: >-
      Maintained public subprocessor list at https://seeblindspot.com/subprocessors/
      with service and processing location per vendor, plus a commitment to "at least
      30 days' notice before adding or replacing a subprocessor that processes
      customer personal data, so they can review or object on reasonable
      data-protection grounds."
  - regime: US state privacy / opt-out
    evidence: >-
      Dedicated "Your Privacy Choices" page (https://seeblindspot.com/your-privacy-choices/)
      alongside a cookie policy and a mobile-advertising-ID explainer
      (https://seeblindspot.com/mobile-advertising-ids/).
  - regime: WCAG 2.2 AA accessibility
    evidence: >-
      Published accessibility statement at
      https://seeblindspot.com/accessibility-statement/ claiming WCAG 2.2 AA
      conformance with a barrier-reporting route.
  - regime: Advertising content standards
    evidence: >-
      Published advertising policy (allowed/prohibited creative, restricted
      categories, review process) at https://seeblindspot.com/advertising-policy/ and
      an acceptable use & enforcement policy at
      https://seeblindspot.com/acceptable-use-policy/.
security_practices:
  source: https://seeblindspot.com/trust-and-security/
  encryption_in_transit: 'TLS 1.2+ ("Encryption of data in transit (TLS 1.2+) and of stored personal data at rest")'
  encryption_at_rest: true
  access_control: >-
    "Access control on a least-privilege basis, with multi-factor authentication for
    administrative and remote access"
  logging: '"Logging, monitoring, and alerting across key systems"'
  vulnerability_management: '"Vulnerability and patch management and secure software-development practices"'
  backups: '"Backups and tested restoration for resilience"'
  hosting: >-
    "The Platform runs on Amazon Web Services (AWS)" — EU data centres for EEA
    customer data, US data centres otherwise. AWS is resold via DoiT International
    per the subprocessor list.
  penetration_testing: not published
  data_retention: not published
subprocessors:
  url: https://seeblindspot.com/subprocessors/
  notice_period: 30 days
  count: 13
  vendors:
  - {name: DoiT International / AWS, service: Cloud hosting, location: EU and US}
  - {name: Pipedrive, service: CRM, location: EU / US}
  - {name: Cookiebot (Usercentrics), service: Cookie consent, location: EU}
  - {name: SendGrid (Twilio), service: Transactional email, location: US / EU}
  - {name: MailerLite, service: Marketing email, location: EU}
  - {name: PostHog, service: Product analytics, location: EU / US}
  - {name: Google Analytics, service: Analytics, location: US / EU}
  - {name: LogRocket, service: Session analytics, location: US}
  - {name: Mapbox, service: Maps, location: US}
  - {name: Gleap, service: Support widget, location: EU / US}
  - {name: Usermaven, service: Analytics, location: EU / US}
  - {name: Narrative, service: Audience/attribution data, location: US}
  - {name: Accretive, service: Measurement, location: US}
contacts:
  security: security@seeblindspot.com
  privacy: dpo@seeblindspot.com
  support: support@seeblindspot.com
  billing: billing@seeblindspot.com
legal_documents:
  url: https://seeblindspot.com/legal/
  documents:
  - {name: Terms of Service, url: https://seeblindspot.com/terms-of-service/}
  - {name: Privacy Policy, url: https://seeblindspot.com/privacy-policy/}
  - {name: Cookie Policy, url: https://seeblindspot.com/cookie-policy/}
  - {name: Your Privacy Choices, url: https://seeblindspot.com/your-privacy-choices/}
  - {name: Accessibility Statement, url: https://seeblindspot.com/accessibility-statement/}
  - {name: Advertising Policy, url: https://seeblindspot.com/advertising-policy/}
  - {name: Refund & Credits Policy, url: https://seeblindspot.com/refund-and-credits-policy/}
  - {name: Support & Disputes Policy, url: https://seeblindspot.com/support-and-disputes-policy/}
  - {name: Acceptable Use & Enforcement Policy, url: https://seeblindspot.com/acceptable-use-policy/}
  - {name: Subprocessors, url: https://seeblindspot.com/subprocessors/}
  - {name: Trust & Security, url: https://seeblindspot.com/trust-and-security/}
  - {name: Agency Addendum, url: https://seeblindspot.com/agency-addendum/}
observed:
- url: https://seeblindspot.com/trust-and-security/
  status: 200
  checked: '2026-08-13'
- url: https://seeblindspot.com/legal/
  status: 200
  checked: '2026-08-13'
- url: https://seeblindspot.com/subprocessors/
  status: 200
  checked: '2026-08-13'
- url: https://seeblindspot.com/trust/
  status: 404
  checked: '2026-08-13'
gaps:
- No third-party audit or certification of any kind.
- No published penetration-test cadence or summary letter.
- No published data-retention schedule.
- No machine-readable security.txt pointing at the trust page (see security/tps-engage-vulnerability-disclosure.yml).
- No uptime/availability commitment (see lifecycle/tps-engage-lifecycle.yml).