Windfall · Trust Center

Windfall Trust Center

Trust center

Windfall maintains a public trust center documenting SOC 2 Type 2 and CCPA / California registered data broker compliance.

CompanyFintechData EnrichmentWealth DataPeople IntelligenceCareer DataIdentity ResolutionSales IntelligenceMarketing
Trust center: https://www.windfall.com/platform/privacy-security

Certifications & Compliance

SOC 2 Type 2CCPA / California registered data broker

Source

Trust Center

Raw ↑
generated: '2026-08-14'
method: searched
probe: false
url: https://www.windfall.com/platform/privacy-security
also: https://www.windfall.com/security
certifications:
- name: SOC 2 Type 2
  status: attested
  continuity: 5 consecutive years
  evidence: https://www.windfall.com/company/news/windfall-secures-5th-consecutive-soc-2-type-2-certification
- name: CCPA / California registered data broker
  status: registered
  evidence: https://www.windfall.com/platform/privacy-security
evidence:
- source: https://www.windfall.com/platform/privacy-security
  keywords:
  - soc 2 type 2 compliant
  - registered data broker in the state of California
  - fully compliant with CCPA
- source: https://www.windfall.com/security
  keywords:
  - TLS/HTTPS, SFTP, SSL certificates, data encryption
  - AES 256-bit server-side encryption
  - OWASP-aligned development standards
  - intrusion monitoring and data loss prevention
- source: https://www.windfall.com/company/news/windfall-secures-5th-consecutive-soc-2-type-2-certification
  keywords:
  - 5th consecutive SOC 2 Type 2 certification
trust_portal:
  exists: false
  probes:
  - {url: 'https://trust.windfall.com', status: 404}
  note: >-
    No dedicated trust portal, evidence room, subprocessor list, or downloadable
    attestation. Windfall publishes a narrative security page instead; obtaining
    the SOC 2 report goes through sales.
vulnerability_disclosure:
  exists: false
  security_txt: false
  bug_bounty: false
  contact: null
  probes:
  - {url: 'https://www.windfall.com/.well-known/security.txt', status: 404}
  - {url: 'https://windfall.com/.well-known/security.txt', status: 404}
  - {url: 'https://api-docs.windfall.com/.well-known/security.txt', status: 404}
  note: >-
    No responsible-disclosure policy, no security.txt on any host, no
    HackerOne/Bugcrowd/Intigriti program, and no published security contact
    address. A researcher who finds a flaw in an API that moves third-party PII
    has no documented channel. NO Security or VulnerabilityDisclosure pointer is
    wired, because there is no program to point at.
not_claimed:
- ISO 27001
- PCI DSS
- HIPAA
- FedRAMP
- GDPR
notes: >-
  Re-verified 2026-08-14. Windfall's compliance posture is a sustained SOC 2
  Type 2 program plus statutory California data-broker registration — the latter
  being the regime that actually governs this API, since the request body is
  third-party PII and the response is inferred wealth, philanthropy and
  political-giving data about a natural person.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/windfall-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.