Security & Compliance

    Enterprise-Grade Security

    Built for the security requirements of Fortune 500 companies, healthcare organizations, and financial services firms.

    Trusted by Global Clients and Agencies

    OracleGE HealthcarePhilipsMayne PharmaAstraZenecaThermo FisherAdobe

    SOC 2 Type II Aligned

    Full security, availability, and confidentiality controls with annual third-party audit. Documentation available for enterprise procurement.

    ISO 27001

    Information security management system aligned with international standard. Our controls are audited and continuously monitored.

    GDPR Compliant

    Full data processing agreements, right-to-erasure support, and EU data residency options for European customers.

    HIPAA-Aligned

    Healthcare data handled with HIPAA-aligned safeguards. Business Associate Agreements (BAA) available for covered entities.

    Data Encryption

    AES-256 encryption at rest, TLS 1.3 in transit for all data. No plaintext data storage at any layer of our infrastructure.

    Zero Data Retention

    Email addresses submitted for verification are deleted within 24 hours post-processing. No long-term storage of customer email data.

    Enterprise Security

    Built for Regulated Industries

    Our security posture was designed from the ground up to satisfy the requirements of pharmaceutical companies, financial services firms, and healthcare organizations. We understand that compliance isn't optional, it's a prerequisite.

    Full audit trails for all data access
    Role-based access control (RBAC)
    Single sign-on (SSO) via SAML 2.0
    IP allowlisting for API access
    Penetration testing, annual third-party
    Dedicated security contact: [email protected]

    Compliance Documentation

    Request our full security documentation package for enterprise procurement and legal review.

    BAA for Healthcare

    Business Associate Agreements available for covered entities under HIPAA. Contact [email protected].

    Security Review

    We accommodate customer security questionnaires and vendor review processes for enterprise onboarding.

    Catch-All Email Verification

    Verification Compliance

    Our catch-all verification engine checks deliverability without sending mail, so it does not trigger the anti-spam regulations that apply to a marketing send.

    SMTP-Based, Non-Intrusive

    Verification checks mailbox deliverability at the server level. No email is ever sent or delivered to the inbox owner during the process.

    CAN-SPAM & CASL Outside Scope

    Because verification does not transmit marketing content, it falls outside the scope of CAN-SPAM (US) and CASL (Canada) anti-spam requirements.

    24-Hour Deletion

    Email addresses submitted for verification are deleted from our systems within 24 hours of processing. No long-term storage of submitted lists.

    B2B & HCP Data Licensing

    Data Licensing Compliance

    Every B2B and HCP record we license is documented against a clear legal basis, by country, with no patient data included anywhere in the dataset.

    GDPR Lawful Basis

    UK and EU business contact records are documented under GDPR Article 6 legitimate interest, with full data provenance and lawful-basis documentation on request.

    CCPA Tagged

    California business records are tagged for CCPA applicability, with opt-out and deletion requests honored across our full dataset.

    No PHI, No Patient Records

    HCP data includes lawful business contact information only, no patient data, no clinical records, no prescribing history, and no Protected Health Information.

    CAN-SPAM Documentation

    US business records include CAN-SPAM compliance documentation, supporting lawful B2B outreach under US federal regulations.

    Country-Specific Adherence

    Licensed contact data spans the USA, UK & Ireland, and Canada today, each handled under that country's specific data protection requirements.

    Opt-Out & Suppression Lists

    Individuals who request removal are added to a permanent suppression list, honored across all future data refreshes and deliveries.

    Request Compliance Documentation

    SOC 2, ISO 27001, GDPR DPA, and HIPAA BAA, all available on request.

    Contact Enterprise Team