Company profile

Customer.io

Security, DPA, Subprocessors, AI Data Usage, and Privacy Evidence

Customer.io is strong for legal/privacy evidence despite lacking a standalone Trust Center. AI subprocessor opt-out is a high-value teardown angle.

Evidence surface Observed public source What it means What not to infer
Security Observed security page or security documentation Security review surface Not implementation verification
DPA Observed DPA or legal terms reference Legal review surface Not a GDPR compliance determination
Subprocessors Observed subprocessor reference or list Vendor review surface Verify the live list before relying on it
AI data usage Observed AI policy, data usage language, or product documentation Model-training and data-handling review relevance Not implementation verification
Privacy Observed privacy policy or privacy documentation Privacy review surface Not legal compliance determination
Terms / Legal Observed terms, legal, or policy page Contract / legal review surface Not legal sufficiency or compliance determination
Category Customer engagement / messaging
Evidence status Candidate signal
Last checked 2026-06-27

Public evidence lookup surfaces

These rows summarize reviewed public evidence fields for each company profile. They show observed and not-promoted surfaces without making security, compliance, or buying-intent conclusions.

Evidence surface Review status Observed public source What it means What not to infer
Trust Center Not observed during review No standalone public source promoted in this review Customer-assurance surface Not proof of trust maturity, security quality, certification, or buying intent
Security Observed during review Source URL observed Security review surface Not implementation verification or control operating effectiveness
Privacy Observed during review Source URL observed Privacy review surface Not legal compliance determination
Terms / Legal Observed during review Source URL observed Contract and legal review surface Not legal sufficiency or compliance determination
DPA Observed during review Source URL observed Data processing legal review surface Not GDPR compliance proof
Subprocessors Observed during review Source URL observed Vendor and data-flow review surface Verify the live list before relying on it
Certification / compliance claim review Observed during review Observed field without standalone URL in this profile Assurance packaging or public claim review surface Not independent audit validation or current certification proof
AI policy / data usage Observed during review Source URL observed Model-training and data-handling review relevance Not implementation verification or model-risk conclusion
Enterprise-readiness evidence Observed during review Observed field without standalone URL in this profile Enterprise-readiness surface Not a complete control assessment or enterprise suitability judgment

Public evidence sections

Customer.io trust, security, and compliance evidence

Customer.io's reviewed public evidence includes trust, security, or compliance-related surfaces where observed. These may include security pages, compliance claims, security reports, customer-assurance references, or a Trust Center only when one is observed. Treat this as public evidence of trust packaging, not as independent verification of security quality or compliance status.

Customer.io privacy and AI data usage evidence

Customer.io's reviewed public evidence includes privacy or data-usage surfaces where observed. For AI products, these surfaces may be relevant to customer data handling, model-training language, retention, deletion, or buyer review questions. This profile does not independently verify legal compliance or technical implementation.

Customer.io DPA and subprocessor evidence

Customer.io's reviewed public evidence includes DPA or subprocessor-related surfaces where observed. Buyers should verify the live legal terms and current subprocessor list before relying on this evidence in a vendor review.

Customer.io enterprise-readiness evidence

Customer.io's reviewed public evidence includes enterprise-readiness surfaces where observed, such as SSO, SCIM, RBAC, audit logs, data residency, admin controls, report request workflows, or enterprise security references. This is public evidence context, not a complete control assessment.

What this public evidence does not prove

Do not infer that Customer.io is currently buying compliance, security, privacy, trust center, questionnaire automation, or AI governance tooling. Do not infer that unobserved evidence is absent. Do not treat this profile as a legal opinion, vendor-risk decision, compliance certification, security ranking, or proof that implementation matches public documentation.

Company name
Customer.io
Category
Customer engagement / messaging
Evidence status
Candidate signal
Current maturity stage
customer-data messaging platform with strong legal/security surface
Last checked
2026-06-27

Compliance and security claim status

AICPA SOC-related public claim observed; report type, entity scope, report period, and current status require verification; HIPAA-related public language observed; GDPR-related public language observed

Enterprise-readiness evidence

DPA; subprocessor list; AI feature subprocessors; HIPAA/GDPR/SOC positioning; security monitoring/pentest

False-positive note

Do not treat lack of Trust Center as immaturity; legal/security docs are strong and may fit a different disclosure model.