Is this your company?Buyers are checking Clay Labs here. Claim clay.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Go to market with unique data—and the ability to act on it. Access 100+ premium data sources and AI research agents in one platform, then automate growth workflows to turn insights into revenue. Note: To obtain a signed Data Processing Agreement (DPA) by Clay, customers must be on an Annual or Enterprise plan.
SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Clay Labs SOC 2 compliant?
Clay Labs is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Clay Labs GDPR compliant?
According to Clay Labs's public trust center, Clay Labs is GDPR compliant. On SOC2C this listing is Listed.
Is Clay Labs CCPA compliant?
According to Clay Labs's public trust center, Clay Labs is CCPA compliant. On SOC2C this listing is Listed.
Is Clay Labs ISO 27001 certified?
According to Clay Labs's public trust center, Clay Labs is ISO 27001 certified. On SOC2C this listing is Listed.
Is Clay Labs SOC 2 Type I or Type II?
Clay Labs is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Clay Labs's SOC 2 for a vendor risk assessment?
Yes. Clay Labs's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Clay Labs penetration tested?
Yes — Clay Labs undergoes third-party penetration testing as part of its security program. The pentest vendor is listed on its SOC2C profile.
Does Clay Labs have a penetration test report?
Clay Labs publishes a penetration test summary on its trust center. You can request access to it through SOC2C.
Does Clay Labs have an ISO 27001 certificate?
Clay Labs publishes an ISO certificate on its trust center; you can request access through SOC2C.
Is Clay Labs secure?
Security isn't a single yes/no, but Clay Labs is SOC 2 Type II compliant and holds SOC 2 Type II, SOC 2 Type I, GDPR, CCPA, ISO 27001, and undergoes third-party penetration testing. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Clay Labs have a bug bounty or vulnerability disclosure program?
Clay Labs hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@clay.com or via a /security page (Clay Labs lists a security contact).
Who are Clay Labs's subprocessors?
Clay Labs lists 34 subprocessors on its trust center, including Amazon Web Services, Amplitude, Anthropic, Braintrust, Datadog. Buyers use this for fourth-party risk review.
Where does Clay Labs host or store data?
Clay Labs hosts on AWS. Data residency details are on its trust center.
Where is Clay Labs's trust center or security page?
Clay Labs's trust center is at https://trust.clay.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Is Clay registered under the EU-US Privacy Framework?
Clay is not registered under the EU-US Privacy Framework. Insofar as Clay is required to legitimize data transfers pursuant to the GDPR, it does so using Standard Contractual Clauses.
Where does Clay get its data?
Clay provides its users with data from three types of sources. * Integration partners. Clay provides its customers with tools that enable them to connect with more than seventy third-party data providers and obtain data directly from them. * Websites. Clay’s HTTP API tool allows Clay’s customers to download data from public websites. * Proprietary Data. Clay maintains proprietary databases containing data it has acquired from third parties.
Who are your third-party data providers?
You can find a list of Clay’s integration partners here -https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit. This list includes location of data sources.
Where do your third-party data providers get their data?
We work with more than seventy integration partners who use industry-standard practices to collect lead data from a wide array of sources. Some sources are public. Others may be private or proprietary. For specific questions, we would invite you to reach out to the data provider directly. You can find a list of our data providers here - https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit).
Do your third-party data providers get consent to collect and share contact information?
While we are not in a position to monitor each provider’s specific practices, we expect and assume each of them obtains any permissions they would be required to obtain under the law – if any permission is required at all. In many cases, people may have already acknowledged and agreed their information may be copied when they share it on platforms like LinkedIn based on the User Agreement - https://www.linkedin.com/legal/user-agreement-summary - they accept upon signing up: When you share information on our Services, you understand that others can see, copy and use that information." If you have questions about a specific provider, we would invite you to reach out to that provider directly. You can find a list of our data providers here https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit.
Do your third-party data providers obtain their data lawfully?
We would not work with data providers who break the law. While we are not in a position to assess each provider’s specific practices, we work with data providers who have established strong reputations and employ industry-standard practices to gather the lead data they provide. If you have questions about a specific provider, we would invite you to reach out to that provider directly.
Do your third-party data providers scrape data from other platforms in violation of those platforms’ terms of service?
We work with more than seventy integration partners who use industry-standard practices to collect lead data from a wide array of sources. Some sources are public. Others may be private or proprietary. While we are not in a position to assess each provider’s specific practices, we work with data providers who have established strong reputations and employ industry-standard practices to gather the lead data they provide. If you have questions about a specific provider, we would invite you to reach out to that provider directly.
Do your third-party data providers transmit or receive personal data from countries outside the United States?
Clay works with more than seventy third-party data providers. While we are not in a position to monitor each provider’s specific practices, it is possible that some of the data they provide to Clay customers is collected in other countries. Insofar as that is the case, Clay relies on each provider to ensure the lawful transfer of data. To the extent Clay is required to legitimize data transfers pursuant to the GDPR, it does so using Standard Contractual Clauses.
Do you notify people that you have their contact information?
We would only notify people where required to do so by law. When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, we would rely on the third-party data provider (or other data controller) to provide any required notifications. Clay customers are, of course, free to provide notifications to people whose data they collect. We leave it to each data provider or customer to make its own assessment about any legal obligations they might have in this regard.
Do you get consent to collect and share contact information?
We would only obtain consent where required to do so by law. When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, we would rely on the third-party data provider (or other data controller) to obtain any required consent. While we are not in a position to monitor each provider’s specific practices, we expect and assume each of them obtains any permissions they would be required to obtain under the law – if any permission is required at all. In many cases, people may have already acknowledged and agreed their information may be copied when they share it on platforms like LinkedIn based on the User Agreement - https://www.linkedin.com/legal/user-agreement-summary - they accept upon signing up: “When you share information on our Services, you understand that others can see, copy and use that information.” If you have questions about a specific provider, we would invite you to reach out to that provider directly.
Do your third-party data providers notify people they have their contact information?
We rely on each third-party data provider to determine whether notice may be required, and provide any notice that may be required. If you have questions about a specific provider, we would invite you to reach out to that provider directly.
Do your third-party data providers get consent to collect and share contact information?
We rely on each third-party data provider to determine whether any consent would be required, and to obtain any such consent if any consent is required at all. In many cases, people may have already acknowledged and agreed their information may be copied when they share it on platforms like LinkedIn based on the User Agreement - https://www.linkedin.com/legal/user-agreement-summary - they accept upon signing up: “When you share information on our Services, you understand that others can see, copy and use that information." If you have questions about a specific provider, we would invite you to reach out to that provider directly.