SOC2C

Clay Labs security & compliance

An overview of Clay Labs's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksSOC 2 Type II, SOC 2 Type I, GDPR, CCPA, ISO 27001
Penetration testNot listed
Subprocessors34 listed
HostingAWS
Trust centerView

Security questions about Clay Labs

Is Clay Labs secure?
Security isn't a single yes/no, but Clay Labs is SOC 2 Type II compliant and holds SOC 2 Type II, SOC 2 Type I, GDPR, CCPA, ISO 27001, and undergoes third-party penetration testing. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Clay Labs have a bug bounty or vulnerability disclosure program?
Clay Labs hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@clay.com or via a /security page (Clay Labs lists a security contact).
Who are Clay Labs's subprocessors?
Clay Labs lists 34 subprocessors on its trust center, including Amazon Web Services, Amplitude, Anthropic, Braintrust, Datadog. Buyers use this for fourth-party risk review.
Where does Clay Labs host or store data?
Clay Labs hosts on AWS. Data residency details are on its trust center.
Where is Clay Labs's trust center or security page?
Clay Labs's trust center is at https://trust.clay.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Clay Labs's full SOC 2 profile →