SOC2C

Is this your company? Buyers are checking Conversica here. Claim conversica.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Conversica logo

Conversica

conversica.com· United States· 51–200 employees
Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Conversica is SOC 2 Type II compliant. Conversica also holds ISO 27001, GDPR, CCPA, and PCI DSS.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to the Conversica Trust Center. We recognize that trust is built on transparency and earned with experience. For more than a decade we have been providing AI-powered digital assistant solutions from a SaaS platform, and we have implemented numerous safeguards to protect the data which our customers entrust to us.

Compliance & infrastructure

Hosting
AWSGCP

Documents

9

Subprocessors

10
  • Amazon Web Services · Data hosting and related processing and security services.
    USA
  • G
    Google Cloud · Data translation, DLP filtering, Vertex for vector embeddings for RAG (chat and
    USA
  • O
    OpenAI · Natural language generation for Chat, generative AI service features, NLP tasks
    USA
  • D
    Datadog · Converisca Primary Observability Platform
    USA
  • T
    Twilio · SMS (Text Message) services.
    USA
  • S
    Scanii · Security Software that processes and contains files for malware, phishing, spam
    USA
  • W
    Workato · Facilitates personal data transfer via API integration with our customers’ respe
    USA
  • Z
    Zendesk · Facilitates technical support plus chat integration and related data transmissio
    USA
  • V
    Vellum · Orchestration, configuration, testing, and monitoring layer for use of third par
    USA
  • A
    AtData (fka Fresh Address) · E-mail validation and analytics integration
    USA

Compliance leadership

The person who leads Conversica's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Conversica's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Conversica 2025 ISO-27001:2022 CertificateSep 2025

The latest ISO-27001:2022 certificate has been uploaded to the Conversica Trust website.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Conversica SOC 2 compliant?
Conversica is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Conversica ISO 27001 certified?
According to Conversica's public trust center, Conversica is ISO 27001 certified. On SOC2C this listing is Listed.
Is Conversica GDPR compliant?
According to Conversica's public trust center, Conversica is GDPR compliant. On SOC2C this listing is Listed.
Is Conversica CCPA compliant?
According to Conversica's public trust center, Conversica is CCPA compliant. On SOC2C this listing is Listed.
Is Conversica PCI DSS compliant?
According to Conversica's public trust center, Conversica is PCI DSS compliant. On SOC2C this listing is Listed.

Answers published by Conversica

Reproduced from Conversica's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Is Conversica a Data Controller or Data Processor?
With respect to the personal data which Conversica receives from its Customers and processes to initiate conversations with their prospects or customers, Conversica is a data processor. With respect to the data Conversica receives in connection with its own marketing efforts, Conversica is a data controller.
What transfer mechanism does Conversica use for cross-border transfers of data?
We certify to and rely on the EU-U.S. Data Privacy Framework, the United Kingdom (“UK”) extension thereto, and the Swiss-U.S. Data Privacy Framework as the primary transfer mechanisms. In addition, as a secondary mechanism we enter into the EU-approved Standard Contractual Clauses for cross-border transfers originating in the EU and similar contractual clauses for cross-border transfers originating in the UK.
Do I have to download code from Conversica to use the service?
No. But if you choose to use our website chat feature you would need to download an small amount of open-source Javascript code to deploy the chat feature. Also, if your company used salesforce as its CRM system and you wanted to transfer data from it to Conversica via the Conversica API, you could download the Conversica app from the salesforce appexchange to faciliate this transfer.
Does Conversica use any third parties in the process of providing services to customers?
Conversica does utilize sub-processors who are listed at https://trust.conversica.com/subprocessors/ All Customer Data is stored in Amazon Web Services data centers. The other sub-processors may or may not see a particular Customer’s data depending on which Conversica products and services that Customer is using.
How can I report a security issue?
You can contact us via email us at security@Conversica.com.

Business & Industrial peers that completed SOC 2