SOC2C

Is this your company? Buyers are checking Crossmint here. Claim crossmint.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Crossmint logo

Crossmint

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Report dated Dec 2024

Crossmint is SOC 2 Type II compliant, with its most recent report dated Dec 2024. Crossmint also holds GDPR, and US Data Privacy.

Framework
Auditor
Last report
Dec 2024
Renewal
View official trust center ↗

About

An all-in-one platform for companies and agents: wallets, payments, tokenization, and more.

Compliance & infrastructure

SOC 2 Type IIGDPRUS Data Privacy
Hosting
AWSGCPAzure

Documents

4

Compliance leadership

The person who leads Crossmint's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Crossmint's penetration test vendor isn't listed yet.

Claim this profile to add it.

Listing history

  • Listing information updated · by SOC2C
  • Listing information updated · by SOC2C
  • Listed on SOC2C

Recent updates

Crossmint DPF CertificationJul 2025

We’re proud to share that Crossmint, Inc. has successfully renewed its certification under the EU-U.S. Data Privacy Framework (EU-U.S. DPF), including the UK Extension and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). You can view our current certification on the official DPF website: https://www.dataprivacyframework.gov/list (Search for “Crossmint, Inc.” to confirm our active status.) Crossmint undergoes this re-certification annually, as required by the U.S. Department of Commerce, to ensure continued compliance with the data protection standards governing the transfer of personal data from the European Union, United Kingdom, and Switzerland to the United States.

Crossmint’s Privacy CommitmentsJul 2025

At Crossmint, we’re committed to transparency and data protection. We’ve recently updated our Privacy Policy to reflect the expansion of our services and to ensure alignment with the EU-U.S. Data Privacy Framework (DPF). These updates clarify: - Our participation in the DPF and the enforcement role of the U.S. Federal Trade Commission (FTC) - How we handle personal data through trusted subprocessors (e.g., customer support platforms) - How we may use secure, governed AI tools to improve internal workflows—never to train third-party models You can always review how your data is collected, used, and protected by visiting our Privacy Policy. Have questions? Reach out to us at privacy@crossmint.com

Subscribe to Updates From Crossmint's Trust CenterJul 2025

You can now subscribe to updates from Crossmint's Trust Center to be notified of any updates to our contractual terms, managed vendors, compliance and security program.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Crossmint SOC 2 compliant?
Crossmint is SOC 2 Type II compliant, with its most recent report dated Dec 2024. On SOC2C this listing is Listed.
Is Crossmint GDPR compliant?
According to Crossmint's public trust center, Crossmint is GDPR compliant. On SOC2C this listing is Listed.
Is Crossmint US Data Privacy compliant?
According to Crossmint's public trust center, Crossmint is US Data Privacy compliant. On SOC2C this listing is Listed.
Is Crossmint SOC 2 Type I or Type II?
Crossmint is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Crossmint's SOC 2 for a vendor risk assessment?
Yes. Crossmint's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Crossmint

Reproduced from Crossmint's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Is customer data encrypted?
Yes, Crossmint ensures that all customer data is encrypted both at rest and in transit. We utilize Advanced Encryption Standard (AES) for stored data and enforce Transport Layer Security (TLS) protocols for data transmitted over public networks. Our cryptographic controls adhere to industry standards, including NIST SP 800-57. Additionally, Crossmint has implemented a comprehensive Cryptography Policy that outlines our commitment to maintaining the confidentiality, integrity, and availability of customer data. This policy governs the selection, implementation, and management of cryptographic controls within our organization, ensuring that all encryption practices meet or exceed current industry standards.
Where is customer data stored?
Crossmint infrastructure is hosted in compliant data centers within the US and the EU. We leverage industry-standard cloud and database services, ensuring compliance with SOC 2, GDPR, and other industry-standard security measures​.
Where can I find Crossmint's Data Processing Addendum?
Crossmint's Data Processing Addendum (DPA) can be found here. Crossmint's Data Processing Addendum is also available upon request. Please contact us at [legal@crossmint.com](mailto:legal@crossmint.com) to obtain a copy.
How does Crossmint review NFT collections?
Crossmint reviews NFT collections to ensure they comply with our Terms of Service, Content Policy, and regulatory requirements. Our Collection Review Process assesses: - Submission quality – Collections must include accurate details, social accounts, and project documentation. - Regulatory compliance – NFTs must not be structured as investment contracts under U.S. securities laws. - Prohibited content – Collections must not contain IP-infringing, deceptive, or restricted content (e.g., gambling, adult content). Collections that do not meet these standards may be rejected or disabled at Crossmint’s discretion. If a collection is rejected, users can submit an appeal within 7 days. For more details, refer to our Collection Review Guidelines.
When does Crossmint require KYC verification?
Crossmint requires Know Your Customer (KYC) verification in compliance with Anti-Money Laundering (AML) regulations. To complete KYC, users must provide a government-issued photo ID, proof of address, and a selfie.

Retail & Commerce peers that completed SOC 2