SOC2C

Is this your company? Buyers are checking Grata Inc here. Claim grata.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Grata Inc logo

Grata Inc

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Grata Inc is SOC 2 Type II compliant. Grata Inc also holds GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Grata Inc. is a B2B search engine that helps private equity, corporate development, investment banking, and consulting teams discover deal-making opportunities in the middle market.

Compliance & infrastructure

Hosting
AWS

Documents

2

Subprocessors

5
  • A
    Amazon Web Services · Cloud provider
    US East 1 - Northern Virginia; EU Central 1 - Frankfurt, Germany
  • M
    MongoDB Atlas · Data storage and processing
    US East 1 - Northern Virginia; EU Central 1 - Frankfurt, Germany
  • T
    Twilio, Inc · SMS for Multi-Factor Authentication
    US East - Ashburn, Virginia
  • A
    Auth0 · Identity provider
    US East
  • D
    Datasite Costa Rica SRL · Customer Support
    San José, Costa Rica

Compliance leadership

The person who leads Grata Inc's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Grata Inc's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Grata Inc SOC 2 compliant?
Grata Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Grata Inc GDPR compliant?
According to Grata Inc's public trust center, Grata Inc is GDPR compliant. On SOC2C this listing is Listed.
Is Grata Inc SOC 2 Type I or Type II?
Grata Inc is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Grata Inc's SOC 2 for a vendor risk assessment?
Yes. Grata Inc's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Grata Inc penetration tested?
Grata Inc hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Grata Inc

Reproduced from Grata Inc's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do you support Single Sign-On (SSO)?
No. Single sign-on (SSO) is not supported.
What types of data does Grata collect from users?
Grata collects the first name, last name, and email from users solely for login/registration purposes. Additionally, Grata collects firmographic data on companies, which includes details such as company name, size, location, ownership, funding, growth, business model, industry, and executives. However, this data is primarily sourced from public sources and vendors. Grata does not collect personal information from mobile devices, except for tracking application performance and troubleshooting purposes.
Are web scraping activities traceable for the host sites?
Yes- although our proxy provider does not identify itself, individuals with specific anti-scraping protection are able to contact us. While we may not be directly traceable due to rotating IP addresses, any host site can still contact us (via our website or other means) if needed.
Do you encrypt data at rest?
Yes, all data is encrypted both at rest and in transit.
Is customer data used to train LLMs?
No, Grata does not use customer data to train our AI or any LLMs.

Business & Industrial peers that completed SOC 2