Is this your company? Buyers are checking Judge.me here. Claim judge.me free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Judge.me
Sourced from public information. Not yet verified by the company.
Judge.me is SOC 2 Type II compliant. Judge.me also holds ISO 27001, NIST CSF, GDPR, and CCPA.
About
Our Mission: Trust Gap Zero Judge.me is driven by a singular mission: scaling merchants with consumer confidence. We believe that trust is the fundamental currency of e-commerce, and our platform exists to bridge the gap between merchant capabilities and consumer confidence. By facilitating authentic social proof at scale, we help businesses of all sizes build the trust necessary for sustainable growth. Security as a Core Pillar At Judge.me, security isn't just a feature - it's foundational to our mission of building trust. We recognise that our role in the e-commerce ecosystem carries signifi
Compliance & infrastructure
Documents
3Subprocessors
8- AAmazon Web Services · Cloud provider
- MMongoDB Atlas · mongoatlas
- GGitHub · Version control
- IIntercom · Customer support
- PPostmark · Marketing
- GGoogle Workspace · Document management
- RRedis Inc · Data storage and processing
- SSendgrid · Marketing
Compliance leadership
The person who leads Judge.me's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Judge.me's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
ISO 27001:2022Dec 2025
Judge.me are pleased to announce that we are now ISO 27001 certified. Our certificate is now available to download via the resources section of this portal.
SOC 2 Type 2 Yearly AuditJun 2025
We are pleased to announce that our most recent SOC 2 Type 2 report is now available for access (April 2025)
SOC 2 Type 2 Yearly AuditJan 2025
We are currently in the process of validating our SOC2 Type 2 compliance for this cycle. Please check back in May 2025 for our latest compliance report.
This listing is partial
7/11 details · 64%SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Judge.me SOC 2 compliant?
Is Judge.me ISO 27001 certified?
Is Judge.me NIST CSF compliant?
Is Judge.me GDPR compliant?
Is Judge.me CCPA compliant?
Is Judge.me SOC 2 Type I or Type II?
Can I use Judge.me's SOC 2 for a vendor risk assessment?
Is Judge.me penetration tested?
Does Judge.me offer a Data Processing Agreement (DPA)?
Is Judge.me secure?
Does Judge.me have a bug bounty or vulnerability disclosure program?
Who are Judge.me's subprocessors?
Where does Judge.me host or store data?
Does Judge.me offer a Data Processing Agreement (DPA)?
Where is Judge.me's trust center or security page?
How do I disable review request emails for customers opting out of Shopify marketing emails?
Retail & Commerce peers that completed SOC 2

Paella Inc

Wrks
