SOC2C

Is this your company? Buyers are checking Kustomer here. Claim kustomer.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Kustomer logo

Kustomer

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Kustomer is SOC 2 Type II compliant. Kustomer also holds ISO 27001, ISO 27701, GDPR, HIPAA, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

At Kustomer, we believe trust from our customers is paramount. We recognize the importance of providing a top performing application that is continuously available, while protecting your data and keeping it private. Our security consists of layers of protection, starting with team policies and procedures, and incorporates continuous monitoring and automation built into our software development cycle. Our commitment to security extends to our partners and trained third-party security professionals who provide guidance, ensure compliance, and validate security across all areas of the organizatio

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card information

Documents

12

Subprocessors

15
  • A
    Amazon Web Services · Cloud Hosting Provider for Kustomer Application, SES, and AI Services (Amazon Be
    United States, Ireland, India
  • M
    MongoDB Atlas · Database
    United States, Ireland, India
  • C
    Coralogix · Cloud monitoring
    United States, Ireland, India
  • T
    Twilio · Native Voice + SMS Channel
    United States
  • G
    Google · EMail API
    United States
  • P
    Postmark · Email Channel
    United States
  • O
    OpenAI · AI Features
    United States
  • S
    Sentry · Cloud monitoring
  • E
    Elastic Cloud · Search Functionality
    United States or Ireland
  • S
    Snowflake · Data storage and processing
    United States, Ireland
  • P
    Pubnub · Supports Chat Functionality
    United States
  • P
    Pendo · Data analytics
    United States
Show all 15 subprocessors
  • D
    Deepgram · Voice Transcription
    United States
  • C
    ClickHouse, Inc. · Reporting and Analytics
    United States
  • A
    Anthropic · Engineering

Compliance leadership

The person who leads Kustomer's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Kustomer's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

New Subprocessor Notice: ClickHouse, Inc.Mar 2026

Kustomer has added ClickHouse, Inc. as a subprocessor to support reporting and analytics within the Kustomer platform. For more information, see our Subprocessor List and Data Protection Addendum.

CAIQ v4.1.0 Now AvailableFeb 2026

We’ve updated our Cloud Security Alliance (CSA) Consensus Assessments Initiative Questionnaire (CAIQ) to version 4.1.0 and published it in our Trust Center. This refresh helps ensure our security and privacy responses remain aligned to the latest CSA guidance and provides customers with clearer, up-to-date information for due diligence and risk assessments. CAIQ v4.1.0 was released on January 27, 2026, and our Trust Center now includes the updated questionnaire for review. If you rely on CAIQ mappings as part of your vendor assessment, you can use this version to support internal reviews, procurement, and compliance workflows.

New Security Datasheet & Information Security PoliciesNov 2025

To provide greater transparency into how we protect customer data, Kustomer has released an updated Security Datasheet, now available to all visitors through our Trust Center. The datasheet includes: - Highlights of in-app security features such as SSO, role-based access controls, IP allow listing, granular permissions and masking, and other controls built directly into the Kustomer app. - Highlights of Kustomer’s internal security program including our approach to data protection, secure development, incident management, vendor risk management, business continuity, and compliance. These highlights are intended to give security, privacy, and procurement teams a concise overview of how Kustomer protects customer data across both the product and our internal operations. For organizations that require deeper documentation, we also make Kustomer’s Information Security Policies available under NDA. These policies provide more detailed coverage of topics such as access management, secure development, incident response, vendor management, and data retention and disposal. - The Security Datasheet can be downloaded directly from the Kustomer Trust Center. - Information Security Policies can be requested through the Trust Center and will be shared under NDA.

New SOC 2 Type II Report Now AvailableNov 2025

Kustomer is pleased to announce that our latest SOC 2 Type II report is now available to customers and prospects via our Trust Center under NDA. This independent examination validates the design and operating effectiveness of our controls to safeguard customer data and keep our platform resilient and reliable. As part of our broader compliance program, Kustomer has also successfully completed an independent audit against ISO/IEC 27001:2022, the globally recognized standard for information security management systems. Together, these attestations demonstrate our commitment to maintaining strong security practices, rigorous access controls, and robust monitoring and incident response processes across our environment. If you are a current or prospective customer and would like access to the SOC 2 Type II report and ISO 27001 certificate, please submit a request through the Kustomer Trust Center so we can provide them under NDA.

Kustomer Achieves ISO 27701 CertificationOct 2025

We are proud to announce that Kustomer has been awarded ISO/IEC 27701:2019 certification, the leading international standard for Privacy Information Management Systems (PIMS). This certification extends the foundation of our ISO 27001 security framework to include robust, independently audited controls for the collection, processing, and protection of personal data. It demonstrates our commitment to aligning with global privacy regulations such as GDPR and CCPA, and provides customers with additional assurance that their data is handled with the highest standards of accountability and transparency. By achieving ISO 27701, we strengthen our position as a trusted partner, giving customers confidence that privacy and security are central to everything we do.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Kustomer SOC 2 compliant?
Kustomer is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Kustomer ISO 27001 certified?
According to Kustomer's public trust center, Kustomer is ISO 27001 certified. On SOC2C this listing is Listed.
Is Kustomer ISO 27701 certified?
According to Kustomer's public trust center, Kustomer is ISO 27701 certified. On SOC2C this listing is Listed.
Is Kustomer GDPR compliant?
According to Kustomer's public trust center, Kustomer is GDPR compliant. On SOC2C this listing is Listed.
Is Kustomer HIPAA compliant?
According to Kustomer's public trust center, Kustomer is HIPAA compliant. On SOC2C this listing is Listed.

Business & Industrial peers that completed SOC 2