Is this your company? Buyers are checking Urllo here. Claim urllo.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Urllo
Sourced from public information. Not yet verified by the company.
Urllo is SOC 2 Type II compliant. Urllo also holds PCI DSS, and GDPR.
About
At ur*ll*o, safeguarding your data is central to our operations. Our commitment to security, privacy and compliance informs every aspect of our platform and processes. This trust center provides transparency into the security practices we follow to protect your information. We invite you to explore our [compliance standards](/resources#67f84efb7590d2cc7cda101c), [controls](/controls), [subprocessors](/subprocessors) and [FAQs](/faq). Enterprise customers can also request access to our reports and attestations. To subscribe to updates (including changes to our subprocessors), click the bell ico
Compliance & infrastructure
Subprocessors
8- AAmazon Web Services · Platform infrastructureUnited States
- CChargebee, Inc. · Subscription & invoice managementUnited States
- DDatadog · Platform observability and error reportingUnited States
- IIntercom R&D Unlimited Company · Customer supportIreland
- AActiveCampaign, LLC · Transaction emailUnited States
- CCastle Intelligence, Inc. · Threat managementUnited States
- SSmartBear Software · Error reportingUnited States
- TTwilio Inc. · Product analyticsUnited States
Compliance leadership
The person who leads Urllo's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Urllo's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
urllo 2026 SOC2 Type II ReportMay 2026
ur*ll*o has just released its SOC2 Type II report for the period of November 25, 2025 - February 25, 2026. SOC2 Type II reports are typically valid for at least 12 months after the certification date, and ur*ll*o will continue to validate its controls internally and externally with 3rd party AICPA accredited auditors. Enterprise customers and prospects may request access to the report under [Resources](/resources).
PCI Data Security Standard - Self-Assessment Questionnaire A and Attestation of ComplianceJun 2025
ur*ll*o has updated our Payment Card Industry Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance. The complete document is available to Enterprise customers upon request here-data-security-standard). Summary of changes: Removed Requirements 6.4.3, 11.6.1, and 12.3.1 and added an Eligibility Criteria for merchants to confirm that their site is not susceptible to attacks from scripts that could affect the merchant’s e-commerce system(s).
Subprocessor updateApr 2025
ur*ll*o has updated our Subprocessor List. These changes go into effect on Friday May 30th, 2025. The following subprocessors have been removed: - PagerDuty Inc. for application monitoring provider - Bugsnag Inc. for application monitoring - Atlassian, Inc. for application monitoring - Stripe, Inc. for subscription management and payment processing - Zoom Video Communications for video conferencing - Slack Technologies, LLC for customer communications - Docusign, Inc. for legal agreements - HubSpot, Inc. for customer communications - Peaberry Software, Inc. for customer communications - Zapier Inc. for analytics delivery - Satismeter s.r.o, for NPS testing - ChartMogul CMTDE GmbH & Co. KG for subscription analytics - Typeform SL for surveys - Google LLC for usage analytics - Mixpanel, Inc. for usage analytics - Inspectlet for usage analytics - APIHub, Inc. (dba Clearbit) for visitor and customer data enrichment You may object to a subprocessor by emailing [security@urllo.com](mailto:security@urllo.com) with the subject line “Subprocessor Objection” along with your name, your company’s name, the name of the subprocessor and the specific grounds for objection.
urllo 2025 SOC2 Type II ReportApr 2025
ur*ll*o has just released its SOC2 Type II report for the period of November 25, 2024 - February 25, 2024. SOC2 Type II reports are typically valid for at least 12 months after the certification date, and ur*ll*o will continue to validate its controls internally and externally with 3rd party AICPA accredited auditors. Enterprise customers and prospects may request access to the report under [Resources](/resources).
This listing is partial
6/11 details · 55%SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.