SOC2C

Is this your company? Buyers are checking Urllo here. Claim urllo.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Urllo logo

Urllo

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Urllo is SOC 2 Type II compliant. Urllo also holds PCI DSS, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

At ur*ll*o, safeguarding your data is central to our operations. Our commitment to security, privacy and compliance informs every aspect of our platform and processes. This trust center provides transparency into the security practices we follow to protect your information. We invite you to explore our [compliance standards](/resources#67f84efb7590d2cc7cda101c), [controls](/controls), [subprocessors](/subprocessors) and [FAQs](/faq). Enterprise customers can also request access to our reports and attestations. To subscribe to updates (including changes to our subprocessors), click the bell ico

Compliance & infrastructure

Hosting
AWS
Data handled
Limited personally identifiable information (PII): https://www.urllo.com/legal/privacy-policy#a-3-personal-information-that-we-collect

Subprocessors

8
  • A
    Amazon Web Services · Platform infrastructure
    United States
  • C
    Chargebee, Inc. · Subscription & invoice management
    United States
  • D
    Datadog · Platform observability and error reporting
    United States
  • I
    Intercom R&D Unlimited Company · Customer support
    Ireland
  • A
    ActiveCampaign, LLC · Transaction email
    United States
  • C
    Castle Intelligence, Inc. · Threat management
    United States
  • S
    SmartBear Software · Error reporting
    United States
  • T
    Twilio Inc. · Product analytics
    United States

Compliance leadership

The person who leads Urllo's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Urllo's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

urllo 2026 SOC2 Type II ReportMay 2026

ur*ll*o has just released its SOC2 Type II report for the period of November 25, 2025 - February 25, 2026. SOC2 Type II reports are typically valid for at least 12 months after the certification date, and ur*ll*o will continue to validate its controls internally and externally with 3rd party AICPA accredited auditors. Enterprise customers and prospects may request access to the report under [Resources](/resources).

PCI Data Security Standard - Self-Assessment Questionnaire A and Attestation of ComplianceJun 2025

ur*ll*o has updated our Payment Card Industry Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance. The complete document is available to Enterprise customers upon request here-data-security-standard). Summary of changes: Removed Requirements 6.4.3, 11.6.1, and 12.3.1 and added an Eligibility Criteria for merchants to confirm that their site is not susceptible to attacks from scripts that could affect the merchant’s e-commerce system(s).

Subprocessor updateApr 2025

ur*ll*o has updated our Subprocessor List. These changes go into effect on Friday May 30th, 2025. The following subprocessors have been removed: - PagerDuty Inc. for application monitoring provider - Bugsnag Inc. for application monitoring - Atlassian, Inc. for application monitoring - Stripe, Inc. for subscription management and payment processing - Zoom Video Communications for video conferencing - Slack Technologies, LLC for customer communications - Docusign, Inc. for legal agreements - HubSpot, Inc. for customer communications - Peaberry Software, Inc. for customer communications - Zapier Inc. for analytics delivery - Satismeter s.r.o, for NPS testing - ChartMogul CMTDE GmbH & Co. KG for subscription analytics - Typeform SL for surveys - Google LLC for usage analytics - Mixpanel, Inc. for usage analytics - Inspectlet for usage analytics - APIHub, Inc. (dba Clearbit) for visitor and customer data enrichment You may object to a subprocessor by emailing [security@urllo.com](mailto:security@urllo.com) with the subject line “Subprocessor Objection” along with your name, your company’s name, the name of the subprocessor and the specific grounds for objection.

urllo 2025 SOC2 Type II ReportApr 2025

ur*ll*o has just released its SOC2 Type II report for the period of November 25, 2024 - February 25, 2024. SOC2 Type II reports are typically valid for at least 12 months after the certification date, and ur*ll*o will continue to validate its controls internally and externally with 3rd party AICPA accredited auditors. Enterprise customers and prospects may request access to the report under [Resources](/resources).

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Urllo SOC 2 compliant?
Urllo is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Urllo PCI DSS compliant?
According to Urllo's public trust center, Urllo is PCI DSS compliant. On SOC2C this listing is Listed.
Is Urllo GDPR compliant?
According to Urllo's public trust center, Urllo is GDPR compliant. On SOC2C this listing is Listed.
Is Urllo SOC 2 Type I or Type II?
Urllo is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Urllo's SOC 2 for a vendor risk assessment?
Yes. Urllo's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.