SOC2C

Is this your company? Buyers are checking Zoominfo here. Claim zoominfo.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Zoominfo logo

Zoominfo

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Zoominfo is SOC 2 compliant. Zoominfo also holds CSA STAR, ISO 27017, ISO 27001, and ISO 27701.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

ZoomInfo is a privacy-first company. From its inception, and as the discussion of data privacy in a digital world has evolved recently, ZoomInfo has consistently recognized privacy as an industry-wide priority and company-wide obligation. ZoomInfo provides companies with non-sensitive data, in a business context, for business purposes. We connect sellers and marketers with their next customer and recruiters with their next hire. We do this by offering the type of data you typically see on a business card or resume. ZoomInfo focuses exclusively on this non-sensitive data.

Compliance & infrastructure

CSA STARISO 27017ISO 27001ISO 27701
Hosting
AWS

Documents

13

Subprocessors

28
  • S
    SingleStore, Inc. · Database services; Analytics services
    USA
  • S
    Slack Technologies, LLC · Collaboration and messaging services
    USA
  • T
    The Trade Desk, Inc. · Digital advertising services
    USA
  • T
    Transloadit-II GmbH · File processing and security services
    Germany
  • T
    Twilio Inc. (Sendgrid) · Authentication; Telephony services
    USA
  • W
    Wasabi Technologies LLC · Data storage services
    USA
  • G
    Google LLC · Cloud hosting and infrastructure services; Generative AI services
    USA
  • A
    Amazon Web Services · Cloud hosting and infrastructure services
    USA
  • A
    Amplitude, Inc. · Product analytics services
    USA
  • A
    Anthropic, PBC · Generative AI services
    USA
  • 1
    1Mind AI, Inc. · Virtual AI chatbot services
    USA
  • A
    Adjiva Pte. Ltd. (aka DeltaX) · Digital advertising services
    Singapore
Show all 28 subprocessors
  • B
    Box · Document hosting and delivery services
    USA
  • C
    Catamorphic Co., dba LaunchDarkly · Feature management and testing services
    USA
  • C
    Confluent, Inc. · Data streaming services
    USA
  • D
    Databricks, Inc. · Data warehouse services
    USA
  • F
    Functional Software, Inc. dba Sentry · Application error monitoring services
    USA
  • G
    Gainsight, Inc. · Customer success platform
    USA
  • G
    Groq, Inc · AI services
    USA
  • L
    LangChain · AI development and observability services
    USA
  • M
    MongoDB, Inc. · Database services
    USA
  • O
    Okta, Inc. · Authentication and access management
    USA
  • O
    OpenAI OpCo, LLC · Generative AI services
    USA
  • O
    Outreach Corporation · Sales engagement services
    USA
  • P
    Pusher Limited · Real-time messaging services
    UK
  • S
    Salesforce.com Inc. · Customer relationship management
    USA
  • S
    Snowflake, Inc. · Data warehouse services
    USA
  • S
    Segment.io, Inc. · Customer data platform and analytics
    USA

Compliance leadership

The person who leads Zoominfo's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Zoominfo's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Zoominfo SOC 2 compliant?
Zoominfo is SOC 2 compliant. On SOC2C this listing is Listed.
Is Zoominfo CSA STAR certified?
According to Zoominfo's public trust center, Zoominfo is CSA STAR certified. On SOC2C this listing is Listed.
Is Zoominfo ISO 27017 certified?
According to Zoominfo's public trust center, Zoominfo is ISO 27017 certified. On SOC2C this listing is Listed.
Is Zoominfo ISO 27001 certified?
According to Zoominfo's public trust center, Zoominfo is ISO 27001 certified. On SOC2C this listing is Listed.
Is Zoominfo ISO 27701 certified?
According to Zoominfo's public trust center, Zoominfo is ISO 27701 certified. On SOC2C this listing is Listed.

Answers published by Zoominfo

Reproduced from Zoominfo's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Are you a data processor or controller?
Controller vs. Processor Under the GDPR, a “controller” means a person who “determines the purposes and means of the processing of personal data,” while a “processor” “processes personal data on behalf of the controller.” (GDPR Art. 4(7)-(8).) To the extent that ZoomInfo processes personal data within its proprietary database, ZoomInfo determines the means and purpose of such processing, and is therefore a controller. When those data are transmitted to one of ZoomInfo’s customers, we believe that the recipient also becomes a controller of those data because that customer is processing those data by its own means and for its own purposes. Because we are each independently controllers with respect to these data, to the extent we are processing them, ZoomInfo and its customer each have independent duties of a controller under the GDPR. ZoomInfo also acts as the processor of customer data that is provided to us in order to provide our products and services, such as customers’ employees’ personal data processed in order to access and use our database (e.g., name, email address, password) or the business contact information customers may transmit to ZoomInfo for purposes of matching, cleansing, or updating records with information from ZoomInfo’s database. In these situations, ZoomInfo acts as the processor of its customer data because it is processing the data on behalf of and at the direction of its customers.
What SLAs do you offer?
We strive for 99.9% uptime on a monthly basis. Status can be tracked here.
How Is Zoominfo Preparing for the Frontier AI Threat Landscape
Anthropic's announcement of Claude Mythos, and the broader emergence of frontier AI models capable of autonomously discovering and chaining software vulnerabilities, represents a pivotal evolution in the cyber threat landscape. ZoomInfo has been preparing for this, actively assessing how these new tools will change how we build and protect our systems, and converting those insights to actionable measures. ZoomInfo maintains a formal Vulnerability Management Program that governs the identification, prioritization, and remediation of CVEs across our environment. We leverage continuous scanning and threat intelligence feeds to ensure remediation velocity keeps pace with the abbreviated windows that AI-powered threat actors now operate within. We also maintain incident response and preparedness plans that account for advanced attack scenarios, including exploit chaining and AI-crafted social engineering, validated through periodic tabletop exercises and red team testing. Trust is foundational to everything we do at ZoomInfo. Protecting the data our customers entrust to us is not a compliance obligation, it is a core commitment. We will continue to invest in the people, processes, and technologies needed to stay ahead of an evolving threat landscape.

Business & Industrial peers that completed SOC 2