Third Party Index

Snapshot 17948

Document
Trust center
URL
https://trust.optimove.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
125854 bytes
SHA-256 (raw)
d8c197d72448c3e725da3ccb69d863d0f98f2752c3b1b7252835769c428c4f83
SHA-256 (normalized text)
c0f0932dc94f5219c61fa1ab1cf804bea6006fbcff2f709ba177a9e5aaef90f7

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
Welcome to Optimove's Trust Center!
[email protected]
Privacy PolicyOpens in new tab
Our commitment to data privacy and security is embedded in every part of our business. The information on this portal is intended to help customers better understand the security posture and features of Optimove's products and our commitment to security and privacy.
Compliance
SOC 2
ISO 27001:2022
GDPR
CCPA
CREST Pen Tested
Resources
View all
ISO 27001
SOC2 Type 2 report
Optimove - SOC 2 Type 2 June 1 2025 May 31 2026
Policies
Code of Conduct
Ethics Policy
Information Security Policy
Modern Slavery Statement
Penetration test
Optimove API Penetration Test Final - 2025
Optimove SFTP Penetration Test Final - 2025
Optimove - Main Portal Attestation Letter 2025
GDPR
Optimove GDPR Compliance
Architecture
Architecture Diagram - Optimove 2026
Controls
View all
Infrastructure security
Unique production database authentication enforced
Encryption key access restricted
Unique account authentication enforced
View 18 more Infrastructure security controls
Organizational security
Asset disposal procedures utilized
Production inventory maintained
Portable media encrypted
View 9 more Organizational security controls
Product security
Data encryption utilized
Control self-assessments conducted
Penetration testing performed
View 2 more Product security controls
Internal security procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Cybersecurity insurance maintained
View 34 more Internal security procedures controls
Data and privacy
Data retention procedures established
Customer data deleted upon leaving
Data classification policy established
Subprocessors
View all
Google Cloud Platform
•
Cloud Provider
EU/US
Processed in the U.S. or EU, based on the information and preferences provided by the customer during the onboarding process.
Amazon Web Services
•
Cloud Provider
EU/US
Processed in the U.S. or EU, based on the information and preferences provided by the customer during the onboarding process.
Microsoft Corporation
•
Reporting and BI
EU/US
Processed in the U.S. or EU, based on the information and preferences provided by the customer during the onboarding process.
Snowflake
•
Database Platform
EU/US
Processed by default in the U.S., unless the customer specifically requests EU processing during commercial negotiations.
Updates
View all
General
Customer notice regarding Infobip
Published August 13, 2026
Customer notice regarding Infobip:
Please send out the following customer notification regarding the addition of Infobip as our new sub-processor. Please use the following language:
Sub-Processor Notification: Infobip
Purpose: SMS delivery via Optimove’s native messaging channel
⚠️ important Note:
This update is only applicable to customers who have purchased Optimove’s native SMS channel. Customers who utilize their own messaging infrastructure are not affected by this change.
We are updating our sub-processors list to include Infobip, a global cloud communications provider, for the purpose of enabling SMS delivery through Optimove’s native messaging capabilities.
In order to ensure that Infobip provides sufficient guarantees to process your personal data in an appropriate manner, the following measures have been implemented:
Infobip and Optimove have executed a data processing agreement.
Infobip has committed to executing Standard Contractual Clauses where required for international transfers.
Infobip will generally store personal data in Infobip data centers within the European Union.
Infobip represented that it provides sufficient guarantees to implement appropriate technical and organizational measures in such a manner that processing of personal data will meet the requirements of applicable privacy laws, including GDPR/UK GDPR, and ensure the protection of the rights of the data subjects. Infobip states that it is ISO 27001 and SOC 2 certified, among others.
We hereby provide notice of the engagement of a new sub-processor. Customers may raise objections in accordance with the terms of their Data Processing Agreement with Optimove by contacting_ [email protected].
To stay informed about future sub-processor updates, you may subscribe to notifications via your account settings or click here to subscribe.
For more information, please visit our Trust Center.
Best, Optimove
Compliance
SOC 2 Type II report
Published August 5, 2026
We're pleased to announce that our SOC 2 Type II report is now complete and available through our Trust Center. Existing customers and authorized partners can access the report directly through our Trust Center. If you have any questions or need assistance accessing the report, please contact our Security or Customer Success team.
Compliance
ISO 27001:2022 Certification Renewed
Published April 14, 2026
We're pleased to announce that Optimove has successfully renewed its ISO 27001:2022 certification, reaffirming our commitment to maintaining the highest standards of information security management.
This renewal reflects the continued effectiveness of our Information Security Management System (ISMS) and our ongoing dedication to protecting customer data through rigorous security controls, risk management practices, and continuous improvement.
For more details or to request a copy of our certificate, please download it or contact our security team.
Security
CREST Certified Penetration Testing Completed
Published September 15, 2025
Optimove has successfully completed a comprehensive CREST-certified penetration test, further strengthening our commitment to world-class cybersecurity.
What is CREST?
CREST is the internationally recognized gold standard for cybersecurity assessment. As one of the most prestigious certification bodies in the industry, CREST maintains exceptionally rigorous standards:
✅ Less than 5% of cybersecurity professionals worldwide achieve CREST certification
✅ Recognized across 24 countries as the premier security testing standard
✅ 500+ hours of intensive training and examination required for certification
✅ Continuous monitoring ensures only elite professionals maintain their status
Why This Matters for You?
By choosing CREST-certified penetration testing, Optimove demonstrates our unwavering dedication to enterprise-grade security that meets the most stringent international standards. This isn't just compliance – it's proof that your data is protected by security measures validated by the industry's most skilled professionals.
Your customer data and business intelligence remain absolutely secure under Optimove's rigorously tested security infrastructure.