Third Party Index

Snapshot 20857

Document
Trust center
URL
https://trust.ortto.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
168989 bytes
SHA-256 (raw)
3bc2adb334f5655de349fd1617f9bbc23e0e5ca36aff584ab4cb013bc3b4e952
SHA-256 (normalized text)
6a922342d2c7461ad438260db1bd63c1b87b4af6051f8197b7fb8b2e0177905d

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
Ortto
Ortto (formerly Autopilot), is the world’s first complete marketing automation and analytics solution. We’re on a mission to empower marketers to execute impressive campaigns that drive business growth.
Sophisticated yet easy-to-use, our platform combines three powerful tools and supercharges them with AI so teams finally benefit from their customer data, marketing automation, and analytics working together.
[email protected]
Privacy PolicyOpens in new tab
Our Commitment to Security
Ortto is committed to the highest standards of security, integrating robust policies and procedures to protect both customer data and proprietary information. To ensure the confidentiality, integrity, and availability of all processed data, we employ industry-leading practices including data encryption, strict access controls, and continuous monitoring. Backed by a culture of continuous improvement, we are dedicated to maintaining compliance with rigorous frameworks such as SOC 2, ensuring our security posture proactively addresses emerging threats.
Explore Our Security Posture
Here, you can find our compliance artifacts, request specific documentation, and view high-level details on our established controls. In this portal, you can:
Review our compliance artifacts and high-level security controls.
Request Access to sensitive documents by clicking the button at the top of the page and submitting the short form.
Query our documentation instantly using the Trust Center AI feature (unlocked once your access is approved).
Terms of Use & Sharing Restrictions
All downloads provided are strictly for your internal and audit purposes only. If you need to share any of these materials with a third party other than your designated third-party auditor, you must obtain prior authorization:
Current or former clients: Please contact your Account Manager.
Prospective clients: Please contact your Sales Representative.
Compliance
SOC 2
ISO 27001:2022
ISO 27701:2019
GDPR
HIPAA
CCPA
Resources
View all
Compliance
SOC 2 Type II Report
ISO 27001:2022 and ISO 27701:2019 Report.pdf
View 1 more
Penetration Tests
Penetration Test - March 2026
Penetration Test - April 2025
Penetration Test - December 2023
Penetration Test - March 2023
View 2 more
Policies
ISMS Statement of Applicability
Access Control Policy
Business Continuity and Disaster Recovery Plan
Data Management Policy
View 7 more
Bug Bounty Program
Submission Form
Opens in new tab
https://ortto.com/.well-known/security.txt
Opens in new tab
Links
Security and Privacy
Opens in new tab
Data Privacy Framework Policy
Opens in new tab
GDPR Policy
Opens in new tab
Terms of Use
Opens in new tab
Controls
View all
Infrastructure Security
Unique production database authentication enforced
Encryption key access restricted
Unique account authentication enforced
View 41 more Infrastructure Security controls
Organizational Security
Asset disposal procedures utilized
Production inventory maintained
Portable media encrypted
View 107 more Organizational Security controls
Product Security
Data encryption utilized
Control self-assessments conducted
Penetration testing performed
View 11 more Product Security controls
Internal Security Procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Cybersecurity insurance maintained
View 115 more Internal Security Procedures controls
Data and Privacy
Data retention procedures established
Customer data deleted upon leaving
Data classification policy established
View 74 more Data and Privacy controls
Vendor & Third-Party Management
Addressing information security within supplier agreements
Disclosure of subcontractors used to process PII
Engagement of a subcontractor to process PII
View 17 more Vendor & Third-Party Management controls
Data collected
Customer personally identifiable information
Marketing preferences & consent data (opt-ins/opt-outs)
Purchase and transaction history
Campaign interaction data (opens, clicks, bounces. unsubscribes)
IP Geolocation
Behavioral & usage data (web tracking, page visits)
Device & technical data (browser type, cookies, device ID)
Form & survey responses
Externally sourced data (obtained from third-party providers to enhance contact profiles)
Employee personally identifiable information
Credit card information
Personal health information
Biometric data (fingerprinters, facial recognition, etc.)
Government-issued data (passport, driver's license)
Bank account or financial account details
Precise GPS / mobile location data
Medical or prescription data
Voice & call recording data
Video & screen recording data
Subprocessors
View all
Amazon Web Services
•
Cloud Infrastructure
United States, European Union, Australia
AWS provides the core cloud infrastructure that powers Ortto's platform, including compute, networking, and storage resources.
Recurly
•
Subscription Billing and Management
United States
Recurly manages Ortto's subscription billing lifecycle, including invoicing, payment processing, and renewals.
Twilio
•
SMS Delivery
United States, European Union, Australia
Twilio provides the telecommunications infrastructure that powers Ortto's SMS messaging capabilities, routing messages through its global carrier network on Ortto's behalf.
SendGrid
•
Email Delivery
United States
SendGrid handles the delivery of all customer-facing emails sent through Ortto, including campaigns, automated journeys, and transactional messages.
FAQ
View all
Updates
View all
Compliance
CSA STAR Registry Level 1 now available
Published April 30, 2026
Our CAIQ self-assessment is now available on the CSA STAR Registry at Level 1. You can find the link under Resources > Compliance.
Security
Penetration Test Report now available
Published March 22, 2026
Our latest penetration test report for March 2026 is now available.
Compliance
SOC 2 Type II Report now available
Published March 16, 2026
Our latest SOC 2 Type II recertification report, conducted by Prescient Assurance LLC and covering the period November 1, 2024 to January 31, 2026, is now available.
Compliance
ISO 27001 & ISO 27701 Report now available
Published February 25, 2026
Our latest ISO 27001 & ISO 27701 report dated January 23, 2026 is now available.
Media
View all
Introducing Ortto Opens in new tab
Ortto gets your customer data, marketing automation, and analytics working together in a platform underpinned by AI, so businesses can execute campaigns that drive business growth.