generated: '2026-08-09' method: searched probe: true url: https://www.1lookup.io/security description: >- 1Lookup's /security page is its trust surface: a single public page covering compliance posture, security controls, infrastructure, data lifecycle and incident response. There is no separate trust.1lookup.io portal, no downloadable report library and no third-party audit certification. The page is unusually honest about that — each compliance item is explicitly labelled self-assessed, inherited via Stripe, or internal. subdomain_probed: - {url: 'https://www.1lookup.io/trust', status: 404} - {url: 'https://www.1lookup.io/compliance', status: 404} - {url: 'https://www.1lookup.io/dpa', status: 404} certifications: [] compliance_programs: - {name: GDPR, status: self-assessed, detail: 'EU General Data Protection Regulation; data subject rights supported, Standard Contractual Clauses for transfers.'} - {name: CCPA/CPRA, status: self-assessed, detail: 'California Consumer Privacy Act as amended by CPRA; includes an opt-out of sharing for advertising.'} - {name: PCI DSS, status: inherited, detail: 'Card payments handled by Stripe (PCI DSS Level 1). 1Lookup does not store full card numbers.'} - {name: Internal Security Policies, status: internal, detail: 'Documented access control, encryption and incident response policies, reviewed at least annually.'} controls: encryption: at_rest: AES-256 in_transit: TLS 1.3 key_management: AWS KMS with automatic rotation database: Transparent Data Encryption (TDE) access: authentication: Multi-factor authentication (MFA) authorization: Role-based access control (RBAC) api: Bearer token authentication session: Secure JWT with refresh tokens infrastructure: cloud: AWS with VPC isolation and private subnets network: Web Application Firewall (WAF), network ACLs, security groups ddos: Cloudflare Enterprise vulnerability_scanning: Automated daily scans application: OWASP Top 10 protection, input validation, API rate limiting monitoring: siem: 24/7 SIEM with alerts audit_logging: Immutable audit trail incident_response: Automated response playbooks control_review: Internal review, at least annually data_handling: retention: Automatic deletion after 30 days minimization: No personal data stored beyond validation requirements sharing: No data sharing with third parties (as stated) user_control: Download all your data; delete data at any time; granular privacy controls privacy: privacy_policy: https://www.1lookup.io/privacy terms: https://www.1lookup.io/terms gaps: - No SOC 2 Type II, ISO 27001 or other independent audit certification. - No third-party trust portal or document-request workflow. - No published DPA/subprocessor list at a discoverable URL. evidence: - {source: 'https://www.1lookup.io/security', keywords: [security & compliance, gdpr, ccpa, pci dss, soc, encryption, incident response]} x-evidence: - url: https://www.1lookup.io/security http_status: 200 fetched: '2026-08-09'