generated: '2026-08-09' method: searched source: https://trust.cbinsights.com/ docs: - https://trust.cbinsights.com/ - https://www.cbinsights.com/security-and-privacy/ - https://www.cbinsights.com/security/ trust_center: url: https://trust.cbinsights.com/ platform: Vanta http_status: 200 page_title: CB Insights Trust Center machine_readable: false readability_note: >- The trust center is a Vanta-hosted single-page app. It serves the same HTML shell with HTTP 200 for EVERY path on the host — /api/*, /trpc/*, invented paths — so a 200 there is not evidence that any particular document exists, and the certification list, control set and document requests all render client-side and could not be read without a browser. Certifications below are therefore taken from CB Insights' own server-rendered security page, not from the trust center. access: >- Reports appear to be gated behind a document request (an app.vanta.com/doc?s=... link is present in the page shell); no report is downloadable anonymously. certifications: - name: SOC 2 Type II status: certified evidence: '"Our infrastructure is audited and certified to meet the most rigorous standards for data security."' source: https://www.cbinsights.com/security-and-privacy/ - name: GDPR status: compliant evidence: '"We meet the strict requirements of the General Data Protection Regulation for data privacy and protection."' source: https://www.cbinsights.com/security-and-privacy/ - name: CCPA status: in-progress evidence: '"We''re actively preparing to meet CCPA standards."' source: https://www.cbinsights.com/security-and-privacy/ - name: EU AI Act (deployer obligations) status: in-progress evidence: '"...and the EU AI Act for deployers."' source: https://www.cbinsights.com/security-and-privacy/ not_claimed: - ISO 27001 - HIPAA - PCI DSS - FedRAMP security_controls_published: - AES 256-bit encryption at rest - TLS 1.2 in transit - full audit trail of activity - granular administrative controls on AI features - SSO, MFA and role-based access control - AI hallucination testing and observability ai_data_use: statement: '"Your data is never used to train the AI models we use. Period."' source: https://www.cbinsights.com/security-and-privacy/ vulnerability_disclosure: published: false probed: - url: https://www.cbinsights.com/.well-known/security.txt status: 404 - url: https://api-docs.cbinsights.com/.well-known/security.txt status: 404 - url: https://mcp.cbinsights.com/.well-known/security.txt status: 404 - url: https://api.cbinsights.com/.well-known/security.txt status: 401 note: >- No security.txt, no responsible-disclosure page, and no bug-bounty program (HackerOne, Bugcrowd or Intigriti) was found. The published security page names no security contact address; the only documented contact anywhere in the estate is the general info@cbinsights.com. cross_links: conformance: conformance/cb-insights-conformance.yml domain_security: security/cb-insights-domain-security.yml