generated: '2026-08-04' method: searched probe: true url: https://cordial.com/security/ title: Security & Compliance note: >- probe-security-programs.py returned trust=none because Cordial operates no trust. subdomain and no dedicated trust portal. A manual fetch of https://cordial.com/security/ (HTTP 200) confirmed a real published compliance page naming specific frameworks, so this artifact is recorded as searched with the page body as evidence. Only frameworks Cordial names on its own page are listed. certifications: - name: SOC 2 Type II status: compliant claim: 'Demands rigorous security policy creation, adherence and auditing. Cordial is SOC 2 Type II compliant.' report_available: unknown note: No public report request flow or automated NDA-gated portal was found. regulatory_alignment: - name: GDPR status: compliant claim: 'Cordial is GDPR and CCPA compliant.' - name: CCPA status: compliant claim: 'Cordial is GDPR and CCPA compliant.' - name: EU-U.S. Privacy Shield / Swiss-U.S. Privacy Shield status: claimed claim: 'Cordial complies with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce.' caveat: >- A live-site accuracy issue worth flagging to the provider: the EU-U.S. Privacy Shield was invalidated by the CJEU in July 2020 (Schrems II) and the Swiss-U.S. framework was likewise superseded. The successor is the EU-U.S. Data Privacy Framework. Cordial's own privacy policy at legal.cordial.com does reference dataprivacyframework.gov, so the security page appears to be stale rather than the underlying posture being wrong. channel_compliance: note: >- Cordial's messaging-channel documentation additionally cites compliance tooling for TCPA, CTIA, HIPAA and GDPR in the SMS/MMS channel. These are described as compliance FEATURES of the product (consent capture, quiet hours, opt-out handling), not as certifications Cordial holds. frameworks: [TCPA, CTIA, HIPAA, GDPR] source: https://cordial.com/platform/messaging-channels/sms-marketing/ privacy: policy: https://legal.cordial.com/privacy-policy/ sub_processors: https://legal.cordial.com/sub-processor-list/ note: >- A published sub-processor list is a meaningful enterprise-diligence artifact and is more than many peers publish. Global Privacy Control is referenced in the privacy policy. not_found: iso_27001: 'Not claimed anywhere on the public site.' pci_dss: 'Not claimed. Cordial is not a payments processor.' fedramp: 'Not claimed.' hitrust: 'Not claimed.' csa_star: 'Not claimed.' trust_portal: 'No trust.cordial.com (DNS does not resolve); no Vanta/Drata/SafeBase-style portal.' status_of_reports: 'No self-serve mechanism to request the SOC 2 report.' x-evidence: fetched: '2026-08-04' probes: - {url: 'https://cordial.com/security/', http_status: 200, keywords: ['SOC 2 Type II', 'GDPR', 'CCPA', 'Privacy Shield']} - {url: 'https://legal.cordial.com/privacy-policy/', http_status: 200} - {url: 'https://legal.cordial.com/sub-processor-list/', http_status: 200} - {url: 'https://trust.cordial.com', result: 'DNS does not resolve'} - {url: 'https://cordial.com/compliance/', http_status: 404}