generated: '2026-09-13' method: searched source: https://docs.experianaperture.io/more/request-for-information/experian-address-validation, https://docs.experianaperture.io/more/request-for-information/, https://www.experianplc.com/privacy trust_center: published: false url: null note: 'Experian operates no trust center in the modern sense — no trust.experian.com, no self-service portal serving SOC 2 reports, pen-test summaries or a live sub-processor list, and no downloadable evidence behind an NDA click-through. What it publishes instead is a Request for Information (RFI) page per product, which is a structured security questionnaire response: it answers the standard due-diligence questions in prose and names the certifications, but gates the evidence itself. Recorded as published: false because the artifact a buyer or an agent can actually read is an RFI page, not a trust center.' rfi_surface: published: true url: https://docs.experianaperture.io/more/request-for-information/ per_product_example: https://docs.experianaperture.io/more/request-for-information/experian-address-validation note: A per-product Request for Information page answering security, data-handling and compliance questions for each Data Quality product. certifications: - name: ISO/IEC 27001 scope: Experian Data Quality products evidence: 'Stated verbatim on the product RFI page: "ISO 27001 Certificates available upon request."' source: https://docs.experianaperture.io/more/request-for-information/experian-address-validation verified: documented-not-downloadable note: The certificate itself is not published; it is released on request. No certificate number, registrar or scope statement is public. certifications_unverified: note: 'Third-party and Experian marketing sources describe a wider certification estate — ISO 27017 and ISO 27018 cloud add-ons, Cyber Essentials, and SOC 2 Type 2 for the Tapad business Experian acquired. None of these was found stated on a first-party Experian page reachable in this pass, so they are recorded here as unverified leads rather than as certifications above. EI3PA (Experian Independent Third Party Assessment) is notable in the other direction: it is a standard Experian IMPOSES on its own data recipients rather than one it holds.' leads: - ISO 27017 - ISO 27018 - Cyber Essentials - SOC 2 Type 2 (Tapad, an Experian company) compliance_documents: - name: Privacy statement url: https://www.experianplc.com/privacy - name: Developer Portal privacy policy url: https://developer.experian.com/privacy-policy - name: Standard terms and conditions and policies (regional EDQ T&Cs, EULAs, fair-usage, cancellation) url: https://docs.experianaperture.io/standard-terms-and-conditions-and-policies - name: SaaS Services SLA url: https://docs.experianaperture.io/saas-services-sla - name: Global Support policy url: https://docs.experianaperture.io/global-support-policy/ regulatory_context: note: 'Experian is a consumer reporting agency and its credit products are regulated rather than merely certified — FCRA and GLBA in the United States, the Data Protection Act / UK GDPR and FCA regimes in the United Kingdom. Those obligations are structural to the business and are not a published API-security artifact, so they are recorded as context here and not claimed as certifications.'