generated: '2026-08-13' method: searched probe: true url: https://www.lusha.com/trust-center description: >- Lusha runs a trust centre at https://www.lusha.com/trust-center. The automated probe of that URL returned HTTP 403 (Cloudflare "Just a moment..." interstitial on the marketing host), so the certifications below are read from Lusha's own documentation host, which names the trust centre as the place its compliance documents live and states the SOC 2 Type II certification outright. certifications: - SOC 2 Type II regulations: - GDPR documents: - name: Security overview availability: public (docs host) url: https://docs.lusha.com/user-guide/security/lusha-security-overview - name: Privacy policy availability: public url: https://lusha.com/legal/privacy-notice/ - name: Sub-processor list availability: public (trust centre) - name: SOC 2 Type II report availability: gated gate: Scale plan customers, or accounts with transactions exceeding $10,000 - name: Penetration test report availability: gated gate: NDA required note: findings assessed as very low risk; no separate remediation plan provided controls_published: - Encryption in transit (TLS) - Encryption at rest - Role-based access control (Admin / Manager / User) - SSO via SAML 2.0 (Scale plan) with Okta and custom IdP guides - Automatic inactive-session termination and sign-out-of-all-sessions - Minimum password strength enforcement security_contact: security@lusha.com evidence: - source: https://docs.lusha.com/user-guide/security/lusha-security-overview http_status: 200 keywords: [SOC 2 Type II, GDPR, trust center, penetration test, encryption at rest, RBAC, SAML] - source: https://www.lusha.com/trust-center http_status: 403 note: Cloudflare bot challenge; page not readable by an automated client - source: https://www.lusha.com/.well-known/security.txt http_status: 200