generated: '2026-08-13' method: searched probe: true url: https://mailchimp.com/about/security/ source: https://mailchimp.com/about/security/ checked: '2026-08-13' http_status: 200 description: >- Mailchimp does not run a branded trust portal at trust.mailchimp.com (no such host) — its public security, compliance and privacy posture is published on one page, https://mailchimp.com/about/security/, which names the certifications, the audit cadence, the responsible-disclosure program and the privacy frameworks. Certification documents themselves are distributed through the Intuit compliance portal, since Mailchimp is an Intuit company. certifications: - name: SOC 2 evidence: >- "Our SOC 2 reports cover controls around security, availability, and process integrity of customer data." - name: ISO 27001 evidence: >- "The International Organization for Standardization 27001 Standard (ISO 27001) is an information security standard that ensures office sites, development centers, support centers, and data centers are securely managed." - name: EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF) evidence: >- "We undergo annual verification with a U.S. based third party-outside compliance reviewer under the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF)." - name: GDPR evidence: Dedicated compliance page at https://mailchimp.com/gdpr/ (HTTP 200, fetched 2026-08-13). - name: VPAT (Section 508 accessibility) evidence: >- "Mailchimp also maintains a VPAT, or Voluntary Product Accessibility Template (VPAT®)." audit_cadence: >- "These certifications run for 3 years (renewal audits) and have annual touchpoint audits (surveillance audits)." not_claimed: - PCI DSS - HIPAA - FedRAMP - ISO 27017 - ISO 27018 - CSA STAR notes_on_pci: >- The page describes card-association compliance (Visa CISP, Mastercard SDP, Discover DISC) held by Mailchimp's PAYMENT PROCESSING VENDOR, not by Mailchimp. Recorded here so it is not misread as a Mailchimp certification. security_program: penetration_testing: >- Regular external and internal penetration tests throughout the year using different vendors, plus social engineering drills; results kept confidential. transport: Entire application and API encrypted with TLS 1.2 or higher. account_controls: [two-factor authentication, tiered account access, brute-force protection on API logins] data_residency: Owned and operated servers in United States data centers. memberships: [ESPC, M3AAWG, ISC2, ISACA, ISSA, SANS, IAPP] related: vulnerability_disclosure: security/mailchimp-vulnerability-disclosure.yml domain_security: security/mailchimp-domain-security.yml conformance: conformance/mailchimp-conformance.yml evidence: - source: https://mailchimp.com/about/security/ http_status: 200 keywords: [SOC 2, ISO 27001, responsible disclosure, penetration testing, Data Privacy Framework, VPAT] - source: https://mailchimp.com/gdpr/ http_status: 200 keywords: [GDPR, Data Privacy Framework] - source: https://mailchimp.com/legal/data-processing-addendum/ http_status: 200 keywords: [GDPR, data processing addendum] - source: https://trust.intuit.com/ http_status: 200 note: Resolves but returns a "404 | Page not found" body — no usable Intuit trust portal at that host.