generated: '2026-08-12' method: searched source: https://mountain.com/security/ trust_center: dedicated_portal: false page: https://mountain.com/security/ probes: - {url: 'https://trust.mountain.com', status: 0, result: NXDOMAIN} - {url: 'https://mountain.com/security/', status: 200} note: >- MNTN publishes a first-party security page rather than a hosted trust portal (no Vanta/Drata/ SafeBase/Conveyor instance). Documents are described on the page but are not offered for self-service download; an NDA/sales path is implied for the SOC 2 report itself. certifications: - name: SOC 2 Type II status: achieved period_ending: '2025-09-30' statement: 'We achieved our SOC2 Type II for the period ending 9/30/2025.' source: https://mountain.com/security/ report_self_service: false certifications_not_claimed: - ISO 27001 - ISO 27701 - PCI DSS - HIPAA - FedRAMP - TISAX - CSA STAR privacy_program: policies: - {name: Privacy Policy, url: 'https://mountain.com/privacy-policy/'} - {name: Regional Privacy Notice, url: 'https://mountain.com/regional-privacy-notice/'} - {name: Cookie Policy, url: 'https://mountain.com/cookie-policy/'} - {name: Terms and Conditions, url: 'https://mountain.com/terms-and-conditions/'} - {name: Terms of Use, url: 'https://mountain.com/terms-of-use/'} - {name: Creative Services Terms and Conditions, url: 'https://mountain.com/creative-services-terms-and-conditions/'} subprocessors: listed_on_page: true self_service_url: null note: The security page states a subprocessor list is available; no public URL is published for it. dpa: published_url: null relevance: note: >- MNTN operates a conversion pixel that collects site-visitor behaviour and supports customer audience uploads and CRM list imports (HubSpot, AppsFlyer), so its privacy posture is load-bearing for anyone integrating the pixel or pushing first-party data. A single SOC 2 Type II with no self-service report access and no published DPA is a thin evidence surface for that role.