generated: '2026-08-13' method: searched source: https://www.pabbly.com/security/ provider: Pabbly providerId: pabbly trust_center: published: true style: security-page url: https://www.pabbly.com/security/ mirror: https://buy.pabbly.com/security/ machine_readable_mirror: https://buy.pabbly.com/content/security.md note: >- Not a hosted trust portal (no Vanta/Drata/SafeBase instance, no document request flow). A single marketing-site security page, mirrored as markdown on the buy.pabbly.com content host — which is unusual and genuinely useful: the same claims are retrievable as text/markdown for an agent. certifications: - id: iso-27001-2022 name: ISO/IEC 27001:2022 status: certified claim: >- "Our steadfast commitment is backed by the prestigious ISO 27001:2022 Certification, a testament to our world-class data protection standards." evidence_url: https://www.pabbly.com/security/ report_available: false note: No certificate number, certification body or audit date is published. - id: soc2-type2 name: SOC 2 Type 2 status: compliant claim: >- "We take pride in our SOC2 Type 2 Compliance, showcasing our dedication to rigorous audits, stringent controls, and comprehensive risk management." evidence_url: https://www.pabbly.com/security/ report_available: false note: No auditor, report period or NDA request path is published. not_claimed: - PCI DSS - HIPAA - FedRAMP - GDPR (no dedicated page; https://www.pabbly.com/gdpr/ returns 404) practices_published: - 128-bit SSL encryption in transit - AES encryption at rest - Two-factor authentication - Cloudflare DDoS protection - Periodic third-party penetration testing - Vulnerability scanning and patching - No storage of credit card details (handled by payment gateways only) - Email verification data deleted after 15 days vulnerability_disclosure: security/pabbly-vulnerability-disclosure.yml maintainers: - FN: Kin Lane email: kin@apievangelist.com