generated: '2026-08-13' method: searched probe: true url: https://www.surfe.com/security/ description: >- Surfe publishes a public security page rather than a hosted trust centre. There is no trust.surfe.com (DNS does not resolve) and no third-party trust portal (Vanta / Drata / SafeBase / Whistic) was found. The page names two postures — ISO/IEC 27001 certification and GDPR compliance as both processor and controller — and describes encryption, access and incident-response practices in prose. No certification report, audit letter, or evidence download is offered, and SOC 2 is not claimed. certifications: - name: ISO 27001 claimed: true scope_statement: >- "Our ISO27001 certification sets rigorous requirements for managing and protecting sensitive data." auditor: not disclosed certificate_available: false - name: GDPR claimed: true role: both Data Processor and Data Controller certificate_available: false note: GDPR is a regulation, not a certification; recorded as a stated compliance posture. not_claimed: - SOC 2 - ISO 27017 - ISO 27018 - PCI DSS - HIPAA - FedRAMP - CSA STAR stated_controls: - CRM data accessed on demand only, over secured API connections, never without consent. - Data never sold under any circumstances. - Encryption in transit and at rest, including encrypted databases and secure OAuth token storage. - Salesforce OAuth used for user authentication so credentials are not entered into Surfe. - Disaster and incident-response plans maintained, tested and audited annually. - Data backed up ("Data rescue"). related_pages: - {name: Security, url: 'https://www.surfe.com/security/', status: 200} - {name: Privacy Policy, url: 'https://www.surfe.com/privacy-policy/', status: 200} - {name: Data Protection, url: 'https://www.surfe.com/data-protection/', status: 200} - {name: Terms and Conditions, url: 'https://www.surfe.com/terms-and-conditions/', status: 200} - {name: Terms and Conditions – API, url: 'https://www.surfe.com/terms-and-conditions-api/', status: 200} - {name: Legitimate Interests Assessment, url: 'https://www.surfe.com/legitimate-interests-assessment/'} - {name: Opt-out Mechanism, url: 'https://www.surfe.com/opt-out-mechanism/'} - {name: Legal Notice, url: 'https://www.surfe.com/legal-notice/'} - {name: Cookie Policy, url: 'https://www.surfe.com/cookie-policy/'} data_protection_note: >- Surfe sells B2B contact data, so its GDPR posture carries unusual weight for buyers: it publishes a Legitimate Interests Assessment and a data-subject opt-out mechanism as separate public pages, which is more than most providers in this category expose. evidence: - source: https://www.surfe.com/security/ http_status: 200 fetched: '2026-08-13' keywords: [iso 27001, iso27001 certified, gdpr compliant, encryption, incident response, data processor, data controller] - source: https://www.surfe.com/pricing/ http_status: 200 fetched: '2026-08-13' quote: Surfe is ISO27001 certified and GDPR compliant. probed_absent: - {url: 'https://trust.surfe.com/', result: 'DNS did not resolve (curl exit 6, status 000)'} - {url: 'https://www.surfe.com/trust/', status: 404} - {url: 'https://www.surfe.com/security-and-compliance/', status: 404}