Security
Trust & Security
Documented privacy controls, consent-forward architecture, and transparent data governance, built into every layer of the platform.
Certifications
Compliance You Can Verify
SOC 2 Type 2 in progress
Our security, availability, and confidentiality controls are documented and monitored continuously, and are being prepared for independent audit. We have not completed one yet, and we will not say otherwise until we have.
GDPR Programme
A documented legal basis for every record, a completed data protection impact assessment, and data subject rights you can exercise directly from this site.
CCPA and CPRA Rights
Submit opt-out, access, correction, or deletion requests through our privacy form. Site consent choices and browser opt-out preference signals are recorded by our consent controls.
Consent-Forward Data
Every identity record traces back to a consented, verified source. No scraped data, no inferred consent, no gray areas.
Data Subject Request (DSR)
Exercise your data rights under GDPR, CCPA, and other privacy regulations. Request access, correction, or deletion of your personal data.
Data Architecture
Identity data is processed in isolated environments with encryption at rest and in transit. No raw PII is stored. All identifiers are hashed (SHA-256) before entering the graph.
- AES-256 encryption at rest
- TLS 1.3 for all data in transit
- SHA-256 hashed identifiers only
- Isolated processing environments per customer
- No raw PII storage
Consent Framework
Delivr.ai is consent-forward by design. Every resolution path respects consumer opt-out preferences, and consent signals propagate across all downstream activations.
- Consent-forward architecture
- Consumer opt-out honored across all channels
- Browser opt-out preference signals recognised, including Global Privacy Control
- Suppression list support for email and phone
- Configurable consent policies per customer
Privacy Request Intake
Privacy requests can be submitted through our web form and tracked in Concord.
- Web form intake for access, correction, deletion, and opt-out requests
- Request IDs and status timestamps tracked in Concord
- Consent preferences captured through this site
Infrastructure Security
Platform runs on hardened infrastructure with continuous monitoring, automated vulnerability scanning, and incident response procedures.
- AWS infrastructure with VPC isolation
- Continuous vulnerability scanning
- Automated intrusion detection
- 24/7 security monitoring
- Documented incident response playbook
