Skip to content
Delivr.ai

Security

Trust & Security

Documented privacy controls, consent-forward architecture, and transparent data governance, built into every layer of the platform.

Certifications

Compliance You Can Verify

SOC 2 Type 2 in progress

Our security, availability, and confidentiality controls are documented and monitored continuously, and are being prepared for independent audit. We have not completed one yet, and we will not say otherwise until we have.

GDPR Programme

A documented legal basis for every record, a completed data protection impact assessment, and data subject rights you can exercise directly from this site.

CCPA and CPRA Rights

Submit opt-out, access, correction, or deletion requests through our privacy form. Site consent choices and browser opt-out preference signals are recorded by our consent controls.

Consent-Forward Data

Every identity record traces back to a consented, verified source. No scraped data, no inferred consent, no gray areas.

Data Subject Request (DSR)

Exercise your data rights under GDPR, CCPA, and other privacy regulations. Request access, correction, or deletion of your personal data.

Data Architecture

Identity data is processed in isolated environments with encryption at rest and in transit. No raw PII is stored. All identifiers are hashed (SHA-256) before entering the graph.

  • AES-256 encryption at rest
  • TLS 1.3 for all data in transit
  • SHA-256 hashed identifiers only
  • Isolated processing environments per customer
  • No raw PII storage

Consent Framework

Delivr.ai is consent-forward by design. Every resolution path respects consumer opt-out preferences, and consent signals propagate across all downstream activations.

  • Consent-forward architecture
  • Consumer opt-out honored across all channels
  • Browser opt-out preference signals recognised, including Global Privacy Control
  • Suppression list support for email and phone
  • Configurable consent policies per customer

Privacy Request Intake

Privacy requests can be submitted through our web form and tracked in Concord.

  • Web form intake for access, correction, deletion, and opt-out requests
  • Request IDs and status timestamps tracked in Concord
  • Consent preferences captured through this site

Infrastructure Security

Platform runs on hardened infrastructure with continuous monitoring, automated vulnerability scanning, and incident response procedures.

  • AWS infrastructure with VPC isolation
  • Continuous vulnerability scanning
  • Automated intrusion detection
  • 24/7 security monitoring
  • Documented incident response playbook