Trust and Security

    Built to be trusted with your pipeline.

    Security, compliance, and data-handling practices for the Domain Enrich platform, API, and Pre-Contact SQL Delivery.

    Security

    Encryption in transit (TLS 1.2+) and at rest (AES-256). Role-based access control, audit logs, and SSO / SAML / SCIM available on the Growth plan.

    SOC 2 Type II

    SOC 2 Type II reports are available on request under NDA. Our controls cover security, availability, and confidentiality.

    Data residency

    US data centers by default. Canada residency is available on request. EU residency is on the roadmap.

    Public-data sourcing

    Domain Enrich is built around publicly available business information - company websites, public filings, news, and professional profiles. We honor opt-out and deletion requests.

    CASL, GDPR, CCPA, and CAN-SPAM

    Domain Enrich is built for the US and Canadian Revenue Generation market and designed around the regulations that govern it. Every outbound email sent through the platform carries a compliant unsubscribe mechanism. Opt-out requests are honored across the product, including enrichment records.

    CASL (Canada): implied and express consent tracking on outbound, sender identification, and functioning unsubscribe on every message.

    GDPR / CCPA: data subject access and deletion requests are processed for both customer data and enriched records. Contact privacy@domainenrich.com or call 1-437-837-6002.

    CAN-SPAM (US): accurate headers and subject lines, physical-address footer, and prompt opt-out processing on all outbound sent through Domain Enrich.

    What we don't do

    Trust is easier to check when the boundaries are stated. A few things DomainEnrich will not claim about itself:

    • We do not guarantee meetings, opportunities or revenue outcomes.
    • We do not describe the workflow as 'fully automated' - there is a human loop by design.
    • We do not claim the biggest, best or most complete database. The database is not the product.
    • We do not replace your sales team. We hand your team qualified accounts they can act on.
    • We do not structure engagements around sources we cannot cite in the deliverable.

    Data Processing Agreement (DPA)

    A DPA is available on request and is standard on the Growth plan, alongside MSA and security review support. Request a copy or start a security review:

    See also our Privacy Policy, Terms of Service, and Cookie Policy.