Trust & Compliance

Built for the most regulated industries on earth.

Healthcare, insurance, financial services, capital markets — we operate where the data is most sensitive and the rules change every quarter. Compliance isn't a feature here; it's the foundation.

Security & Compliance Posture

Growth Verticals, Inc.'s service commitments and system requirements were attested to be fully compliant with the applicable SOC 2 trust services criteria, HIPAA rule requirements, and HITRUST framework for the annual periods of 2024 and 2025.

SOC 2 Type II

SOC 2 Type II

Our SOC2 Type II report includes the results of an independent AICPA audit of our security, availability, and confidentiality controls, along with applicable HIPAA and HITRUST mappings.

HITRUST e1

Compliant

Compliant with the HITRUST e1 framework — a foundational set of cybersecurity controls focused on essential cyber-hygiene practices.

HIPAA Security & Breach Notification Rules

HIPAA Security & Breach Notification Rules

In SOC 2 Report

Evaluated as part of our SOC 2 Type II — scoped specifically to the HIPAA Security Rule and Breach Notification Rule. BAAs available on request.

CCPA / US State Privacy

Aligned

Privacy-by-design architecture aligned with CCPA/CPRA and emerging US state privacy laws.

Detailed Assurance and Audit Findings

There is reasonable assurance that Growth Verticals, Inc. achieved its service commitments and met system requirements based on the SOC 2 trust services criteria, which include security, availability, and confidentiality. Additionally, HIPAA criteria were satisfied, covering both security and breach notification rules. The HITRUST e1 framework was also met during this period, demonstrating comprehensive compliance with industry standards.

Independent Audit and Controls

Compliance was confirmed through an independent audit aligned with AICPA standards. This audit evaluated and deemed the company's security, availability, and confidentiality controls to be effective, supporting the overall assurance of regulatory adherence.

How We Protect Your Data

Six principles that govern every product decision — from schema design to vendor selection.

Privacy by Design

Compliance is embedded, not retrofitted. Every data path, schema, and integration is reviewed against regulatory posture before it ships.

Privacy-Preserving Record Linkage

TrustID is our patent-pending PPRL layer. Identity resolution happens without exposing PII — data is anonymized, tokenized, and encrypted before it enters our engine.

Ethically Sourced Data

Audience and intent data is collected from publisher sites and corroborated against opt-in consumer data at the household level — with full provenance.

State-by-State Regulatory Monitoring

We retain third-party privacy counsel to track state-specific privacy laws in real time. Restricted jurisdictions get household-level activation, not individual-level.

Zero-Trust Architecture

Records are decrypted on the fly through our key management system, used in real time, and re-encrypted before activation. No long-lived PII at rest in our engine.

Customer-Controlled Keys

You hold the keys to data access and can revoke them at any time. Our identity management, householding, and matching layers are designed for buyer control, not vendor lock-in.

Privacy Policy

How we collect, use, share, and retain information across our site and applications.

Read policy

Data Ethics

Our principles for ethical data sourcing, governance, and state-compliant activation.

Read our principles

DPA & BAA

Data Processing Addendums and HIPAA Business Associate Agreements available on request.

Request agreement

Questions about how we handle your data?

Our privacy team responds to compliance questions, audit requests, and subprocessor inquiries directly.

Start with the question

What are you trying to figure out?

See What G1 Can Answer

By clicking “Accept All”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.