Built for the most regulated industries on earth.
Healthcare, insurance, financial services, capital markets — we operate where the data is most sensitive and the rules change every quarter. Compliance isn't a feature here; it's the foundation.
Security & Compliance Posture
Growth Verticals, Inc.'s service commitments and system requirements were attested to be fully compliant with the applicable SOC 2 trust services criteria, HIPAA rule requirements, and HITRUST framework for the annual periods of 2024 and 2025.

SOC 2 Type II
Our SOC2 Type II report includes the results of an independent AICPA audit of our security, availability, and confidentiality controls, along with applicable HIPAA and HITRUST mappings.
HITRUST e1
CompliantCompliant with the HITRUST e1 framework — a foundational set of cybersecurity controls focused on essential cyber-hygiene practices.

HIPAA Security & Breach Notification Rules
In SOC 2 ReportEvaluated as part of our SOC 2 Type II — scoped specifically to the HIPAA Security Rule and Breach Notification Rule. BAAs available on request.
CCPA / US State Privacy
AlignedPrivacy-by-design architecture aligned with CCPA/CPRA and emerging US state privacy laws.
Detailed Assurance and Audit Findings
There is reasonable assurance that Growth Verticals, Inc. achieved its service commitments and met system requirements based on the SOC 2 trust services criteria, which include security, availability, and confidentiality. Additionally, HIPAA criteria were satisfied, covering both security and breach notification rules. The HITRUST e1 framework was also met during this period, demonstrating comprehensive compliance with industry standards.
Independent Audit and Controls
Compliance was confirmed through an independent audit aligned with AICPA standards. This audit evaluated and deemed the company's security, availability, and confidentiality controls to be effective, supporting the overall assurance of regulatory adherence.
How We Protect Your Data
Six principles that govern every product decision — from schema design to vendor selection.
Privacy by Design
Compliance is embedded, not retrofitted. Every data path, schema, and integration is reviewed against regulatory posture before it ships.
Privacy-Preserving Record Linkage
TrustID is our patent-pending PPRL layer. Identity resolution happens without exposing PII — data is anonymized, tokenized, and encrypted before it enters our engine.
Ethically Sourced Data
Audience and intent data is collected from publisher sites and corroborated against opt-in consumer data at the household level — with full provenance.
State-by-State Regulatory Monitoring
We retain third-party privacy counsel to track state-specific privacy laws in real time. Restricted jurisdictions get household-level activation, not individual-level.
Zero-Trust Architecture
Records are decrypted on the fly through our key management system, used in real time, and re-encrypted before activation. No long-lived PII at rest in our engine.
Customer-Controlled Keys
You hold the keys to data access and can revoke them at any time. Our identity management, householding, and matching layers are designed for buyer control, not vendor lock-in.
Privacy Policy
How we collect, use, share, and retain information across our site and applications.
Read policyData Ethics
Our principles for ethical data sourcing, governance, and state-compliant activation.
Read our principlesDPA & BAA
Data Processing Addendums and HIPAA Business Associate Agreements available on request.
Request agreementQuestions about how we handle your data?
Our privacy team responds to compliance questions, audit requests, and subprocessor inquiries directly.
