Home / Security
Security & Trust

Enterprise-grade security for every plan.

SOC 2 Type II, ISO 27001, GDPR, CCPA. EU data residency, SSO, encryption at rest and in transit. The same security stack used by Fortune 500 brands — available to every CustomFit customer, every plan. Our AI runs on your first-party data — never sold, never shared.

🔒

SOC 2 Type II

Annual independent audit

📜

ISO 27001

ISMS certified

🇪🇺

GDPR

Full DPA + EU data residency

🇺🇸

CCPA

Privacy rights honored

How we protect your data

Certifications

Compliance you can hand to your security team

SOC 2 Type II

Independently audited controls for security, availability & confidentiality.

ISO 27001

Certified information-security management system.

GDPR

EU data-protection aligned, with DPA & SCCs available.

CCPA

California consumer-privacy compliant.

Pen-tested

Regular third-party penetration testing; summary under NDA.

DPA & sub-processors

Signed DPA and a public sub-processor list on request.

Privacy by design

You stay in control of your data

🌍

Data residency

Choose where data is processed to meet regional requirements.

⏲️

Configurable retention

Set how long event data is kept — down to your policy.

🙈

First-party only

We don't sell or share visitor data. Ever.

🔑

SSO & RBAC

SAML SSO and role-based access on business plans.

🗑️

Right to delete

Honor data-subject deletion & export requests via API.

🔒

Encryption everywhere

TLS in transit, AES-256 at rest.

Straight answer

How does CustomFit.ai keep my data secure?

CustomFit is built to enterprise security standards: SOC 2 Type II and ISO 27001 certified, GDPR and CCPA aligned, with encryption in transit and at rest, edge processing, configurable data residency and retention, and first-party-only data use. Your visitors' data stays yours — we never sell or share it.

At a glance

SOC 2 Type II & ISO 27001 certified
GDPR & CCPA aligned, DPA available
Encryption in transit (TLS) & at rest (AES-256)
First-party data only — never sold or shared
How it works

How protection works

1

Encrypted everywhere

TLS in transit, AES-256 at rest.

2

Processed at the edge

Fast, regional, residency-aware.

3

Access controlled

SSO & role-based permissions.

4

Auditable

SOC 2 controls, logged & reviewed.

Who we support

Security for every team

🔐

Security & IT

SOC 2, ISO, DPA & sub-processor list on request.

⚖️

Legal & privacy

GDPR/CCPA tooling for access & deletion.

🏢

Enterprise buyers

Data residency, SSO & the full security pack.

The SOC 2 report and DPA made our security review painless — CustomFit cleared procurement faster than any tool we've added.
ME
Maria Edlefsen
Head of Growth · D2C brand
The complete guide

Understanding CustomFit.ai security & compliance

CustomFit.ai security is built to enterprise standards: SOC 2 Type II and ISO 27001 certified, GDPR and CCPA aligned, with encryption in transit (TLS 1.3) and at rest (AES-256), edge processing, and configurable data residency and retention.

CustomFit uses first-party data only and never sells or shares your visitors' information. Access is controlled with SSO and role-based permissions, secrets are vaulted, and every API call is audit-logged so security and compliance teams have a complete trail.

For procurement, a SOC 2 report, DPA, and sub-processor list are available on request — the documentation that typically clears enterprise security reviews quickly. Data residency options help teams meet regional requirements without compromise.

Is CustomFit.ai SOC 2 compliant?

Yes — CustomFit is SOC 2 Type II and ISO 27001 certified, and GDPR and CCPA aligned, with a SOC 2 report and DPA available on request.

Does CustomFit sell my data?

No. CustomFit uses first-party data only and never sells or shares visitor data; you control retention and residency.

How is data encrypted?

Data is encrypted in transit with TLS 1.3 and at rest with AES-256, with vaulted secrets and full audit logging.

Where is my data hosted?

On audited cloud infrastructure with regional options. We can process data in your required region to meet residency requirements — ask us for specifics for your market.

Do you sell or share visitor data?

No. CustomFit uses first-party data solely to deliver your experiences and analytics. We never sell, rent, or share visitor data with third parties.

Can I get a DPA and sub-processor list?

Yes. A signed Data Processing Agreement and our current sub-processor list are available on request, along with SCCs for international transfers.

How do you handle a deletion request?

We support data-subject access, export, and deletion through our API and dashboard so you can fulfill GDPR/CCPA requests promptly.

Do I need a developer to use CustomFit.ai?

No. Marketers build experiments and personalized experiences in a no-code visual editor; developers can use the API and SDKs when they want deeper control.

Need the full security pack?

SOC 2 report, ISO certificate, pentest summary, DPA — all available under NDA.

Built for every D2C category

🧴
Skincare
💄
Beauty
🌿
Wellness
F&B
👟
Apparel
💍
Jewelry
🛋️
Home
🍼
Baby
Live · Right now
Mamaearthfree-shipping band +12.4% AOVGIVAfestive collection page +34% revenueBellavitaPDP CTA test +27.4% CVRKapivaQuiz-driven recs +9.48% CTRThe Sleep Colanding personalized 2× capturesPlumReturning shopper swap +18.2% CVRMamaearthfree-shipping band +12.4% AOVGIVAfestive collection page +34% revenueBellavitaPDP CTA test +27.4% CVRKapivaQuiz-driven recs +9.48% CTRThe Sleep Colanding personalized 2× capturesPlumReturning shopper swap +18.2% CVR