{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"courier","name":"Courier","domain":"courier.com","category":"Developer tools","one_liner":"The fastest way for developers to build notifications for their app.","trust_center_url":"https://security.courier.com/","security_page_url":null,"url":"https://certreports.com/vendors/courier/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"hipaa","framework_name":"HIPAA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states that it will sign a business associate agreement on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/courier/hipaa","evidence":[{"source_type":"trust_center","source_name":"Courier trust centre (Drata)","url":"https://security.courier.com/","fetched_at":"2026-09-18 22:50:15.417521+00","content_hash":"08722b56a88fa094d0984cc1e6825d89aaca472b3e0bd5f7299039df1f0a3526","wayback_url":null,"quote":"HIPAA","confidence":1}]},{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/courier/soc-2","evidence":[{"source_type":"trust_center","source_name":"Courier trust centre (Drata)","url":"https://security.courier.com/","fetched_at":"2026-09-18 22:50:15.417521+00","content_hash":"08722b56a88fa094d0984cc1e6825d89aaca472b3e0bd5f7299039df1f0a3526","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/courier/gdpr","evidence":[{"source_type":"trust_center","source_name":"Courier trust centre (Drata)","url":"https://security.courier.com/","fetched_at":"2026-09-18 22:50:15.417521+00","content_hash":"08722b56a88fa094d0984cc1e6825d89aaca472b3e0bd5f7299039df1f0a3526","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/courier/pci-dss","evidence":[{"source_type":"trust_center","source_name":"Courier trust centre (Drata)","url":"https://security.courier.com/","fetched_at":"2026-09-18 22:50:15.417521+00","content_hash":"08722b56a88fa094d0984cc1e6825d89aaca472b3e0bd5f7299039df1f0a3526","wayback_url":null,"quote":"PCI DSS","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: EU-US Certification","issued_at":"2025-12-10","expires_at":"2026-12-10","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/courier/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/9918","fetched_at":"2026-09-17 15:51:22.610064+00","content_hash":"312de8e126f7a50018e7583b1f21d31a47cea3849c80fe6be34300eb35bef5c4","wayback_url":null,"quote":"Courier: Active: EU-US Certification","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/courier/security","evidence":[{"source_type":"trust_center","source_name":"Courier trust centre (Drata)","url":"https://security.courier.com/","fetched_at":"2026-09-18 22:50:15.417521+00","content_hash":"08722b56a88fa094d0984cc1e6825d89aaca472b3e0bd5f7299039df1f0a3526","wayback_url":null,"quote":"CCPA","confidence":1}]}],"brief":null,"legal_docs":[],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T12:38:02.682Z"}