{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"polytomic","name":"Polytomic","domain":"polytomic.com","category":"Data platforms","one_liner":"No-code data syncing between your systems","trust_center_url":"https://trust.polytomic.com/","security_page_url":null,"url":"https://certreports.com/vendors/polytomic/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/polytomic/soc-2","evidence":[{"source_type":"trust_center","source_name":"Polytomic trust centre (Vanta)","url":"https://trust.polytomic.com/","fetched_at":"2026-09-18 23:24:47.442919+00","content_hash":"4c91572af2a0dd2a8caa9935cd8547e37db66462c5232ca2d60dfc33ae638aca","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/polytomic/gdpr","evidence":[{"source_type":"trust_center","source_name":"Polytomic trust centre (Vanta)","url":"https://trust.polytomic.com/","fetched_at":"2026-09-18 23:24:47.442919+00","content_hash":"4c91572af2a0dd2a8caa9935cd8547e37db66462c5232ca2d60dfc33ae638aca","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/polytomic/security","evidence":[{"source_type":"trust_center","source_name":"Polytomic trust centre (Vanta)","url":"https://trust.polytomic.com/","fetched_at":"2026-09-18 23:24:47.442919+00","content_hash":"4c91572af2a0dd2a8caa9935cd8547e37db66462c5232ca2d60dfc33ae638aca","wayback_url":null,"quote":"CCPA","confidence":1}]}],"brief":null,"legal_docs":[{"kind":"privacy","url":"https://www.polytomic.com/privacy-policy","availability":"public","detail":null,"as_of":"2026-09-18"},{"kind":"subprocessors","url":"https://trust.polytomic.com/","availability":"public","detail":"10 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Amazon Web Services","domain":"amazon.com","purpose":"Cloud provider","location":null,"vendor_url":"https://certreports.com/vendors/amazon/security"},{"name":"Chargebee","domain":"chargebee.com","purpose":"Billing software","location":null,"vendor_url":"https://certreports.com/vendors/chargebee/security"},{"name":"Datadog","domain":"datadoghq.com","purpose":"Infrastructure monitoring","location":null,"vendor_url":"https://certreports.com/vendors/datadog/security"},{"name":"Front","domain":"frontapp.com","purpose":"Email client","location":null,"vendor_url":null},{"name":"Google Workspace","domain":"google.com","purpose":"Collaboration","location":null,"vendor_url":null},{"name":"HubSpot","domain":"hubspot.com","purpose":"Sales CRM","location":null,"vendor_url":"https://certreports.com/vendors/hubspot/security"},{"name":"RevOps.io","domain":"revops.io","purpose":"Sales contracts","location":null,"vendor_url":null},{"name":"Sentry","domain":"sentry.io","purpose":"Application bug alerts","location":null,"vendor_url":null},{"name":"Stripe","domain":"stripe.com","purpose":"Billing software","location":null,"vendor_url":"https://certreports.com/vendors/stripe/security"},{"name":"WorkOS","domain":"workos.com","purpose":"SSO APIs","location":null,"vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T11:56:43.267Z"}