Skip to main content
Appcues logo

Appcues

Regulatory evidence

Appcues is an AI-powered customer engagement platform that triggers in-app, email, and push experiences right when users are paying

appcues.comLast verified 21 Sep 2026

Appcues against third-party requirements

For each regulation, how many of the requirements it places on your vendors Appcues’s public evidence reaches. Open one for every item with its date and source.

Documents on the trust centre

What the vendor lists, typed; public items can be read now, the rest are available on request.

16 documents listed on Appcues’s trust centre

trust.appcues.com
  • Architecture or data-flow diagram
    • High Level Network Architecture Diagramon request · seen 21 Sep 2026
  • Business associate agreement
    • Appcues Business Associate Agreement Addendumon request · seen 21 Sep 2026
    • Appcues Business Associate Agreement Formon request · seen 21 Sep 2026
  • Cyber insurance certificate
    • 25-26 Appcues Evidence of Insuranceon request · seen 21 Sep 2026
  • Penetration test report
    • 2024 Pentest Report Finalizedon request · seen 21 Sep 2026
    • 2024 Pentest Summary of Findings (Attestation Letter)on request · seen 21 Sep 2026
    • 2025 Pentest Reporton request · seen 21 Sep 2026
    • 2025 September Pentest Summary of Findings (Attestation Letter)on request · seen 21 Sep 2026
    • 2026 Pentest Reporton request · seen 21 Sep 2026
    • 2026 September Pentest Summary of Findings (Attestation Letter)on request · seen 21 Sep 2026
  • Security questionnaire (SIG, CAIQ, HECVAT)
    • Appcues CAIQ (v4.0.2)on request · seen 21 Sep 2026
    • Appcues VSA - 2025on request · seen 21 Sep 2026
    • CAIQ-Lite - 3.1on request · seen 21 Sep 2026
  • Security policy or overview
    • Appcues Vulnerability Disclosure Policypublic · seen 21 Sep 2026
  • SOC 2 report
    • 2024 SOC 2 Type 2 Reporton request · seen 21 Sep 2026
    • 2025 Appcues, Inc. SOC2 Type 2on request · seen 21 Sep 2026

What the vendor says

Answers the vendor publishes to questions buyers ask, quoted with the link to where it says so.

  • Where data is hosted or processed

    Where are your servers located?

    Appcues hosting environments are operated by Amazon Web Services as follows: US - Oregon, USA EU - Frankfurt, Germany

    Regions named: EU, US, Germanyas of 21 Sep 2026Source

  • International data transfers

    Does Appcues do a Transfer Impact Assessment (TIA)?

    Appcues does not conduct TIAs. Any impact will depend on what data customers choose to send us. Please refer to our subprocessors page which describes how Appcues will transfer data onward.

    Regions named: USas of 21 Sep 2026Source

  • Encryption

    Do you encrypt data at rest?

    All Appcues services and data are protected with strong encryption at rest, using AWS KMS and AES-256.

    as of 21 Sep 2026Source

  • Encryption

    Do you encrypt data in transit?

    All Appcues services and data are protected with strong encryption in transit, using TLS 1.2 and above.

    as of 21 Sep 2026Source

  • Use of customer data to train models

    Does Appcues use data to train AI models?

    No. Appcues does not use customer or end-user data to train AI models. Appcues AI features, such as draft content suggestions or language translation, are based only on information that customers choose to provide. End-user data is not used for AI training or generation. Any draft AI content is optional, reviewed and approved by customers, and not automatically shown to end-users.

    as of 21 Sep 2026Source

  • Penetration testing

    Can you share details of the findings of your pen test?

    Due to confidentiality obligations with our customers, we can not share the specific details of any findings reported by a third party. If you would like to discuss specific findings, Appcues can provide written guidelines for conducting your own pen test assessment of the Appcues platform. Appcues will track and communicate the status of any reported vulnerabilities according to our vulnerability disclosure policy.

    as of 21 Sep 2026Source

  • Data retention and deletion

    What is the data retention policy?

    Since Appcues uses data for core functionality of the product, data is retained for the life of the contract with the customer. Data is deleted upon request from the customer, or in accordance with the EU’s GDPR law. Deletion requests should be sent to [email protected]

    as of 21 Sep 2026Source

  • Data retention and deletion

    What is your data retention period?

    Appcues does not have a data retention window. By default, data sent to Appcues will be retained indefinitely. This is necessary because of the nature of the Appcues product. If a user sees a flow that is configured to only display to the user once, Appcues needs to remember that the user has already seen the flow, so that we don't show the flow to that user again. If we allowed data to expire out of our platform,...

    as of 21 Sep 2026Source

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.