Twilio
Security and trust center evidence
Summary
Twilio has 2 registry-verified rows and 7 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, Twilio states on its trust centre that it holds SOC 2, though no independent report details are provided in this evidence. As of 17 Sep 2026, Twilio is listed in the Visa Global Registry as PCI DSS validated through 31 Dec 2026, with the audit performed by Coalfire Systems, Inc. As of 17 Sep 2026, Twilio is listed in the EU-US Data Privacy Framework registry with active SW-US, EU-US, and UK Extension certifications valid through 20 Apr 2027. As of 17 Sep 2026, Twilio displays a HIPAA badge on its trust centre, described as a claim with BAA availability not yet captured, so a BAA offering cannot be confirmed from this evidence. As of 17 Sep 2026, Twilio states on its trust centre that it holds ISO/IEC 27001, ISO/IEC 27017:2015, ISO/IEC 27018:2019, GDPR, and CCPA/CPRA compliance, and no public evidence found beyond these vendor statements for those frameworks.
- PCI DSS: listed in Visa Global Registry as validated through 31 Dec 2026 (auditor: Coalfire Systems, Inc), as of 17 Sep 2026.
- EU-US Data Privacy Framework: listed in DPF registry with active EU-US, SW-US, and UK Extension certifications through 20 Apr 2027, as of 17 Sep 2026.
- HIPAA: vendor displays a HIPAA badge on its trust centre as of 17 Sep 2026, but this is a claim with BAA availability not yet captured; SOC 2, GDPR, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, and CCPA/CPRA are also vendor-stated on its trust centre as of the same date, with no independent verification in this evidence.
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among communications and cpaas vendors
2verified rows
Category median 1, across 49 indexed communications and cpaas vendors. Twilio has more verified rows than 100 percent of them.
apicustomer-engagementemailsmsvoice
Compare with similar vendors
Pick your own comparisonCompliance grid
- HIPAAVendor-stated
Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)
as of 17 Sep 20261 source
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 17 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 17 Sep 20261 source
PCI DSSVerifiedListed on the Visa Global Registry as PCI DSS validated through 2026-12-31
as of 17 Sep 20261 source · Coalfire Systems, Inc
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27017Vendor-statedVendor states ISO/IEC 27017:2015 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27018Vendor-statedVendor states ISO/IEC 27018:2019 on its trust centre
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkVerifiedActive: SW-US Certification, EU-US Certification, UK Extension Certification
as of 17 Sep 20261 source- CCPA / CPRAVendor-stated
Vendor states CCPA on its trust centre
as of 17 Sep 20261 source
No public evidence yet for FedRAMP, CSA STAR, Cyber Essentials, ISO 27701, ISO 42001. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Legal artefacts
Subprocessors (11)
- APAccount Phishing Incident Incidents Twilio
- CPCVE Publication Twilio
- DTDoes Twilio
- DADoing As part of Twilio
- NVNotification Vulnerabilities The Twilio
- RTReview Twilio
- SUSendGrid Update - April 3 General Twilio
- TIThere is no evidence of a breach of Twilio
- TOTwilio or Twilio
- VMView more Infrastructure Amazon Web Services
- WIWhat is Twilio
Change history
- 17 Sep 2026CCPA / CPRA evidence addedA CCPA / CPRA row entered the index with state Vendor-stated.
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 17 Sep 2026HIPAA evidence addedA HIPAA row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27017 evidence addedA ISO/IEC 27017 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27018 evidence addedA ISO/IEC 27018 row entered the index with state Vendor-stated.
- 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
- 17 Sep 2026Subprocessor added: Account Phishing Incident Incidents TwilioAccount Phishing Incident Incidents Twilio appeared on the subprocessor list.
- 17 Sep 2026Subprocessor added: CVE Publication TwilioCVE Publication Twilio appeared on the subprocessor list.
- 17 Sep 2026Subprocessor added: Does TwilioDoes Twilio appeared on the subprocessor list.
Similar vendors with evidence
Related by product tags and the Communications and CPaaS category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.
Bird
Communications and CPaaS
The world’s largest omnichannel communications platform
Plivo
Communications and CPaaS
Voice AI Agents for customer engagement, including WhatsApp, SMS &…
OneSignal
Communications and CPaaS
Engage customers through personalized omni-channel messaging
Dotgo
Communications and CPaaS