Segment logo

Segment

Customer data platform (CDP) for collecting, unifying, and routing customer event data; a Twilio company.

✓ 10 of 32 frameworks
Security & General Standards
SOC 2 Type II

SOC 2 listed with report on Segment Trust Center (security.segment.com)

SOC 3
?

Not documented on public trust center

SOC 1 Type II
?

Not documented on public trust center

ISO 27001 (Information Security Management)

ISO/IEC 27001 certified (Schellman) with SoA on Segment Trust Center

ISO 27017 (Cloud Security)

ISO/IEC 27017:2015 listed on Segment Trust Center

ISO 27018 (Cloud Privacy)

ISO/IEC 27018:2019 listed on Segment Trust Center

ISO 27701 (Privacy Information Management)
?

Not documented on public trust center

ISO 42001 (AI Management Systems)
?

Not documented on public trust center

ISO 9001 (Quality Management)
?

Not documented on public trust center

CSA STAR (Cloud Security Alliance)
?

Not documented on public trust center

HITRUST CSF
?

Not documented on public trust center

BSI C5 (German Cloud Security)
?

Not documented on public trust center

Privacy & Data Transfer
GDPR (EU)

GDPR listed on Segment Trust Center with DPA available

CCPA / CPRA (California)

CCPA listed on Segment Trust Center

UK GDPR

Not explicitly documented

LGPD (Brazil)
?

Not documented on public trust center

PIPEDA (Canada)
?

Not documented on public trust center

DPDP Act (India)
?

Not documented on public trust center

PIPL (China)
?

Not documented on public trust center

EU-US Data Privacy Framework

Twilio (Segment's parent) self-certifies under EU-US Data Privacy Framework

Swiss-US Data Privacy Framework

Twilio self-certification covers Swiss-US Data Privacy Framework

Global CBPR (APEC)
?

Not documented on public trust center

Global PRP (APEC)
?

Not documented on public trust center

Industry & Government
HIPAA (US Healthcare)

HIPAA listed on Segment Trust Center

PCI DSS (Payment Card Industry)
?

Twilio-wide PCI DSS Level 1 exists but not explicitly documented for Segment product

FedRAMP (US Federal)

Not listed on FedRAMP Marketplace

StateRAMP / TX-RAMP (US State)
?

Not documented on public trust center

DORA (EU Finance)
?

Not documented on public trust center

CJIS (US Law Enforcement)
?

Not documented on public trust center

FINRA (US Broker-Dealers)
?

Not documented on public trust center

IRAP (Australian Government)
?

Not documented on public trust center

Emerging & Strategic
NIST CSF (Cybersecurity Framework)
?

Not documented on public trust center

Data last verified: September 2026

Is this data outdated?

Spotted an error or a recent change in Segment's posture? Submit a correction.

Submit a correction →

Work at Segment?

Claim this profile to verify and enrich your compliance data.

Claim this profile →

Compare Segment with:

← All Data & Analytics tools

Data sourced from public trust centers. Not legal or compliance advice.

Logos and trademarks are property of their respective owners. Use does not imply endorsement, affiliation, or sponsorship.

© Compliance Posture 2026