Infrastructure to get any data, run agentic workflows, and launch GTM plays.
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
-
CCPA
Publicly advertised on the organization’s trust center.
-
ISO 27001
International standard for an information security management system, certified by accredited bodies.
-
ISO 42001
International standard for AI management systems. Adoption is early; advertising it is a notable signal.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Clay discloses on its trust center. Linked entries have their own profile in the Trust Index.
76% chain trust: 26 of 34 disclosed subprocessors are themselves in the Trust Index.
- Amazon Web Services Cloud provider
- Amplitude Data analytics
- Anthropic LLM provider/hosting
- Braintrust LLM Operations
- Datadog APM and security
- Segment Data analytics
- Snowflake Data analytics
- ClickHouse Database
- Browserbase LLM Operations
- Cohere LLM operations
- Cube Dev Data analytics
- Fireworks LLM provider/hosting
- Fivetran Data ETL
- Google Gemini LLM provider/hosting
- Grafana Logging and metrics
- Intercom Customer support
- Langsmith LLM logging and tracing
- Mezmo Logging and metrics
- Mistral LLM provider/hosting
- OpenAI LLM provider/hosting
- Planetscale
- Parallel Web Systems LLM operations
- Postmark Email service provider
- Raindrop.ai LLM operations
- Sentry Error logging
- SerpApi LLM operations
- Serper LLM operations
- Smartlead Email sequencer
- Slack Customer Support
- Turbopuffer Vector Database
- Verisoul Fraud Detection
- WorkOS Authentication support
- Zapier Data imports
- Zenrows LLM operations
Named as a subprocessor by
Organizations in the Trust Index that disclose Clay as a subprocessor.
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.