Simplify tracking and compliance with HIPAA, SOC 2, and GDPR. Automate expiration reminders and centralize management. Start your free trial today!
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
HIPAA
Public claim of compliance with US health-data privacy and security rules. HIPAA has no certification; compliance is self-attested.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
Compliance timeline
-
March 2024
Trust center first observed in public web archives
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Expirationreminder discloses on its trust center. Linked entries have their own profile in the Trust Index.
45% chain trust: 9 of 20 disclosed subprocessors are themselves in the Trust Index.
- HubSpot Marketing
- Intuit Finance and payments
- Microsoft Azure Cloud provider
- ClickUp Collaboration
- FeatureBase Customer feedback management
- GitHub Version control
- Google Analytics
- Hookdeck Webhook management
- Humi Employee management
- Loom Collaboration
- PandaDoc Document management
- PostHog Analytics
- SendGrid Marketing
- Sentry Cloud monitoring
- Stripe Finance and payments
- Office 365 Email Processing
- Zoom Collaboration
- DNSimple DNS and hosting management
- Twilio Sending text messages
- Webflow Website hosting
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.