Mailchimp security review: SOC 2, AI training & subprocessors

What Mailchimp publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.

Transparency score
90/100
SOC 2
Not mentioned
ISO 27001
Not mentioned
Trains AI on your data?
See quote
Subprocessors
25 listed

"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.

Does Mailchimp train AI on your data?

Has a statement about using data to train or improve AI

Mailchimp's own words (mailchimp.com/legal/terms):

We may use your Inputs and Outputs, including Customer Data, for machine learning purposes in order to develop and improve the AI Model, the Services, and similar products and features, and you instruct us to process Customer Data for such purposes.

Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.

Certifications Mailchimp claims

Certification or reportMentioned on
HIPAAmailchimp.com/legal/terms

Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA, EU-U.S. Data Privacy Framework. These are laws the vendor says it follows, not certifications.

A certification on a website is a claim. For anything sensitive, ask Mailchimp for the SOC 2 report or ISO certificate.

Mailchimp subprocessors

Mailchimp lists 25 subprocessors on mailchimp.com/legal/subprocessors:

Security features mentioned

SSO / SAMLNot found
SCIM provisioningNot found
Multi-factor authenticationMentioned
Encryption at restNot found
Encryption in transitNot found
Penetration testingNot found
Bug bounty / disclosure programNot found
Audit logsNot found
Data residencyMentioned EU
security.txt contacthttps://mailchimp.com/about/security/#Responsible_Disclosure

Key documents

Trust / security centermailchimp.com/gdpr
Privacy policyNot found
Subprocessor listmailchimp.com/legal/subprocessors
Data processing agreement (DPA)mailchimp.com/legal/data-processing-addendum
AI policyNot found
Termsmailchimp.com/legal/terms
Status pagestatus.mailchimp.com

How this score is worked out

CheckPointsResult
Security or trust page15Yes
Certifications listed20Yes
Privacy policy10No
Subprocessor list15Yes
DPA available10Yes
AI training policy stated15Yes
security.txt contact5Yes
Status page10Yes

The score measures how much of a standard security review our reader could answer from Mailchimp's public pages. It is not a rating of how secure Mailchimp is, and a "No" can mean the document exists where our reader couldn't see it.

Check another vendor

Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.

Other Communication vendors

Aircall · Braze · Customer.io · Dialpad · Discord · Front · Gong · Klaviyo · Postmark · RingCentral · SendGrid · Slack

Source: Mailchimp's own public website (5 pages read on October 10, 2026). Stormap is not affiliated with Mailchimp. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.