Compliance frameworks, security audits, and quality certifications this company maintains.
Braze undergoes annual SOC 2 Type II audits covering security, availability, and confidentiality trust service criteria, providing enterprise customers assurance that Braze messaging infrastructure and customer data handling meet rigorous independent security standards.
Braze maintains ISO 27001 certification for its information security management system, demonstrating to global enterprise customers that Braze customer data and messaging infrastructure are managed according to internationally recognized security controls.
Braze is designed as a GDPR-compliant data processor, offering EU data residency options, standard contractual clauses, data subject request APIs, and privacy controls that allow brands to meet their GDPR obligations when using Braze for customer messaging in Europe.
Braze supports CCPA compliance for US-based brands, providing opt-out of sale controls, data deletion APIs, and data portability capabilities so that customers using Braze for consumer messaging can fulfill California privacy rights requests.
Braze offers HIPAA-eligible configuration for healthcare and digital health customers, enabling compliant patient engagement messaging via push notifications and email under a signed Business Associate Agreement with appropriate PHI handling controls.
Braze is PCI DSS compliant for the handling of payment-adjacent messaging workflows, ensuring that Braze infrastructure used by fintech and retail customers for transactional notifications meets payment card industry data security requirements.
Braze participates in the APEC Cross-Border Privacy Rules framework, enabling lawful cross-border data transfers for brands using Braze to engage customers across Asia-Pacific markets including Australia, Japan, and Singapore.
Braze dashboard and SDK documentation meet WCAG 2.1 AA accessibility standards, ensuring that marketing teams using the Braze platform can operate it effectively regardless of disability, supporting inclusive workplace tooling for enterprise customers.
Braze holds ISO 27701 certification extending its ISO 27001 ISMS to include a Privacy Information Management System, providing global enterprise customers with independent verification of Braze privacy program maturity beyond GDPR compliance alone.
Braze is pursuing FedRAMP authorization to expand its customer engagement platform to US federal government agencies and government contractors, enabling compliant cloud-based messaging for public sector digital transformation initiatives.