Compliance frameworks, security audits, and quality certifications this company maintains.
Mixpanel maintains SOC 2 Type II certification covering the security, availability, and confidentiality of its product analytics platform, providing enterprise customers with independent audit validation that behavioral event data and user behavioral records are protected by rigorous security controls.
Mixpanel holds ISO 27001 certification for its information security management systems, offering internationally recognized assurance of security governance practices that protect the product analytics data of 9,000+ enterprise and growth-stage customers.
Mixpanel is compliant with the EU General Data Protection Regulation, providing EU data residency options, signed data processing agreements, and user suppression APIs that enable Mixpanel customers to fulfill GDPR data subject rights requests for behavioral event data collected from EU residents.
Mixpanel supports California Consumer Privacy Act compliance for its customers by providing opt-out APIs and data deletion workflows that allow product teams to honor CCPA data subject requests for California users whose behavioral event data is tracked in Mixpanel.
Mixpanel offers HIPAA-eligible configurations for healthcare and digital health customers that need product analytics without exposing protected health information, including BAA execution and configuration guidance for avoiding PHI capture in Mixpanel event properties.
Mixpanel supports PCI DSS compliance for e-commerce and fintech customers through configuration guidance that prevents payment card data fields from being captured in Mixpanel event properties, ensuring Mixpanel does not become part of the cardholder data environment.
Mixpanel participates in the EU-US Data Privacy Framework, providing a legal mechanism for the cross-border transfer of EU user behavioral event data to Mixpanel US infrastructure in compliance with GDPR cross-border data transfer requirements.
Mixpanel has completed CSA STAR Level 1 self-assessment, publishing its cloud security controls documentation through the CSA registry to give enterprise procurement teams transparent visibility into the Mixpanel security posture during vendor evaluation.
Mixpanel is committed to WCAG 2.1 AA accessibility standards for the Mixpanel Analytics platform, ensuring that product managers and data analysts with disabilities can access funnels, cohort builders, and dashboard charts using screen readers and keyboard navigation.
Mixpanel is certified under ISO 27017, the cloud-specific security controls standard, ensuring that additional safeguards appropriate for a multi-tenant SaaS analytics platform are implemented to protect the behavioral event data of thousands of paying customers.