Compliance frameworks, security audits, and quality certifications this company maintains.
Reddit maintains SOC 2 Type II certification covering its advertising platform and data API infrastructure, providing advertisers and data partners with independent assurance that Reddit's security controls protect sensitive campaign and user data.
Reddit's information security management system for its core platform infrastructure is certified to ISO 27001, demonstrating systematic risk management for the systems that store and process content from over 100,000 active communities.
Reddit complies with the EU General Data Protection Regulation by providing EU users with data access, deletion, and portability rights, and by processing European user data through Reddit's Ireland-based legal entity under standard contractual clauses.
Reddit complies with the California Consumer Privacy Act, offering California residents the right to know, delete, and opt-out of the sale of their personal data, with dedicated privacy controls accessible through Reddit's account settings.
Reddit complies with the Children's Online Privacy Protection Act by requiring users to be at least 13 years of age to create an account and restricting data collection and ad targeting for users identified as minors.
Reddit's web and mobile applications target WCAG 2.1 Level AA conformance to ensure that users with visual, auditory, and motor disabilities can browse, post, and engage with Reddit communities using assistive technologies.
Reddit's payment processing flows for Reddit Premium subscriptions and Reddit Coins purchases comply with PCI DSS standards, ensuring cardholder data is handled securely and never stored on Reddit's own servers.
Reddit operates a DMCA-compliant content takedown process allowing copyright holders to report infringing content across subreddits, with a designated DMCA agent registered with the US Copyright Office.
Accessibility
VPAT / Section 508
In ProgressReddit is actively working toward full Section 508 compliance for its web platform to ensure federal agency employees and government users can access Reddit's platform and advertising tools without accessibility barriers.
Reddit aligns its cybersecurity program with the NIST Cybersecurity Framework, applying identify, protect, detect, respond, and recover controls across its platform infrastructure to manage risk from security threats at scale.