Q39
Are you PCI DSS compliant? At what level?
PCI DSS compliance claim found on trust page (Vendor attested)
ThirdProof independently checks public intelligence sources to show what your team can verify about SendGrid before SendGrid sends a questionnaire or a security document.
SendGrid's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from SendGrid — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on SendGrid's own trust page.
⚠ SendGrid was not found in the FedRAMP Marketplace. Checked August 2026.
This matters if you place federal workloads with this vendor: agencies may only use cloud services holding a FedRAMP certification. It carries no weight for a purely commercial deployment.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 25 returning usable evidence. The SendGrid assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest SendGrid Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 58% of a 133-question vendor security questionnaire — without waiting for SendGrid. The remaining 56 are listed as open, so the follow-up you send is short and specific.
Q39
PCI DSS compliance claim found on trust page (Vendor attested)
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
SendGrid is GDPR compliant and provides a Data Processing Addendum (DPA) available at craemer.com and Twilio's resource center for processing personal data under GDPR.
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q23
SendGrid encrypts data at rest using AES-256 bit encryption and enforces TLS encryption for data in transit.
+ 72 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing SendGrid for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for SendGrid
SendGrid is a mature, well-established email delivery and marketing platform owned by Twilio, serving a global customer base with multi-region infrastructure and a 99.99% uptime SLA.
The vendor demonstrates strong foundational security practices, including AES-256 encryption at rest, TLS 1.3 in transit, valid SAML 2.0 SSO, and a 24/7 incident response capability. However, the assessment identifies three material areas requiring attention: (1) unverified certification claims—SOC 2, ISO 27001, PCI DSS, and HIPAA are vendor-attested but lack independent registry confirmation; (2) AI data practices that favor vendor interests—customer data may be used for AI model training by default unless customers actively opt out, with indefinite retention for AI processing; and (3) HTTP security header gaps—the marketing site received a D- grade (25/100) from HTTP security scanner, indicating missing or misconfigured security headers despite valid TLS and HSTS configuration.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence was independently sourced from external registries, public threat intelligence platforms, domain registries, and automated security scans conducted without vendor participation.
4 findings identified for SendGrid
Historical news archives reference SendGrid account compromise in OpenAI invoice scams and alleged breach claims, but these articles are aged (511+ days) and severity has been downgraded accordingly. The 'alleged massive SendGrid breach' was repudiated by the vendor, and phishing/account takeover incidents reflect attacker exploitation of customer credentials rather than platform vulnerabilities. …
[SendGrid's privacy policy](https://www.twilio.com/en-us/legal/privacy) indicates that customer data may be used for AI model training unless customers actively opt out. This is a material data practice difference from vendors that commit to zero training by default. …
SendGrid's [privacy policy](https://www.twilio.com/en-us/legal/privacy) permits indefinite retention of customer data for AI processing purposes, separate from the standard 30–60 day deletion window for transactional content. This means data retained for AI purposes may persist beyond normal data lifecycle expectations, increasing exposure over time.
A subprocessor page (https://sendgrid.com/subprocessors) was discovered but automated parsing could not extract individual subprocessor entries. The page may use dynamic JavaScript rendering, embedded formats, or proprietary markup that prevents automated extraction. …
Showing the 4 most severe of 5 findings.
Evidence that positively supports SendGrid's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No Sanctions Matches Found
Sanctions & Watchlist Screening →No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Clean IP Reputation
IP Reputation →SendGrid complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Represent SendGrid? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The SendGrid assessment above is already written; ask for it and it lands in your inbox.