Secure and private by default

We take the responsibility of helping you manage your customer data seriously. That’s why security and privacy are key focus areas for our organization and product development.

hero
spot-internal-security

Internal Security

Data encryption
Your data is encrypted at rest and protected by TLS in transit. Your Segment password is hashed using bcrypt, and we manage our production secrets with AWS tools.

Rigorous product design
Our projects pass thorough security-design reviews, threat models, and regular pen tests using trusted security vendors. We also employ a private bug bounty for continuous assessment.

Company training
All employees are required to complete security and privacy training. In addition, engineers must complete specialized security training.

Product Security

Manage access to your account
Centrally manage your policies for access with Single Sign-On (SSO) on the Business plan.

Control visibility with user access levels
Control access to your Sources and Workspaces with fine-grained permissions to manage how your users interact with your data.

product

Segment's commitment to data privacy

As a data processor, adhering to local regulations is only one component of our commitment to privacy. Our higher order mission is to treat you and your customers with the respect you deserve.

Data Processing Agreement

Our Data Processing Agreement (DPA) reflects the requirements of the GDPR.

Data Transfer Practices

We are certified under the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks for user data transfer and storage.

Privacy by Design

Your data is yours to own. Segment never shares or sells your user data.

Privacy Policy

Our Privacy Policy honors the GDPR, EU-U.S. and Swiss-U.S. Privacy Shield Frameworks.

Data Protection Officer

Segment has appointed a Data Protection Officer to oversee our ongoing compliance efforts.

Certifications

Segment’s privacy and security framework are based on and aligned with the ISO 27000 series. We are ISO/IEC 27001:2013 certified, and we meet the requirements of ISO 27017 and ISO 27018.

ColeenCoolidge A

Any experienced security practitioner can tell you that technology and processes are just two key components of an effective security program. People are the third component. At Segment, security is everyone’s responsibility.

Read more

Coleen Coolidge

Head of Security

Segment horizontal 2C RGB