Security & Compliance
At Measured, we’re trusted by leading brands to handle sensitive marketing and performance data. We take this responsibility seriously. Our platform is built from the ground up with privacy, data security, and transparency at its core — incorporating enterprise-grade safeguards, routine audits, rigorous access controls, and industry-leading privacy standards. Whether running large-scale incrementality experiments or integrating media platforms, we ensure that every aspect of data handling is secure and compliant.
Measured meets leading security standards
ISO27001 Certified
Measured is ISO/IEC 27001:2022 certified, demonstrating our adherence to rigorous international standards for information security. This certification underscores our dedication to systematically managing sensitive information and ensuring data integrity.
SOC 2 Type 2 Compliance
Measured is SOC 2 Type 2 compliant. This attestation verifies that our systems are designed to keep customer data secure, available, and confidential over time, reflecting our commitment to ongoing operational excellence.
GDPR & CCPA Compliant
Measured adheres to the California Consumer Privacy Act (CCPA) and the European Union’s General Data Protection Regulation (GDPR), ensuring data is processed lawfully, transparently, and securely. We work closely with clients to meet their compliance requirements under these regulations.
Measured Uses Sprinto to Power Continuous Compliance
Sprinto enables automated monitoring and enforcement of security controls, helping us stay audit-ready at all times. From access management to vendor risk, we ensure ongoing adherence to frameworks such as ISO/IEC 27001 through a real-time compliance backbone, giving our clients confidence in how their data is secured.
Frequently Asked Questions
How do I report possible security vulnerabilities?
Measured encourages responsible disclosure of potential security vulnerabilities. We ask that you act in good faith to protect our customers’ data and coordinate with us to resolve any issues before publicly disclosing them. Please do not submit security vulnerabilities via public channels. Instead, report them directly to our Compliance & Security Team at security@measured.com.
How is my data protected in-transit and at rest?
All data is encrypted in transit and at rest. Data in transit is encrypted using industry standard cipher suites that promote security and performance while being protected with TLS1.2 or greater. All data at rest is encrypted using AES-256 or greater.
Does Measured support ‘Role Based Access Control’ (RBAC)?
Yes. Measured supports multiple user roles with varying levels of permissions.
Has Measured experienced a security breach in the past three years?
No. To date, Measured has not experienced a security breach.
Are customers permitted to perform security testing against Measured?
No. Measured performs extensive SCA, SAST, and third-party penetration testing regularly. As of now, we don't permit individual customer security testing against Measured services.
Does Measured offer a bug bounty program?
Measured does not currently offer a bug bounty program or financial rewards. However, we strongly encourage the responsible disclosure of potential security vulnerabilities. To maintain confidentiality and protect customer data, please refrain from reporting vulnerabilities via public forums or issue trackers. Instead, contact our Compliance & Security Team directly at security@measured.com.
Where is Measured client data stored?
Measured stores all client data within the United States. Our data infrastructure is hosted on secure, industry-leading cloud platforms that operate under U.S. jurisdiction. This ensures that data handling, access, and privacy protections comply with applicable U.S. laws and regulatory frameworks. If your organization has specific data residency or compliance requirements, our Compliance & Security Team is happy to provide further details. Please reach out at security@measured.com.
Can Measured provide security certifications and audit reports for review?
Yes. Measured provides access to key security documentation, including our ISO/IEC 27001 certification, SOC 2 Type II audit report, penetration test results, and other compliance materials as part of client or prospect security assessments. These documents are shared upon request and contingent on a signed non-disclosure agreement (NDA). To initiate the process, please contact security@measured.com.
Have a security concern or question?
If you’d like to report a security incident or request more information about Measured’s security practices, please contact our Compliance & Security Team at security@measured.com. We take every report seriously and are committed to protecting our customers’ data with transparency and care.