99.2%
Junk submissions blocked
Measured across 1.4M synthetic submissions during the HackerOne Q3 2023 engagement, including credential-stuffing patterns, headless-browser farms, and AI-generated form fills.
Security & Compliance
ContactYou ships lead-capture infrastructure for B2B revenue teams that answer to a CISO before they answer to a marketer. Every deployment inherits the same audited controls, the same encryption posture, and the same regional isolation — no add-on, no enterprise tier, no fine print.
Section 01 — Certifications
Mapped to the standard vendor-security questionnaire, with the certifying body, scope, and effective date a procurement reviewer needs to close the ticket.
Continuous auditing across Security, Availability, and Confidentiality trust-service criteria. The full report is available under NDA through the evidence pack below.
Lawful basis documented per capture flow, sub-processor list published, breach-notification runbook rehearsed quarterly. EU customer data stays in Frankfurt by default.
Verifiable consumer requests for access, deletion, and opt-out are honored across every customer workspace. Identity verification documented in the DPA addendum.
A third-party penetration test verified that the built-in spam and bot-suppression layer blocks 99.2% of junk submissions before they reach a CRM. Re-audited annually.
Section 02 — Infrastructure
ContactYou runs on isolated VPC tenants inside AWS eu-central-1 (Frankfurt) for EU customers and AWS us-east-1 (Northern Virginia) for US customers. Conversations never cross regions — a lead captured in Berlin is routed, qualified, and stored entirely inside Frankfurt, and the same applies to US-bound traffic in Virginia.
Section 03 — Bot suppression
The 99.2% figure is not a benchmark, a self-report, or a marketing estimate. It is the measured block-rate from an independent penetration test conducted by HackerOne in Q3 2023 against the production capture layer.
99.2%
Measured across 1.4M synthetic submissions during the HackerOne Q3 2023 engagement, including credential-stuffing patterns, headless-browser farms, and AI-generated form fills.
312%
ContactYou processed 184 million lead conversations in 2024 — a 312% year-over-year increase that the suppression layer absorbed without measurable false-positive drift.
<0.4%
Independent re-audit confirmed a false-positive rate below 0.4% on legitimate B2B inbound traffic — verified across 8,400+ active deployments in the G2 Spring 2024 cohort.
Methodology, sample scripts, and the auditor's letter are included in the evidence pack.
Editor's note — from engineering
“Secure by default” is a phrase every vendor uses. Inside ContactYou it means a new engineer cannot ship a capture flow that stores lead text unencrypted, ships PII to a third-party webhook, or skips the spam layer — the platform refuses to compile that path. The bot-suppression score, the Frankfurt residency, the SOC 2 controls: they are consequences of that one constraint, not a separate checklist someone runs once a year.”
For security & procurement reviewers
The evidence pack bundles the SOC 2 Type II report (NDA), the Data Processing Addendum, the penetration-test summary from HackerOne, the sub-processor list, and the regional architecture diagram — delivered as a single download after a short verification step.
Or email [email protected] · response within one business day · Austin, TX.