Provision record
Segment · Segment Privacy Policy · View original document ↗

Security governed by ISO 27001 and NIST standards

Medium severity Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Segment and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
ⓘ

This analysis describes what Segment's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

Recent Activity

This document changed recently

Medium May 22, 2026

The updated policy establishes a new opt-out mechanism allowing users to decline having their data disclosed to third parties (other than service providers) or used for purposes materially different from the original collection purpose. The policy also explicitly discloses that Twilio Inc. is subject to FTC investigatory and enforcement powers, providing users with notice of the regulatory authority overseeing the company's privacy practices. You can exercise this opt-out right by contacting Segment through the mechanism specified in their privacy policy.

View change record →
Medium May 19, 2026

The updated terms establish clearer disclosure of how Segment transfers personal data internationally. Segment now explicitly certifies its compliance with the EU-U.S. Data Privacy Framework, UK Extension, and Swiss-U.S. Data Privacy Framework, and states that these DPF Principles take precedence if they conflict with other policy terms. The updated policy also adds specific rights allowing you to opt out of: (i) disclosure of your personal data to third parties other than service providers acting under Segment's instructions, or (ii) use of your personal data for purposes materially different from the original purpose or your subsequent authorization. You can exercise these rights by contacting privacy@twilio.com.

View change record →

How other platforms handle this

OpenAI Medium

We implement commercially reasonable technical, administrative, and organizational measures designed to protect Personal Data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction.

Google Medium

Investing in industry-leading approaches to advance safety and security research and benchmarks, pioneering technical solutions to address risks, and sharing our learnings with the ecosystem.

Amazon Marketplace Medium

We maintain physical, electronic, and procedural safeguards in connection with the collection, storage, and disclosure of customer personal information.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
All systems are governed by policies built on industry best practices, including ISO 27001 and NIST standards.

Excerpt from Segment's Privacy Policy

Provision details

Document information
Document
Segment Privacy Policy
Entity
Segment
Date stated by the document
April 9, 2026
As printed in Segment’s text (version CA-V-004456), not a ConductAtlas date.
Tracking information
First captured by ConductAtlas
May 5, 2026
Text quoted from version
CA-V-004456, captured July 3, 2026
Record ID
CA-P-055102
Document ID
CA-D-000700
Evidence Provenance
Source URL
Wayback Machine
Extracted-text SHA-256 (version CA-V-004456)
9419eb7dec5f3301f5da5b1a8bbe0860ef439551d3cacb024c22402db293b1fe
Analysis generated
July 9, 2026 09:48 UTC
Methodology
Evidence
✓ Excerpt found verbatim in version CA-V-004456 (checked Oct. 5, 2026)
Citation Record
Entity: Segment
Document: Segment Privacy Policy
Record ID: CA-P-055102
Version: CA-V-004456
Captured: 2026-07-03 01:14:50 UTC
SHA-256: 9419eb7dec5f3301…
URL: https://conductatlas.com/platform/segment/segment-privacy-policy/provision/CA-P-055102/security-governed-by-iso-27001-and-nist-standards/
Accessed: Oct. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Segment's Security governed by ISO 27001 and NIST standards clause do?

The clause states: “All systems are governed by policies built on industry best practices, including ISO 27001 and NIST standards.”

Is ConductAtlas affiliated with Segment?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Segment.