clay.com

Featured in our Forbes AI 50 security study: see how clay.com compares with the other 49 →
C-
Trust rating
Fair · 70/100
Procurement snapshot
0 critical findings identified — these point to architectural gaps, not just configuration tweaks.
Strengths
MX Records & Mail Provider
TLS Configuration
TLS Protocol Support
security.txt (RFC 9116)
Questions to ask
Confirm MTA-STS rollout plans for inbound email
Sign in to see 1 more
Estimated remediation effort: 2–4 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change 1 scan · Last scanned September 28, 2026
Score
100 75 50 25 0
C-
clay.com
70/100
Compliance & Certifications
Not yet verified
SOC 2 TYPE II
SOC 2 Type II
Audit report not on file
3rd party · AICPA
ISO 27001
ISO 27001
Certificate not on file
3rd party · accredited body
GDPR
GDPR
DPA not on file
Self-reported
CCPA
CCPA
Privacy policy not on file
Self-reported
Incident History
No public breaches on record
Security Posture
6 items need attention
9 passed
Finish setting up email authentication
DMARC / Email Security
2–4 hours High

Spoofed emails can still reach your customers and partners until this is fully enforced. Email authentication for clay.com is partly set up, but there are gaps: your DMARC policy is set to monitor-only, so nothing actually gets blocked yet. Until it's fully in place, someone could still send a convincing fake email pretending to be you.

NIST SP 800-177r1§4
Trustworthy Email recommends SPF, DKIM and DMARC for every email domain
How to fix this
1Change your DMARC policy from "none" to "quarantine" in your DNS settings (you're using Google Workspace — see https://knowledge.workspace.google.com/admin/security/set-up-dkim) — this moves suspicious mail to spam instead of just watching it happen. Your current record with just that change:
v=DMARC1; p=quarantine; rua=mailto:[email protected]; ruf=mailto:[email protected]
2Double-check it's live: search "dmarc record checker" and enter clay.com.
Report unlocked.
View all 9 passed checks
MX Records & Mail Provider
TLS Configuration
TLS Protocol Support
security.txt (RFC 9116)
Known Breaches
Subprocessors & Tech Stack
Cookie Security
CVE Exposure
Certificate Hygiene
Couldn't check: Malware / Phishing Blocklist — the check didn't complete (the site blocked or timed out our scanner, or a data source was unavailable), so this isn't counted in the score.
Company Signals
Operational risk
Last funding
Employees
Trust Resources
Claim profile →
Trust Center
Not detected
Security contact (security.txt)
clay.com/.well-known/security.txt
Privacy Policy
DPA (Data Processing Agreement)
Subprocessors List
Similar companies
Appears in
Vendors graded C
697 companies · LynxRadar ranking