Clay AI Vendor Risk Profile
GTM (go-to-market) data enrichment and AI automation platform. Combines 100+ data providers with LLM-powered research and outreach to build targeted prospect lists and personalized outbound at scale.
Risk overview
Risk score: 38/100
Risk tier: Moderate
Safety rating: 62/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: Sep 1, 2025 Stale — re-verification queued
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 28/100 |
| IP Exposure | 40/100 |
| Jurisdiction | 13/100 |
| Security | 40/100 |
| Regulatory Compliance | 60/100 |
| Transparency | 80/100 |
| Business Stability | 35/100 |
| Dependency Chain | 32/100 |
| Agent Governance | Not assessed |
Analyst summary
Rating: Acceptable
Clay is a fast-growing GTM / sales enrichment platform (Series C, $100M at $3.1B led by Alphabet's CapitalG in 2025) with a respectable enterprise compliance posture: SOC 2 Type II, ISO 27001, GDPR DPA, CCPA. Customer data is processed in AWS US-East and is contractually excluded from training by upstream LLM providers (OpenAI, Anthropic, Google).
Bottom line: Solid for US-anchored GTM teams; verify the data-broker chain and US-only residency against your policy.
Strengths
- SOC 2 Type II and ISO 27001 active certifications; GDPR DPA available
- Contractual no-training agreements with OpenAI, Anthropic, Google, and other LLM providers
- Public subprocessor list at trust.clay.com/subprocessors
- CapitalG-led Series C ($100M at $3.1B, 2025) provides strong financial runway
Concerns
- Data residency limited to AWS US-East — no EU region disclosed for customer-data processing
- No HIPAA BAA disclosed — not positioned for healthcare data
- No FedRAMP authorization
- Platform pulls from 130+ third-party data providers; data-broker chain warrants review against your privacy policy
Best for
- B2B sales and GTM teams running outbound enrichment at mid-market and enterprise scale
- Revenue ops teams needing programmable enrichment workflows with controlled LLM usage
- Companies that have approved AWS US-East as their primary processing region
Avoid if
- You require EU data residency for processing of EU contact data
- You need HIPAA-compliant enrichment for healthcare workflows
- Your privacy program restricts ingestion of broker-sourced contact data
Citations
- Data Handling — Subprocessors Disclosed
- Security Compliance — Soc2 Type2
- Vendors — Funding Stage
- Vendors — Valuation
- Data Handling — Trains On User Data