ZoomInfo says it hosts in the U.S. across 3 unnamed cloud providers, then reserves the right to transfer data to any other country. Lusha names exactly 1 region, the United States, and 1 provider, AWS, but admits processing elsewhere without naming those countries beyond its own Israeli affiliate. Both publish only a SOC 2 Type II attestation; FedRAMP, StateRAMP, GovCloud and a HIPAA BAA are absent from both. Scope compared, criterion by criterion. Checked 14 September 2026.





ZoomInfo and Lusha both publish a SOC 2 Type II attestation and nothing beyond it on the regulated-cloud front: FedRAMP, StateRAMP, GovCloud and a HIPAA business associate agreement are absent from both vendors’ pages. A buyer who needs any of those four to close a public-sector or healthcare-adjacent deal finds the same blank space on either side of this comparison.
ZoomInfo states it hosts in the United States across three major cloud providers, naming none of them, with no region specified and no residency option offered. Its own privacy policy then admits that data may be transferred to any other country, which sits awkwardly next to the U.S.-only hosting claim on the same page.
Lusha is more specific on one point: AWS, in the United States, is the named host. But its privacy policy also describes processing in other countries, and the only one it names is not a hosting location at all — it is Lusha Systems Ltd., the company’s Israeli affiliate. No other country in that processing chain is identified.
Lusha’s Trust Center lists SOC 2 Type II plus ISO 27001, 27701, 27017, 31700 and 42001. Lusha’s privacy page lists SOC 2 plus ISO 27001, 27018 and 27701 instead — 27017 on one page, 27018 on the other. Both pages are Lusha’s, both are current, and Lusha reconciles neither list.
Two ZoomInfo pages list two different sets of certifications: ISO 27001, ISO 27701 and SOC 2 Type II appear on both, while TRUSTe and ISO 27017 appear on one page and not the other. ZoomInfo publishes both lists and reconciles neither, the same pattern Lusha runs on its own Trust Center against its own privacy page.
ZoomInfo registers as a data broker in Texas alone, despite admitting elsewhere that it sells personal data. Lusha names only California’s CCPA, with a dedicated removal form and phone line, and reserves its Do Not Call and UK TPS or CTPS scrubbing for the Scale tier only — a buyer on Starter, Pro or Premium gets no suppression tool at all, named or otherwise.
Can't find what you're looking for ? Contact us here
jordan@bulldozer-collective.comGet access to playbooks and feedback from those who are shaping the next wave of marketing and AI.