Last updated June 26, 2026. Questions? founders@petrarch.co
Compliance is not a checkbox for Petrarch — it's the foundation that makes the marketplace viable. Buyers will only transact if they trust the data is clean. Sellers will only participate if they trust their interests are protected. Our compliance work is the product.
Our goal is basic SOC 2 certification plus US-compliant commercial agreements — sufficient to de-risk transactions for both sides of the marketplace from day one.
We are in Phase 1 of SOC 2 certification, which requires an independent auditor assessment of our security controls at a point in time. This covers security, availability, and confidentiality trust service criteria relevant to our data handling operations.
Type 2 — which covers the effectiveness of controls over a period of time — will follow after Type 1 is complete. We expect to begin this process after we've operated live transactions for a full audit period.
Data broker registration laws vary by U.S. state. We are actively reviewing our obligations under these laws with our legal counsel. Relevant recent developments:
We will not transact any dataset that we cannot confirm meets our anonymization standard. If a proposed dataset contains residual PII that cannot be fully removed, we decline the transaction.
All Petrarch transactions are documented through executed legal agreements, drafted by Wilson Sonsini Goodrich & Rosati:
Covers provenance representations, chain-of-custody verification, seller indemnification, PII removal obligations, and IP licensing terms. Sellers confirm they have the right to license the data before any transaction proceeds.
Covers permitted use restrictions, exclusivity/non-exclusivity terms, buyer liability for downstream use, and dataset-specific specifications. Primary liability for data use sits with the buyer.
Used in the pre-transaction phase to allow sharing of data samples with potential buyers for evaluation. Standard NDA terms with an additional clause permitting downstream sample sharing for the specific purpose of evaluating a potential transaction.
All agreements are executed via DocuSign. No transaction proceeds without a fully signed agreement.
Before facilitating any transaction, we verify:
For data from failed or distressed startups — our primary sourcing focus — we apply additional scrutiny around ownership, particularly in cases where "work for hire" arrangements may create partial third-party ownership claims. We do not acquire datasets where ownership is unclear.
The following are explicitly out of scope for the current Petrarch marketplace:
For compliance questions, audit requests, or to report a concern: founders@petrarch.co