Data classification

Customer Content

Customer content is data created by or belonging to your customers — documents, messages, user-generated content, configurations, and business data stored in your product. SaaS vendors with access to your product data store carry this risk.

Risk profile

Unauthorized access to customer content can violate contractual confidentiality obligations, trigger data breach notification requirements, and destroy customer trust. Vendors with access to customer content should be assessed at the same level as your own internal systems.

Applicable frameworks

SOC 2ISO 27001GDPR

Example vendors

AWSGoogle CloudDatabricksSnowflake

Common questions

Is customer content covered by my SOC 2 audit scope?
If your SOC 2 covers the systems that store customer content, then yes — but verify the system description in Section I to confirm scope. Infrastructure-level vendors (AWS, GCP) are typically listed as subprocessors, not in scope themselves.

Which of your vendors handle Customer Content?

TrustVendor tracks data class exposure across your entire vendor portfolio and computes residual risk per relationship.

Book a demo