Pipefox

Security

Company-level by design

The simplest way to protect personal data is not to hold it. Pipefox never reads contact records, so there is no PII in our systems to lose.

What we hold and what we refuse

We read company names and domains, campaign and spend metrics, deal stage and amount, and aggregated engagement counts. That is the entire list.

We do not sync contacts, leads or people. If your security review asks how we handle subject access requests for individuals, the answer is that we have nothing to return.

What Pipefox stores and what it does not

Controls

SOC 2 Type II

Audited annually. Report available under NDA on request.

GDPR aligned

EU data residency available. DPA signed as standard.

Encrypted throughout

TLS 1.3 in transit, AES-256 at rest, keys rotated quarterly.

Least privilege

OAuth scopes limited to read. Revoke from your CRM at any time.

Sub-processors listed

Published, with notice before any change takes effect.

Deletion on request

Full workspace deletion inside 30 days, confirmed in writing.

Found something? Write to security@pipefox.com. We acknowledge reports within one working day.

Ready to show where the pipeline came from?

Thirty days free. No card, no call, no implementation project.

Start free