Security
Company-level by design
The simplest way to protect personal data is not to hold it. Pipefox never reads contact records, so there is no PII in our systems to lose.
What we hold and what we refuse
We read company names and domains, campaign and spend metrics, deal stage and amount, and aggregated engagement counts. That is the entire list.
We do not sync contacts, leads or people. If your security review asks how we handle subject access requests for individuals, the answer is that we have nothing to return.
Controls
SOC 2 Type II
Audited annually. Report available under NDA on request.
GDPR aligned
EU data residency available. DPA signed as standard.
Encrypted throughout
TLS 1.3 in transit, AES-256 at rest, keys rotated quarterly.
Least privilege
OAuth scopes limited to read. Revoke from your CRM at any time.
Sub-processors listed
Published, with notice before any change takes effect.
Deletion on request
Full workspace deletion inside 30 days, confirmed in writing.
Found something? Write to security@pipefox.com. We acknowledge reports within one working day.
Ready to show where the pipeline came from?
Thirty days free. No card, no call, no implementation project.