You own the inbox. You own the CRM. You own the data.
Cirrus Insight works inside systems you already own. We hold that access to a simple standard: we take only the permissions a feature needs, we tell you exactly what we do with each one, and we never sell your data.
Compliance & certifications
Each attestation below states what it covers, the period it covers, and who performed it.
SOC 2 Type I & Type II
Type I covered security, availability and confidentiality. The current Type II report covers the Cirrus Insight Sales Enablement Platform and the operating effectiveness of its security controls from November 1, 2024 to October 31, 2025. Reports available under NDA on request; bridge letters available on request.
STAR
CSA STAR Level One
We completed the Cloud Security Alliance’s STAR Level One self-assessment by answering the Consensus Assessments Initiative Questionnaire (CAIQ v4.1.0), which maps our security controls to the Cloud Controls Matrix. The completed questionnaire is public in the STAR Registry. Level One is performed by Cirrus Insight rather than an outside auditor; for independent attestation, see our SOC 2 Type II report above. View our STAR Registry listing →
27001
Infrastructure certifications
Cirrus Insight runs on Microsoft Azure. Azure data centres are ISO/IEC 27001 certified and SOC 2 attested. Payment processing is handled by a PCI DSS compliant third party.
GDPR & UK GDPR
We act as processor for customer data. Transfers out of the EEA, UK and Switzerland rely on the EU Standard Contractual Clauses and the UK Addendum. Our DPA is available on request.
CPRA
CCPA / CPRA
We process personal information as a service provider under CCPA/CPRA. We do not sell personal information. See your rights for how to make a request.
How we protect your data
Four pillars, all drawn from controls already described in our Privacy Policy.
Encryption
Data is encrypted in transit and at rest.
- TLS with 256-bit encryption in transit
- Transparent Data Encryption at rest
- Automated masking of personal data
- OAuth 2.0 — we never store your mail or CRM password
Access control
Least privilege, enforced and reviewed.
- Employee access limited to job function
- Need-to-know basis, reviewed on a defined cadence
- Recurring privacy and security training
- Support access only when providing live technical support
Infrastructure
Built on Microsoft Azure.
- ISO 27001 certified, SOC 2 attested data centres
- Data resides in North America where Cirrus is controller
- Business continuity and disaster recovery
- No device fingerprinting in logs
Testing
Audited independently, scanned continuously.
- Regular manual and automated security audits
- Incident Response Program, 72-hour notification
- Continuous vulnerability scanning
Privacy & your data rights
Cirrus Insight is a data processor for customer data and a controller for the information you give us directly. We do not sell personal information. Full detail lives in the documents below.
Reliability
Live status is published independently of our own infrastructure, so it stays up when we don't.
Live status
Every component — mail sync, calendar sync, tracking, scheduling, Buyer Signals — is monitored and reported at status.cirrusinsight.com. Subscribe there for incident notifications. For P1 issues, such as a total outage, we respond within one hour; other response targets depend on severity and your agreement.
Incident response
In the event of a data breach, Cirrus Insight activates its Incident Response Program: isolation of the event, notification to impacted individuals within 72 hours, a remediation plan and corrective action.
Report a security issue
If you've found something, we want to hear about it. This is never gated and never requires a form.
Security issues affecting
cirrusinsight.com or the Cirrus Insight applications can be reported to the
address below. We investigate every report and will confirm receipt.
Frequently asked questions
Answered here, not behind a form.
Are you SOC 2 compliant, and can we see the report?
Where is our data stored?
Do you sell our data?
How is our mail and CRM access authenticated?
Will you sign our DPA, or do you have your own?
How will we know if you add a subprocessor?
Running a security review?
Tell us what you need and we'll send it. SOC 2 reports and bridge letters go out under NDA, the DPA is available on request, and everything else on this page is already open.