<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=2732602&amp;fmt=gif">
Trust & Security

You own the inbox. You own the CRM. You own the data.

Cirrus Insight works inside systems you already own. We hold that access to a simple standard: we take only the permissions a feature needs, we tell you exactly what we do with each one, and we never sell your data.

Attestation
SOC 2 Type I & II
Live status
Section 01

Compliance & certifications

Each attestation below states what it covers, the period it covers, and who performed it.

SOC 2

SOC 2 Type I & Type II

Audited by Insight Assurance · Type I attested November 2024 · Type II period November 1, 2024 to October 31, 2025

Type I covered security, availability and confidentiality. The current Type II report covers the Cirrus Insight Sales Enablement Platform and the operating effectiveness of its security controls from November 1, 2024 to October 31, 2025. Reports available under NDA on request; bridge letters available on request.

CSA
STAR

CSA STAR Level One

Self-assessment · CAIQ v4.1.0 · Listed in the CSA STAR Registry September 30, 2026

We completed the Cloud Security Alliance’s STAR Level One self-assessment by answering the Consensus Assessments Initiative Questionnaire (CAIQ v4.1.0), which maps our security controls to the Cloud Controls Matrix. The completed questionnaire is public in the STAR Registry. Level One is performed by Cirrus Insight rather than an outside auditor; for independent attestation, see our SOC 2 Type II report above. View our STAR Registry listing →

ISO
27001

Infrastructure certifications

Held by our infrastructure providers, not by Cirrus Insight

Cirrus Insight runs on Microsoft Azure. Azure data centres are ISO/IEC 27001 certified and SOC 2 attested. Payment processing is handled by a PCI DSS compliant third party.

GDPR

GDPR & UK GDPR

Standard Contractual Clauses · UK Addendum

We act as processor for customer data. Transfers out of the EEA, UK and Switzerland rely on the EU Standard Contractual Clauses and the UK Addendum. Our DPA is available on request.

CCPA
CPRA

CCPA / CPRA

Service provider

We process personal information as a service provider under CCPA/CPRA. We do not sell personal information. See your rights for how to make a request.

Section 02

How we protect your data

Four pillars, all drawn from controls already described in our Privacy Policy.

Encryption

Data is encrypted in transit and at rest.

  • TLS with 256-bit encryption in transit
  • Transparent Data Encryption at rest
  • Automated masking of personal data
  • OAuth 2.0 — we never store your mail or CRM password

Access control

Least privilege, enforced and reviewed.

  • Employee access limited to job function
  • Need-to-know basis, reviewed on a defined cadence
  • Recurring privacy and security training
  • Support access only when providing live technical support

Infrastructure

Built on Microsoft Azure.

  • ISO 27001 certified, SOC 2 attested data centres
  • Data resides in North America where Cirrus is controller
  • Business continuity and disaster recovery
  • No device fingerprinting in logs

Testing

Audited independently, scanned continuously.

  • Regular manual and automated security audits
  • Incident Response Program, 72-hour notification
  • Continuous vulnerability scanning
Section 04

Reliability

Live status is published independently of our own infrastructure, so it stays up when we don't.

98%
Standard contractual uptime baseline · up to 99.9% for enterprise

Live status

Every component — mail sync, calendar sync, tracking, scheduling, Buyer Signals — is monitored and reported at status.cirrusinsight.com. Subscribe there for incident notifications. For P1 issues, such as a total outage, we respond within one hour; other response targets depend on severity and your agreement.

Incident response

In the event of a data breach, Cirrus Insight activates its Incident Response Program: isolation of the event, notification to impacted individuals within 72 hours, a remediation plan and corrective action.

Section 05

Report a security issue

If you've found something, we want to hear about it. This is never gated and never requires a form.

Security issues affecting cirrusinsight.com or the Cirrus Insight applications can be reported to the address below. We investigate every report and will confirm receipt.

Coordinated disclosure
Programme returning
Section 06

Frequently asked questions

Answered here, not behind a form.

Are you SOC 2 compliant, and can we see the report?
Yes — SOC 2 Type I and Type II, audited by Insight Assurance. Type I was attested in November 2024 covering security, availability and confidentiality. The current Type II report covers the security controls of the Cirrus Insight Sales Enablement Platform from November 1, 2024 to October 31, 2025. Reports are available under NDA on request, as are bridge letters. Email privacy@cirrusinsight.com.
Where is our data stored?
On Microsoft Azure. Where Cirrus Insight acts as data controller, all data collected resides exclusively in North America unless specifically noted otherwise. Where we act as data processor, location depends on the configuration your organisation selected.
Do you sell our data?
No. Cirrus Insight does not sell data to third parties and does not sell personal information. Some analytics and advertising activity on our public website may constitute "sharing" for cross-context behavioural advertising under California law — you can opt out via Your Privacy Choices.
How is our mail and CRM access authenticated?
Through OAuth 2.0. Cirrus Insight receives a token scoped to the permissions you grant and does not receive or store passwords for connected third-party services. Access never escalates beyond what the connected user's own permissions already allow.
Will you sign our DPA, or do you have your own?
We have a standard DPA incorporating the EU Standard Contractual Clauses and the UK Addendum, available on request from privacy@cirrusinsight.com. Publishing it as a downloadable standard form is in progress.
How will we know if you add a subprocessor?
We email Cirrus Insight admins when our subprocessors change. The current list is always published on our trust centre.

Running a security review?

Tell us what you need and we'll send it. SOC 2 reports and bridge letters go out under NDA, the DPA is available on request, and everything else on this page is already open.

Request review documents

Conversion Pixel Image