Security & Compliance Overview

    How Pipeline CRM protects your data, which certifications we hold, and what you control.

    Compliance at a Glance

    Standard

    Where Pipeline CRM stands

    SOC 2

    Certified — independently audited against the AICPA Trust Services Criteria

    GDPR

    Supported — you can edit, export, and request deletion of your records at any time

    PCI DSS

    Not applicable — we don't store credit card data anywhere in our systems

    HIPAA

    Not compliant — we can't sign a Business Associate Agreement (BAA)

    Certifications and Standards

    SOC 2

    Our security controls, availability, and data handling practices have been independently audited and verified against the AICPA's Trust Services Criteria.

    GDPR

    Our data practices are built to give you control over your data — you can edit records, export them, and request deletion at any time. See our Privacy Policy and GDPR page for details.

    PCI DSS

    We don't store credit card information anywhere in our systems, so PCI compliance isn't required for how we operate. We don't undergo the external PCI audit.

    HIPAA

    Pipeline CRM is not HIPAA compliant and we're unable to sign a BAA.

    Handling protected health information? Pipeline CRM is not the right fit for storing or managing PHI. Check with your compliance team before using any CRM for that data.

    Where Your Data Is Hosted

    • Data is hosted on Amazon Web Services (AWS), in data centers located in Virginia, in the United States.
    • The full database is backed up every four hours to geographically redundant locations.

    For more detail, see Where are your data centers located?

    Encryption and Access Controls

    • All data is transmitted over HTTPS using TLS encryption.
    • Access to account data is controlled through role-based permissions.
    • Admins can manage user access and immediately revoke permissions for inactive users. See User Management.

    Your Data Rights

    You stay in control of your data at all times:

    • Edit or delete any record directly in the app.
    • Export your data to CSV or PDF whenever you need it. See Export Your Data for Backup or a Data Request.
    • Request special data removal by contacting support with written admin consent.

    Data Retention After Cancellation

    Your account stays accessible until the end of your current billing cycle. After that, Pipeline CRM retains your data for 270 days from the cancellation date, then permanently and automatically deletes it. Deleted data cannot be recovered.

    Export anything you want to keep before the 270-day window closes. See Pause or Cancel Your Account.

    Need help? Contact support at customercare@pipelinecrm.com.