Skip to main content

SalesOS Compliance & Roadmap

Which certifications SalesOS holds (none yet), what it does instead, and what we plan to do next.

Status by framework

Compliance status by framework
FrameworkStatusDetail
SOC 2Not startedSalesOS has no SOC 2 report and no audit is under way.
ISO/IEC 27001Not startedSalesOS is not ISO 27001 certified.
Independent penetration testNot doneNo third-party penetration test has been carried out yet.
GDPRTools in placeSelf-service export and deletion, a published sub-processor list and a DPA click-through for organization admins. There is no independent GDPR assessment.
PCI DSSHandled by StripeCard payments go through Stripe. SalesOS has no PCI DSS attestation of its own.
HIPAANot supportedSalesOS has not been assessed against HIPAA. Do not store protected health information in it.
WCAG 2.1 AATarget, tested automaticallySee the accessibility statement for how we test and the known gaps.

Security roadmap

Planned work, not started unless stated. Each item closes a gap named on the Security or Privacy page.

  1. Enforce the PostgreSQL row-level security policies for the application’s own database role.
  2. Scheduled, encrypted backups with an off-site copy and regular restore tests.
  3. Always ask for a two-factor code when a user has turned 2FA on, whatever the enforcement policy.
  4. An idle timeout and a fixed maximum session length.
  5. HSTS and other security headers on the web pages, not only the API.
  6. Field-level encryption for connected email and calendar OAuth tokens.
  7. Fixed retention periods for request logs, audit logs, notifications, analytics events and export files.
  8. Adopt the drafted incident response procedure and publish breach-notification commitments in the DPA.
  9. An independent penetration test.
  10. SOC 2 readiness work.

Accessibility

We aim to meet WCAG 2.1 level AA. Read the full accessibility statement for how the app is tested and the known exceptions.

Security questionnaires

Send your questionnaire to [email protected]. We answer from the same facts published in this Trust Center.

Last reviewed 29 September 2026. Questions about anything here: [email protected].