SalesOS Compliance & Roadmap
Which certifications SalesOS holds (none yet), what it does instead, and what we plan to do next.
Status by framework
| Framework | Status | Detail |
|---|---|---|
| SOC 2 | Not started | SalesOS has no SOC 2 report and no audit is under way. |
| ISO/IEC 27001 | Not started | SalesOS is not ISO 27001 certified. |
| Independent penetration test | Not done | No third-party penetration test has been carried out yet. |
| GDPR | Tools in place | Self-service export and deletion, a published sub-processor list and a DPA click-through for organization admins. There is no independent GDPR assessment. |
| PCI DSS | Handled by Stripe | Card payments go through Stripe. SalesOS has no PCI DSS attestation of its own. |
| HIPAA | Not supported | SalesOS has not been assessed against HIPAA. Do not store protected health information in it. |
| WCAG 2.1 AA | Target, tested automatically | See the accessibility statement for how we test and the known gaps. |
Security roadmap
Planned work, not started unless stated. Each item closes a gap named on the Security or Privacy page.
- 1Enforce the PostgreSQL row-level security policies for the application’s own database role.
- 2Scheduled, encrypted backups with an off-site copy and regular restore tests.
- 3Always ask for a two-factor code when a user has turned 2FA on, whatever the enforcement policy.
- 4An idle timeout and a fixed maximum session length.
- 5HSTS and other security headers on the web pages, not only the API.
- 6Field-level encryption for connected email and calendar OAuth tokens.
- 7Fixed retention periods for request logs, audit logs, notifications, analytics events and export files.
- 8Adopt the drafted incident response procedure and publish breach-notification commitments in the DPA.
- 9An independent penetration test.
- 10SOC 2 readiness work.
Accessibility
We aim to meet WCAG 2.1 level AA. Read the full accessibility statement for how the app is tested and the known exceptions.
Security questionnaires
Send your questionnaire to [email protected]. We answer from the same facts published in this Trust Center.
Last reviewed 29 September 2026. Questions about anything here: [email protected].