Log in

Trust center

At Pipedrive, we maintain the highest standards of security and privacy, giving you transparency and reassurance in how we protect your data.

Our CRM security policies are designed to meet the necessary criteria for businesses in different locations to comply with local and global security standards. Pipedrive uses a world-class hosting infrastructure and state-of-the-art encryption for your data, employing a dedicated data protection officer who spearheads data protection compliance and initiatives.

Certificates

Pipedrive is dedicated to protecting your data with multiple security certificates, world-class infrastructure and a range of CRM privacy and security features, including user permissions, single sign-on and two-factor authentication.

Resources

SOC 2
ISO/IEC 27001:2013
Whitepaper
RFC 2350
Pipedrive Vulnerability Disclosure Program

Pipedrive shares the following information with all customers:

  1. Security and Privacy Whitepaper
  2. SOC 3 report
  3. ISO/IEC 27001:2013 certificate
  4. Pipedrive DPA (our legal contract detailing our commitments in regard to data protection)

Pipedrive shares the following additional information with all customers who’ve signed NDAs*:

  1. SOC 2 Type II report
  2. Security questionnaires. Pipedrive fills out questionnaires for customers who are on the Enterprise Tier

*Please reach out to your contact person/account executive for clarification or to receive the above documents.

Pipedrive CRM security policy

We at Pipedrive adhere to the following guidelines to meet the highest standards of CRM security policy:

  • Customers’ data is stored in separate databases to avoid the risk of any leaks into other databases
  • Pipedrive accounts are hosted in AWS data centers in Europe and the US by hosting providers compliant with SAS 70 type II
  • All information is encrypted via secure HTTPS connections and is backed up daily through Amazon Web Services
  • Pipedrive complies with GDPR and adheres to SOC 2, SOC 3, the EU-US Data Privacy Framework and ISO/IEC 27001:2013
  • Pipedrive employees are regularly trained regarding security best practices and regulations

FAQs

Updates

Update to Supplemental Terms and Sub-processor’s list

4th September 2024

As part of our continuing commitment to comply with data protection laws, we’re letting you know that we’ll be updating our sub-processors list:

  • We have removed Twilio, Inc., a third-party service provider that previously powered the Caller feature, as the feature has been sunsetted.
  • We removed Cognism from the list of Sub-processors because Cognism defines itself as a data controller, meaning that Pipedrive facilitates the data exchange between two data controllers - Cognism and the Client. This has also been reflected in the LeadBooster Feature Supplemental Terms.
  • We specified Rackspace GmbH's changed role. Pipedrive no longer uses Rackspace GmbH for hosting and CDN services; instead, Rackspace provides support services for AWS.
  • We specified the OpenAI entity we contract with - instead of OpenAI LLC, it’s OpenAI Ireland Limited.
  • We unified the terminology used to match our other legal documents.

You can see the list of the most up-to-date sub-processors here.

Updated Privacy Notice

4th July 2024

We've updated our Privacy Notice. You can find the latest version here.

See how Pipedrive works for your business