Pipelizo
Legal · Security

Security overview

Last updated: May 1, 2026

01

Certifications

Pipelizo holds SOC 2 Type II and ISO/IEC 27001:2022 certifications. Reports are available under NDA from our security portal.

Pipelizo is HIPAA-ready for Scale customers with a signed BAA, and GDPR / UK-GDPR / CCPA compliant by default.

02

Encryption

Customer data is encrypted at rest using AES-256-GCM with per-tenant data encryption keys (DEKs) wrapped by per-region key encryption keys (KEKs) stored in cloud HSM. Keys rotate every 90 days.

Data in transit is encrypted using TLS 1.3 with certificate pinning on our mobile apps.

03

Access controls

Customer workspaces support SAML 2.0 SSO, SCIM provisioning, IP allow-listing, hardware-key 2FA enforcement, and granular role-based access control.

Internal Pipelizo employee access to customer data is strictly limited, requires individual just-in-time approval, and is fully logged. Production access requires hardware MFA.

04

Infrastructure

Pipelizo runs on top-tier cloud infrastructure across four regions (EU/UK/US/APAC). Each region is multi-AZ with automated failover.

Daily encrypted backups are retained for 35 days. RPO is <15 minutes; RTO is <1 hour.

05

Application security

Pipelizo undergoes annual third-party penetration testing. We run a public bug bounty program — reports go to support@pipelizo.com.

All code changes pass static analysis, dependency scanning (SCA), and require approval from a different engineer before merge.

06

Incident response

We maintain a documented incident response plan tested twice per year. Customer notification SLA: within 72 hours of confirmed security incidents affecting customer data.

Status page: status.pipelizo.com — subscribe via RSS, email, or webhook.

07

Privacy by design

Pipelizo AI does not train on customer workspace data without explicit per-workspace opt-in. Inference is per-tenant isolated.

No customer data is used for marketing or analytics outside the customer's own workspace.

08

Reporting a vulnerability

Found a security issue? Email support@pipelizo.com with PGP key 0x4F2DD9. We confirm receipt within 24 hours and pay bounties for valid reports.

Questions about this policy?

Reach out to our legal team — we reply within 2 business days.

Contact legal →
Ready when you are

Move your pipeline
like it's 2026.

Spin up a workspace in 90 seconds. Import your contacts in two clicks. Close your first deal in Pipelizo by Friday.

  • 20-min call
  • Weekend migration
  • Real operators
  • SOC 2 Type II
Onboarding · Day 1
3 of 4 steps complete
On track
Connect inbox
Import contacts (1,284)
Build first pipeline
4 Invite your team