Log in

Trust center

At Pipedrive, we maintain the highest standards of security and privacy, giving you transparency and reassurance in how we protect your data.

Our CRM security policies are designed to meet the necessary criteria for businesses in different locations to comply with local and global security standards. Pipedrive uses a world-class hosting infrastructure and state-of-the-art encryption for your data, employing a dedicated data protection officer who spearheads data protection compliance and initiatives.

Certificates

Pipedrive is dedicated to protecting your data with multiple security certificates, world-class infrastructure and a range of CRM privacy and security features, including user permissions, single sign-on and two-factor authentication.

Resources

SOC 2
ISO/IEC 27001:2013 and ISO/IEC 27701:2019 certificate
RFC 2350
Pipedrive Vulnerability Disclosure Program

Pipedrive shares the following information with all customers:

  1. Security and Privacy Whitepaper
  2. SOC 3 report
  3. ISO/IEC 27001:2013 and ISO/IEC 27701:2019 certificate
  4. Pipedrive DPA (our legal contract detailing our commitments in regard to data protection)

Pipedrive shares the following additional information with all customers who’ve signed NDAs*:

  1. SOC 2 Type II report
  2. Security questionnaires. Pipedrive fills out questionnaires for customers who are on the Enterprise Tier

*Please reach out to your contact person/account executive for clarification or to receive the above documents.

Pipedrive CRM security policy

We at Pipedrive adhere to the following guidelines to meet the highest standards of CRM security policy:

  • Customers’ data is stored in separate databases to avoid the risk of any leaks into other databases
  • Pipedrive accounts are hosted in AWS data centers in Europe and the US by hosting providers compliant with SOC 1/ISAE 3402, SOC 2, SOC 3
  • All information is encrypted via secure HTTPS connections and is backed up daily through Amazon Web Services
  • Pipedrive complies with GDPR and adheres to SOC 2, SOC 3, the EU-US Data Privacy Framework and ISO/IEC 27001:2013 and ISO/IEC 27701:2019
  • Pipedrive employees are regularly trained regarding security best practices and regulations

FAQs

Updates

Changes to our sub-processors list

14th April 2025

As part of our continuing commitment to comply with data protection laws, we’re letting you know that we have made some updates to our sub-processors list:

From March 17, 2025, Pipedrive has a new sub-processor, Fullview ApS. This tool will be used by customer support for screen sharing and co-browsing to help resolve customer issues. Fullview ApS will be activated during support calls after the customer support specialist has informed the user and obtained their consent.

From April 14, 2025, Pipedrive has added two new sub-processors: Forge Technology, Inc. (Paragon) and RightBound Inc.

  • Forge Technology, Inc. (Paragon): Embedded iPaaS (integration platform as a service) used to build integrations for certain Marketplace apps marked accordingly.
  • RightBound, Inc.: Service provider for the data enrichment feature.

These subprocessors will only be used when you use the specific Marketplace app or data enrichment feature, respectively.

We’ve also made the following updates:

  • Standardized the terminology across our legal documents for better consistency
  • Improved the structure of the sub-processors list for clarity
  • Corrected an omission Pipedrive OÜ, which should have been previously listed as a sub-processor, has now been included to ensure full accuracy

You can view the updated list of sub-processors here.

Update to ISO certificate

16th December 2024

Pipedrive has successfully passed its ISO 27001 information security management system (ISMS) surveillance audit and our first-ever ISO 27701 privacy information management certification audit and is now proud to be certified under both ISO 27001 and ISO 27701, reflecting our ongoing commitment to security and privacy. Certificate can be found under security resources above.

Update to Supplemental Terms and Sub-processor’s list

4th September 2024

As part of our continuing commitment to comply with data protection laws, we’re letting you know that we’ll be updating our sub-processors list:

  • We have removed Twilio, Inc., a third-party service provider that previously powered the Caller feature, as the feature has been sunsetted.
  • We removed Cognism from the list of Sub-processors because Cognism defines itself as a data controller, meaning that Pipedrive facilitates the data exchange between two data controllers - Cognism and the Client. This has also been reflected in the LeadBooster Feature Supplemental Terms.
  • We specified Rackspace GmbH's changed role. Pipedrive no longer uses Rackspace GmbH for hosting and CDN services; instead, Rackspace provides support services for AWS.
  • We specified the OpenAI entity we contract with - instead of OpenAI LLC, it’s OpenAI Ireland Limited.
  • We unified the terminology used to match our other legal documents.

You can see the list of the most up-to-date sub-processors here.

Updated Privacy Notice

4th July 2024

We've updated our Privacy Notice. You can find the latest version here.

See how Pipedrive works for your business