Third Party Index

Snapshot 30859

Document
Security page
URL
https://conversion.ai/security/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
156001 bytes
SHA-256 (raw)
0e73b5a23454926219090237880de4803d544b7459bfa5f3732d1ae7c786c089
SHA-256 (normalized text)
806ad4753863780cb19373449c0813c697e7d1aaf1a5aae6f986dd55209c55e3

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to main content
New Introducing Mosaic: attribution built natively into Conversion Introducing Mosaic Learn more
Book a Demo Log in
Enterprise-grade protection, built in
From access controls to audit logs, every layer of Conversion is designed to keep your most sensitive marketing data secure.
Book a demo Contact security
SOC 2 Type II certified · GDPR compliant
Used by enterprise teams leaving
Marketo, Pardot, and HubSpot
How access stays under control.
Your identity provider decides who gets in, roles decide what each person can do, and every agent works inside the limits you set.
Generate a SCIM token
Ensure your identity provider (IdP) supports pushing new users and pushing user updates. You will only be able to view the generated token one time.
Base URL
https://api.conversion.ai/scim/v2
SCIM token
scim_4f9c2e81b7d0a36e5f14c9b2d7a08e3f61c5b94d2a7e0f83c6b1d59e4a27f0c3
Confirm and generate I have copied the token
Provision from your identity provider
SCIM 2.0 creates and updates members from Okta, Microsoft Entra ID, or another provider, and deactivating someone ends their sessions.
Contacts 0/4
View contacts See contact records and their details.
Create contacts Add new contact records, including CSV imports.
Edit contacts Update fields on existing contacts.
Delete contacts Permanently remove contact records.
Give each role the permissions it needs
Start from Administrator, Manager, Editor, or Viewer, or build a custom role one permission at a time, like editing contacts without deleting them.
Search tools... All tools
Contacts 12 tools
Count contacts Counts contacts matching a set of criteria.
Start contact CSV export Starts an export of contacts to CSV.
Create contact Creates a contact.
Process CSV contact import Processes an uploaded contact CSV import.
Choose what each agent can do
Set every tool an agent has to run on its own, wait for your approval, or stay off. Deletes and edits to live assets ask first by default.
Contact meets criteria
Deletion requested is True
Delete contact
Delete contact and Salesforce record
Erase a contact everywhere
Delete a contact from their record, a workflow step, or a request, along with their engagement data and, if you choose, their Salesforce record.
See who changed what, and when.
The audit log records every change across your workspace, from a role's permissions to a workflow going live, with who made it and when. Changes from API keys and agents are recorded the same way.
Audit log
A record of who did what, to which object, and when across your workspace.
All Assets Administration
Activity from today
DW Dana Whitfield Updated the Campaign specialist role permissions.
Permissions changed View
Role · Campaign specialist Today at 10:42 AM
Conversion Agent Created email from the Newsletter base template.
Created View
Email · Webinar invite Today at 10:18 AM
MC Marcus Chen Activated the workflow.
Activated View
Workflow · Trial onboarding Today at 9:51 AM
DW Dana Whitfield Required multi-factor authentication for all members.
Updated View
Security · MFA policy Today at 9:05 AM
DW Dana Whitfield Lavender Data Updated the Campaign specialist role permissions. Role · Campaign specialist
Permissions changed Today at 10:42 AM
Field changes
Create contacts Not granted Granted
Edit contacts Not granted Granted
Context
Actor Dana Whitfield [email protected]
When Sep 24, 2026 at 10:42 AM 2026-09-24 17:42 UTC
Source UI
IP address 203.0.113.24
Compliance
Ready for your security review.
Conversion is SOC 2 Type II audited, and our DPA covers GDPR and CCPA. Request the report and review our subprocessors in the trust center.
Visit the trust center
SOC 2 Type II GDPR CCPA
SOC 2 Type II audited
Independent auditors test our security controls every year. Request the latest report from the trust center.
Conversion AI Zero data retention Model provider
Zero data retention on AI
Every Conversion AI chat and agent model call runs with zero data retention, and your data never trains a model.
In transit TLS 1.2+
At rest AES-256
Hosted Google Cloud, US
Encrypted and hosted in the US
Data is encrypted with TLS 1.2+ in transit and AES-256 at rest, on Google Cloud in the United States.
One thing I really appreciated about the Conversion team was their commitment to building a Salesforce extension that met our security requirements, included detailed logging so nothing fell through the cracks, and held up to our enhanced security standards in a post Salesloft-breach world.
Jayson Lindsley
Director of IT, MyOutDesk
4
Built-in roles, plus custom roles with the permissions you choose
3
Modes for every agent tool: auto-approve, require approval, or off
48h
To notify you of a confirmed breach, under our DPA
FAQ
Common questions
What security and IT teams ask before they approve Conversion.
No. Customer data is never used to train, fine-tune, or improve AI models, ours or anyone else's, and our DPA says so. Every model call Conversion AI makes in chats and agents is routed with zero data retention enforced.
Request it through our trust center, where you can also find our subprocessor list and other security documentation, or email [email protected].
Any SAML 2.0 provider, with setup guides for Okta, Microsoft Entra ID, Google Workspace, and OneLogin. You can require SSO for the workspace and create accounts on first sign-in with just-in-time provisioning. SCIM 2.0 creates and updates members from your provider, and deactivating someone there ends their Conversion sessions right away.
Yes. Start from the built-in Administrator, Manager, Editor, and Viewer roles, or create a custom role and choose each permission it grants, across contacts, emails, workflows, forms, audiences, campaigns, and workspace settings. You can clone a built-in role as a starting point.
Yes. The audit log records who changed what, to which object, and when across your workspace, including changes made through API keys and by agents. Filter it by person, action, asset type, or date, open any event to see its old and new values, and export it as CSV or JSON.
Each tool an agent has is set to auto-approve, require approval, or disabled, and you can change any of them. Deletes, edits to live assets, and new contacts ask first by default. No agent can send a blast, publish a form, or turn on a workflow; your team does that. Plays send only the emails your team puts in their pool.
Yes. Every agent run is saved as a session with its full history of messages, tool calls, and approvals, and the changes an agent makes appear in the audit log next to your team's.
Customer data is stored and processed primarily in the United States, on Google Cloud (us-central1). It is encrypted in transit with TLS 1.2 or higher and at rest with AES-256.
Yes. Our DPA covers GDPR and CCPA, includes the EU Standard Contractual Clauses and UK addendum, and names our EU and UK Article 27 representatives. It commits us to notify you within 48 hours of confirming a breach.
Delete a contact from their record, with a Delete contact step in a workflow, or by request. Deleting a contact removes their engagement data too, and you can choose to delete the linked Salesforce lead or contact at the same time.
Bring your security questionnaire.
We'll walk your team through SSO, custom roles, the audit log, and our SOC 2 Type II report during the demo.
Book a demo
We value your privacy
This site uses cookies to improve your browsing experience, analyze site traffic, and show personalized content. Privacy Policy
Privacy Preferences
Choose which cookies you'd like to allow. Your choices will be saved and you can change them at any time. Privacy Policy · Terms of Service