Third Party Index

Snapshot 35626

Document
Security page
URL
https://www.fibbler.co/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
224669 bytes
SHA-256 (raw)
4202ab4e6fd30f0cfaf8f6ace4c9435f47b4a700f61b0d38c00a80ce11898fb9
SHA-256 (normalized text)
99728365fb2845b82b6c1f21c563b79e4160d2c2fc807177552c166a4a4c99b2

Normalized text

Scripts and page chrome removed; this is what change detection compares.

How Fibbler keeps your data safe
A practical guide to our security, privacy, and data handling practices. Whether you're evaluating Fibbler or already a customer, this page gives you clear answers to the most common security, privacy, and compliance questions we get - no jargon, no fluff.
Last updated: October 2026
The short version
All customer and application data is hosted in the EU on Google Cloud (Belgium region)
Immutable infrastructure and security by design
We don't process personal data as part of our core product, except your account email
We store LinkedIn ads data, Google Ads campaign data, Meta Ads campaign data, and CRM data (company records and deals) in our database for attribution, analytics, and MCP features. The database can't be reached directly from the internet. Access goes through Google's IAM-authenticated proxy, and every connection is encrypted. If you disconnect or cancel, stored CRM data is deleted within 30 days
SOC 2 Type 1 compliant, audited by Sensiba in September 2026, with our GDPR alignment checked in the same audit. SOC 2 Type 2 and ISO 27001 are underway. Our infrastructure provider Google Cloud is SOC 2 Type II and ISO 27001 certified
You control what gets connected, and nothing happens without your authorization
You can disconnect any integration, or switch CRM Sync and Signals off, at any time
Two-factor authentication (TOTP) is available on every plan, and workspace owners can require it for every member of their workspace
MCP (connect your data to LLMs like Claude, ChatGPT, and Cursor) is available on the Unlimited and Agency plans and during the free trial. Some MCP tools need a connected CRM. When you use MCP, the AI tool you connect processes the answers it pulls from Fibbler, under your own agreement with that provider
Website visitor company identification is powered by our partner Dealfront (Leadfeeder), used on fibbler.co and as part of the Google Ads and Meta Ads add-ons. For those add-ons, the Fibbler tracking script (powered by Dealfront) runs on your own website and identifies companies from visitor IP addresses. Dealfront is ISO 27001 and ISO 27701 certified with all data hosted in the EU. We have a Data Processing Agreement in place with Dealfront
Frequently asked questions
Where is data stored?
All customer and application data is hosted in the EU on Google Cloud. No customer data is processed outside the EU. See the Infrastructure section below for details.
Do you process personal data?
The only personal data we handle is your email address for account management. We do not process individual contact records from your CRM, personal identifiers, LinkedIn messages, or sensitive information of any kind.
We do store company-level and deal/opportunity data from your CRM (company names, domains, deal amounts, deal stages) to power attribution and analytics features. This is business data, not personal data.
What do you access in LinkedIn, Google Ads, Meta Ads, HubSpot, Salesforce, Attio, and Pipedrive, and why?
We only access company-level and deal/opportunity data required to power the analytics, attribution, and reporting features you explicitly enable.
LinkedIn Ads
We access your LinkedIn Ads account via the LinkedIn Marketing API:
Data	Access	Fields	Why it's used
Campaigns	Read	name, ID, status, objective	To display and attribute campaign performance
Performance Metrics	Read	impressions, clicks, spend, engagements	For attribution and ROI reporting
Company Engagement	Read	company name, domain, engagement data	To match ad engagement to CRM accounts
Campaign Targeting	Write	targeting exclusions (job titles, companies)	For Audience Exclusions and Impression Caps features (only when enabled by you)
HubSpot, Salesforce, Attio & Pipedrive
We access the following data from your CRM:
Object	Access	Fields	Why it's used
Company/Account	Read	name, domain, ID	To match CRM records to campaigns
Opportunity/Deal	Read	name, amount, status, created/close dates, ID	For revenue attribution and funnel reporting
Custom Fields	Read	field names, and the values of the deal fields we use	To allow mapping of ad data into the CRM
Custom Fields	Write	Fibbler-created fields on Company/Account (HubSpot, Salesforce, Attio & Pipedrive)	For CRM Sync: creates fields to store LinkedIn, Google Ads or Meta Ads engagement data (only when enabled by you)
Custom Fields	Write	Fibbler-created signal fields on Company/Account: signal type, date, name, channels and reason	For Ad Engagement Signals: records why an account was surfaced, so you can filter on it (only when enabled by you)
Company/Account	Create	name, domain, industry, employee count, LinkedIn page - on new records only	For Ad Engagement Signals, only once you turn a signal on. When a signal sends to your CRM it creates the account if it's missing, and marks it as created by Fibbler
List / View / Filter	Create & update	One list of companies per signal, and which companies are in it. Only lists we created, addressed by an id we stored	For Ad Engagement Signals: the queue your team works from. Accounts leave it after 30 days; the records themselves are untouched
Note	Create	A note on the Company/Account (Salesforce, Attio & Pipedrive)	For Ad Engagement Signals: the one-line reason a rep reads. Not in HubSpot, where the only permission for notes is write access to every contact, which we do not ask for
Both features are off until you turn them on, and both apply to all supported CRMs (HubSpot, Salesforce, Attio, and Pipedrive). Everything else we do in your CRM is read-only.
A word on lists, because the permission is broader than the use. In HubSpot a list can hold contacts, companies or deals, and the permission covers all three because HubSpot offers no narrower one. Every list we create is a list of companies, and the only lists we ever touch are the ones we created - addressed by an id we stored when we made them. We never search or browse the lists in your account, so a list we did not make is one we cannot name and will never open. Read access is there so our support team can look up one of those lists when a customer tells us it is not filling; a signal running normally never reads a list at all.
On a record that already exists we only ever write our own fields. Your name, domain, owner, lifecycle stage and everything else your team maintains are never changed by us. The firmographic details above are written only on a record we create.
Google Ads (optional add-on)
We access campaign and performance data via the Google Ads API. We only read your Google Ads data and never change anything in your account.
Data	Access	Fields	Why it's used
Campaigns	Read	name, ID, status, type	To display campaign performance and attribution
Ad Groups / Keywords	Read	name, ID, text, match type, metrics	To group performance and connect search terms to pipeline
Performance Metrics	Read	clicks, impressions, spend, conversions	For attribution and ROI reporting
Website Visitor Data (via Dealfront)	Read	company name, industry, visit behavior	To match website visits to Google Ads campaigns and CRM deals
Meta Ads (optional add-on)
We access campaign and performance data via the Meta Marketing API. We only read your Meta Ads data and never change anything in your account.
Data	Access	Fields	Why it's used
Ad Accounts	Read	name, ID, currency, status	So you can pick which ad accounts we read
Campaigns	Read	name, ID, status, objective	To display campaign performance and attribution
Performance Metrics	Read	impressions, clicks, engagements, spend	For attribution and ROI reporting
Website Visitor Data (via Dealfront)	Read	company domain, landing page, and the campaign and ad from your UTM tags	To match website visits to Meta Ads campaigns and CRM deals
Do you store any of that data?
We store LinkedIn ads data, Google Ads campaign data, Meta Ads campaign data, and CRM data in our database to power attribution, analytics, and MCP features. This includes campaign performance metrics, audience exclusions, attribution data, CRM company records (name, domain), and deal/opportunity records (amount, stage, dates).
CRM data is synchronized on a regular schedule and kept up to date while your integration remains connected. If you disconnect or cancel, stored CRM data is deleted within 30 days. If you prefer not to have CRM data stored, you can opt out by contacting [email protected].
All stored data is encrypted at rest using AES-256 encryption.
Do you push anything back into my CRM?
Only if you explicitly enable it. Two features write to your CRM.
CRM Sync pushes LinkedIn, Google Ads or Meta Ads engagement data into HubSpot, Salesforce, Attio or Pipedrive by creating custom fields on your Company/Account records.
Ad Engagement Signals does more, so it is worth being plain about. For each signal you build it creates a list, view or filter named after that signal, keeps the right accounts in it, and writes its own fields on each one saying why it was surfaced. In Salesforce, Attio and Pipedrive it also leaves a note on the record. If an account is missing from your CRM, the signal creates it and marks it as created by Fibbler, so you can find them all again. Signals are optional: nothing happens until you set one up and turn it on.
Fully user-controlled
Never changes a field your team owns on a record that already exists
Do you sell customer data?
No. Never. We don't sell, resell or profile your data, and we never will.
Do you support two-factor authentication (2FA)?
Yes, on every plan at no extra cost. Fibbler uses time-based one-time passwords (TOTP), so any standard authenticator app works. Workspace owners can also require 2FA for every member of a workspace. Full details are in the Authentication section below.
Do you have a security certification?
Yes. We're SOC 2 Type 1 compliant. Our auditor, Sensiba, went through our controls for security, availability and confidentiality and gave us a clean report in September 2026. The same audit checked us against the GDPR's data protection principles, and we passed that too. You can request the full report through our Trust Center. We've now started our SOC 2 Type 2 audit, together with ISO 27001. Google Cloud, our hosting provider, is SOC 2 Type II and ISO 27001 certified.
Do you run penetration tests?
Yes. Our latest penetration test was done by Atoro, an independent security firm, in June 2026, and we run one every year. On top of that we do our own security reviews and scan our code and infrastructure for vulnerabilities all the time.
Do you have an incident response or recovery plan?
Yes. We maintain internal policies for:
Business continuity
Incident response
Daily backups of stateful systems (like user accounts and settings)
If something breaks, we can restore customer-critical infrastructure within 24 hours. In the event of a personal data breach, we'll notify affected customers without undue delay and within 72 hours.
Authentication & 2FA
Sign-in is by email and password. Two-factor authentication is available to every user on every plan at no extra cost, and workspace owners can require it for their whole team:
Time-based one-time passwords (TOTP, RFC 6238). 6-digit codes on a 30-second rotation, working with any authenticator app such as 1Password, Google Authenticator, Microsoft Authenticator, or Authy. We do not use SMS or email codes as a second factor
With 2FA enabled, a password alone does not create a session. The session cookie is only issued once the code is accepted, and password resets do not bypass it
Sensitive actions require re-verification if more than two hours have passed. Sessions last a maximum of 7 days and are tracked server-side so they can be revoked centrally
Turning 2FA off requires a valid code and signs out every other session on the account. Password changes do the same
Workspace owners can require 2FA for every member of a workspace. The check runs server-side on every request in the app, so members without it are blocked from the workspace until they enable it
We do not offer recovery codes, SAML or OIDC single sign-on, or hardware security keys today. If you lose your authenticator device, email [email protected] and we will help you regain access
Infrastructure & Data Centers
We use Google Cloud to ensure high availability and security:
Google Cloud Platform (Primary Infrastructure)
One EU region (Belgium) for the app and the database
SOC 2 Type II certified
ISO 27001-certified data centers
GDPR compliant infrastructure
Immutable infrastructure and security by design
Fibbler uses Google Cloud Platform as its cloud provider; for more information about how Google manages security, read here.
We have conducted a Transfer Impact Assessment (TIA) as required by GDPR Article 46. All customer and application data is hosted within the EEA. This covers your ad platform data, your CRM data and everything you see in the Fibbler app. Four things are processed outside the EEA under appropriate safeguards (Standard Contractual Clauses or the EU-US Data Privacy Framework): support conversations in Intercom, marketing email in Loops, payment and billing details in Stripe, and the advertising tags on our marketing website. Some of the internal tools listed further down, such as Slack and GitHub, are US-based and covered by the same safeguards, but none of them holds your ad platform or CRM data.
Sub-processors
Fibbler uses the following sub-processors to deliver our services. Customer and application data is processed exclusively within the European Economic Area (EEA), unless otherwise stated below. This table is our authoritative list and matches the one published in our Trust Center.
Sub-processor	Location	Purpose	Data Processed
Google Cloud
(Cloud Run, Cloud SQL)	Belgium region (EU) (GDPR DPA, SOC 2, ISO 27001)	Primary infrastructure and database hosting	Application data, LinkedIn ads data, Google Ads data, Meta Ads data, CRM data
Amazon Web Services
(S3)	Frankfurt region, Germany (eu-central-1). This is our own direct use of AWS. Intercom separately runs on AWS in the US, see its row below	Static file storage behind cdn.fibbler.co	No customer files are stored here and Fibbler has no customer-facing upload feature. The bucket holds our own assets: the Fibbler logo used in emails, notice images uploaded by Fibbler staff, and public documents such as our security audit report. Because your browser and mail client load those assets, AWS receives request metadata including IP addresses in its access logs
Redis	Germany (EU)	Caching layer	Temporary cache data
Sentry	EU region, Frankfurt, Germany	Error monitoring and logging	Error logs and performance metrics
PostHog
(trust center)	EU Cloud	Product analytics for the Fibbler app (pageviews, signup/login, payment, integration connections, activation) and website analytics for fibbler.co (pageviews and attribution). No session recordings, heatmaps, or autocapture	Pseudonymous product events and user identification (ID, email, name)
Resend	Ireland (eu-west-1)	Transactional email delivery	Email addresses for account notifications only
Loops	US-based (EU-US Data Privacy Framework certified)	Marketing emails, announcements, updates	Email address and subscription status (active, trial, former customer) for email communications
Stripe	Ireland (Stripe Technology Europe, Limited, Dublin), with transfers to the US under Standard Contractual Clauses	Payment processing, invoicing and tax calculation	Billing contact name and email address, which we send when a subscription starts, plus the billing address, tax identifiers and payment card details that Stripe collects from you directly at checkout. We never see or store card details
Dealfront
(Dealfront Finland Oy / Leadfeeder)	EU (Finland/Germany) (ISO 27001, ISO 27701)	Website visitor company identification. Used on fibbler.co, and for your data only if you enable Google Ads or Meta Ads attribution	IP addresses, visitor behavior, session data, first-party cookies (if enabled)
Intercom	US, N. Virginia (Intercom hosts on AWS us-east-1) under Standard Contractual Clauses	Customer support inbox and conversation history. We use Intercom's AI agent, Fin, which reads the conversation to answer support questions, so Intercom passes that content to the AI model providers it lists as its own sub-processors	Name, email address and the contents of support conversations you have with us
Internal tools, and why they are not sub-processors
The list above covers the vendors that process your data on your behalf, where you are the controller and we are the processor. The vendors below are how we run Fibbler as a company. None of them touches your ad platform data or your CRM data. Where they hold personal data at all, such as your email address in a message you sent us, we are the controller of it and our Privacy Policy covers it rather than a data processing agreement. We list them for completeness because they appear in our vendor register. The 14 days' notice commitment above does not extend to them.
Vendor	Location	Purpose
Google Workspace
(Google Ireland Limited)	EU (Ireland)	Our business email, calendar and documents, and the identity provider for Fibbler staff accounts. Email you send us lands here, so it holds your contact details and whatever you wrote
Slack
(Salesforce)	US (EU-US Data Privacy Framework, Standard Contractual Clauses)	Our internal chat, and where automated operational alerts arrive. Those alerts carry workspace and user identifiers, and every email address in them is masked before it leaves our servers
GitHub	US (EU-US Data Privacy Framework, Standard Contractual Clauses)	Source control and code review
GitHub Dependabot	US (EU-US Data Privacy Framework, Standard Contractual Clauses)	Dependency vulnerability alerts
npm	US (GitHub / Microsoft)	Package registry we install build dependencies from
Jira
(Atlassian)	EU (EU-US Data Privacy Framework, Standard Contractual Clauses)	Internal issue and product tracking. Fibbler has no integration with Jira and no customer data is sent to it
Integrations you connect
Fibbler connects to the ad platforms and CRMs listed below. These are not sub-processors: each one already holds your data as your own system of record, and we only connect after you authorise us through that platform's own OAuth flow. Nothing is read until you connect the integration, and you can revoke access at any time from the Data sources page or from the platform itself. What we read and write in each one is listed in the sections above.
Ad platforms: LinkedIn Ads, Google Ads, Meta Ads
CRMs: HubSpot, Salesforce, Attio, Pipedrive
All sub-processors are bound by GDPR-compliant data processing agreements. We notify customers at least 14 days before we add or replace a sub-processor that processes customer data, and you may object to the change. We give that notice by publishing the change on this page and by email. This commitment applies to changes made after 28 September 2026, the date we baselined the list above. The change log at the end of this section records every change since. Dealfront (Leadfeeder) runs on fibbler.co, and on your own website only if you install the Fibbler tracking script for the Google Ads or Meta Ads add-on. PostHog is hosted on EU Cloud and is used both in the Fibbler app and on fibbler.co; on fibbler.co it operates in cookieless mode until you give consent, after which cookies and persistent identifiers are used. Our marketing website also uses the LinkedIn Insight Tag, the G2 tag and the Google Ads tag (gtag.js) for advertising measurement. The LinkedIn and G2 tags only load after you accept cookies. The Google Ads tag loads on every visit, but with Google's Consent Mode set to denied, so it sets no advertising cookies until you accept.
Change log
Last updated: 28 September 2026
Date	Change
28 September 2026	Baseline. We reviewed this page against our full vendor register and corrected it. Newly disclosed as sub-processors, both already in use before this date and neither newly engaged: Intercom and Amazon Web Services. Listed as internal tools instead, because they do not process your data on your behalf: Google Workspace, Slack, GitHub, GitHub Dependabot, npm and Jira. Removed the Google Ads API entry and added the "Integrations you connect" section instead, because the ad platforms and CRMs you connect are data sources rather than sub-processors. Recorded that Intercom's AI agent, Fin, is in use, and that support conversation content therefore reaches the model providers Intercom lists as its own sub-processors. Named a country and region for every row that previously said only "EU-hosted", and corrected the Stripe entry, which claimed no personal data was shared. The 14 days' notice commitment above applies to changes made after this date.
Technical & Organizational Measures (TOMs)
We apply the following technical and organizational measures (TOMs) to protect your data, account, and integrations. The measures below, together with the sub-processor list and infrastructure details on this page, are the reference for vendor and security reviews:
Controls independently audited for SOC 2 Type 1 (Sensiba, September 2026)
All data transfer and database connections encrypted using TLS
The database can't be reached directly from the internet. Access goes through Google's IAM-authenticated proxy, and only encrypted connections are accepted
Database accounts have minimal required permissions
All access is logged
Two-factor authentication (TOTP) available to all users and enforceable workspace-wide
Passwords hashed with bcrypt and checked against the Have I Been Pwned breached-password database
Rate limiting on all authentication endpoints
Real-time monitoring and alerting
Regular security updates and patches
Dependency scanning and vulnerability alerts
Backup data encrypted and stored separately
Annual third-party penetration testing (latest by Atoro, June 2026)
Only authorized personnel with specific business needs can access the database or production infrastructure. Authorized personnel may access production data to investigate a fault or answer a support request, and that access is logged.
Documents and DPA/NDA
Trust Center (SOC 2 Type 1 report, policies and sub-processors)
Privacy Policy
Terms of Service
Our Technical and Organizational Measures (TOMs) and full sub-processor list are documented in the sections above. We also offer a standard DPA (aligned with GDPR) and a Mutual NDA for vendor evaluation. Email [email protected] to request these or if you have any other security questions.