Third Party Index

Snapshot 61015

Document
Trust center
URL
https://www.cirrusinsight.com/trust
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
242665 bytes
SHA-256 (raw)
fc02ebf6331bc08c622b0271a0b5352861a15861d0cadb908623e64f8cdcd13e
SHA-256 (normalized text)
17749ceb907e853572d79b49192c557a2e5b750587fb290036a86e2139175b4f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Search Results for:
Trust & Security
You own the inbox. You own the CRM. You own the data.
Cirrus Insight works inside systems you already own. We hold that access to a simple standard: we take only the permissions a feature needs, we tell you exactly what we do with each one, and we never sell your data.
See our compliance posture → Privacy Policy
Attestation
SOC 2 Type I & II
Live status
status page →
Privacy
Privacy Policy →
Cookies
Cookie Policy →
Vendors
Subprocessors →
Section 01
Compliance & certifications
Each attestation below states what it covers, the period it covers, and who performed it.
SOC 2
SOC 2 Type I & Type II
Audited by Insight Assurance · Type I attested November 2024 · Type II period November 1, 2024 to October 31, 2025
Type I covered security, availability and confidentiality. The current Type II report covers the Cirrus Insight Sales Enablement Platform and the operating effectiveness of its security controls from November 1, 2024 to October 31, 2025. Reports available under NDA on request; bridge letters available on request.
CSA
STAR
CSA STAR Level One
Self-assessment · CAIQ v4.1.0 · Listed in the CSA STAR Registry September 30, 2026
We completed the Cloud Security Alliance’s STAR Level One self-assessment by answering the Consensus Assessments Initiative Questionnaire (CAIQ v4.1.0), which maps our security controls to the Cloud Controls Matrix. The completed questionnaire is public in the STAR Registry. Level One is performed by Cirrus Insight rather than an outside auditor; for independent attestation, see our SOC 2 Type II report above. View our STAR Registry listing →
ISO
27001
Infrastructure certifications
Held by our infrastructure providers, not by Cirrus Insight
Cirrus Insight runs on Microsoft Azure. Azure data centres are ISO/IEC 27001 certified and SOC 2 attested. Payment processing is handled by a PCI DSS compliant third party.
GDPR
GDPR & UK GDPR
Standard Contractual Clauses · UK Addendum
We act as processor for customer data. Transfers out of the EEA, UK and Switzerland rely on the EU Standard Contractual Clauses and the UK Addendum. Our DPA is available on request.
CCPA
CPRA
CCPA / CPRA
Service provider
We process personal information as a service provider under CCPA/CPRA. We do not sell personal information. See your rights for how to make a request.
Section 02
How we protect your data
Four pillars, all drawn from controls already described in our Privacy Policy.
Encryption
Data is encrypted in transit and at rest.
TLS with 256-bit encryption in transit
Transparent Data Encryption at rest
Automated masking of personal data
OAuth 2.0 — we never store your mail or CRM password
Access control
Least privilege, enforced and reviewed.
Employee access limited to job function
Need-to-know basis, reviewed on a defined cadence
Recurring privacy and security training
Support access only when providing live technical support
Infrastructure
Built on Microsoft Azure.
ISO 27001 certified, SOC 2 attested data centres
Data resides in North America where Cirrus is controller
Business continuity and disaster recovery
No device fingerprinting in logs
Testing
Audited independently, scanned continuously.
Regular manual and automated security audits
Incident Response Program, 72-hour notification
Continuous vulnerability scanning
Section 03
Privacy & your data rights
Cirrus Insight is a data processor for customer data and a controller for the information you give us directly. We do not sell personal information. Full detail lives in the documents below.
Privacy Policy
cirrusinsight.com/privacy · updated 20 July 2026
→
Cookie Policy
cirrusinsight.com/cookies
→
Submit a data request
Access, correction, deletion, portability
→
Your Privacy Choices
Opt out of sale or sharing · cookie preferences
→
Terms of Service
cirrusinsight.com/terms
→
Contact our DPO
privacy@cirrusinsight.com
→
Data Processing Addendum
Available on request — not yet published as a standard form
→
Subprocessor list
Published on our trust centre · app.drata.com
→
Section 04
Reliability
Live status is published independently of our own infrastructure, so it stays up when we don't.
98%
Standard contractual uptime baseline · up to 99.9% for enterprise
Live status
Every component — mail sync, calendar sync, tracking, scheduling, Buyer Signals — is monitored and reported at status.cirrusinsight.com. Subscribe there for incident notifications. For P1 issues, such as a total outage, we respond within one hour; other response targets depend on severity and your agreement.
Incident response
In the event of a data breach, Cirrus Insight activates its Incident Response Program: isolation of the event, notification to impacted individuals within 72 hours, a remediation plan and corrective action.
Section 05
Report a security issue
If you've found something, we want to hear about it. This is never gated and never requires a form.
Security issues affecting cirrusinsight.com or the Cirrus Insight applications can be reported to the address below. We investigate every report and will confirm receipt.
Email
privacy@cirrusinsight.com
Coordinated disclosure
Programme returning
Section 06
Frequently asked questions
Answered here, not behind a form.
Are you SOC 2 compliant, and can we see the report?
Yes — SOC 2 Type I and Type II, audited by Insight Assurance. Type I was attested in November 2024 covering security, availability and confidentiality. The current Type II report covers the security controls of the Cirrus Insight Sales Enablement Platform from November 1, 2024 to October 31, 2025. Reports are available under NDA on request, as are bridge letters. Email privacy@cirrusinsight.com.
Where is our data stored?
On Microsoft Azure. Where Cirrus Insight acts as data controller, all data collected resides exclusively in North America unless specifically noted otherwise. Where we act as data processor, location depends on the configuration your organisation selected.
Do you sell our data?
No. Cirrus Insight does not sell data to third parties and does not sell personal information. Some analytics and advertising activity on our public website may constitute "sharing" for cross-context behavioural advertising under California law — you can opt out via Your Privacy Choices.
How is our mail and CRM access authenticated?
Through OAuth 2.0. Cirrus Insight receives a token scoped to the permissions you grant and does not receive or store passwords for connected third-party services. Access never escalates beyond what the connected user's own permissions already allow.
Will you sign our DPA, or do you have your own?
We have a standard DPA incorporating the EU Standard Contractual Clauses and the UK Addendum, available on request from privacy@cirrusinsight.com. Publishing it as a downloadable standard form is in progress.
How will we know if you add a subprocessor?
We email Cirrus Insight admins when our subprocessors change. The current list is always published on our trust centre.
Running a security review?
Tell us what you need and we'll send it. SOC 2 reports and bridge letters go out under NDA, the DPA is available on request, and everything else on this page is already open.
Request review documents
Legal Privacy Policy Cookie Policy Cookie Settings Your Privacy Choices Terms Trust & Security
Features
Solutions
Resources
Company
© Copyright 2026 Cirrus Insight® All rights reserved
Raleigh, NC a Cirruspath, Inc. company
×
Ready to Close More Deals?