Third Party Index

Snapshot 64755

Document
Trust center
URL
https://competeiq.io/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
55171 bytes
SHA-256 (raw)
cae102969527a31ed328a235f3eb1f88f16c22fab580aad20739df5bf9ce7bdc
SHA-256 (normalized text)
f785de42536fb5c423ea777732f5881083d179f6edc3b2d77b23bf59d3967a6c

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
Security & Trust
CompeteIQ is designed to meet enterprise security expectations. We take the protection of customer data seriously and maintain security practices appropriate to the sensitivity of the information we handle.
Hosted on Microsoft Azure
Encryption in transit and at rest
Azure infrastructure independently audited (SOC 2 Type II)
Regular backups with redundancy
Automated alerting and operational monitoring
SSO and MFA supported
Security Overview
CompeteIQ maintains a security program informed by ISO 27001 principles and OWASP best practices. Our platform is hosted exclusively on Microsoft Azure infrastructure, which is independently audited, including SOC 2 Type II.
We conduct periodic third-party penetration testing, maintain vulnerability scanning, and follow secure development practices across our engineering team.
Key Commitments
CompeteIQ does not sell customer data.
Access to customer data is restricted to authorized personnel for authorized purposes.
Team members complete security awareness training.
Additional security documentation is available under NDA upon request.
Data Protection
Data in transit is encrypted using TLS 1.2+. Data at rest is protected using encryption provided by the Azure platform, including Transparent Data Encryption (TDE).
Customer data is logically separated at the application and database layers. We enforce role-based access controls and maintain audit logs for data access events.
Authentication
Supports SSO via SAML 2.0 and MFA. SSO is the recommended authentication method for enterprise customers.
Data Retention
Customer data retention and deletion are handled in accordance with the terms of the applicable Master Service Agreement and contractual commitments.
Availability & Resilience
CompeteIQ is hosted on Microsoft Azure with infrastructure distributed across US data centers. Backups and redundancy measures are in place to support business continuity.
Infrastructure Details
Hosting
Microsoft Azure, United States
Backups
Regular automated backups with redundancy
Monitoring
Automated alerting and operational review
Planned Maintenance
Scheduled with advance customer notice
Incident Response
CompeteIQ maintains an incident response plan as part of our business continuity and data security program. In the event of a security incident affecting customer data:
1.Affected customers are notified in accordance with applicable law and contractual commitments.
2.Status updates are provided during active incidents as part of our standard response procedures.
3.Post-incident reports are available to affected customers upon request.
4.Root cause analysis and remediation steps are documented internally.
AI Usage Statement
CompeteIQ uses artificial intelligence to power competitive analysis features including automated intelligence gathering, competitor signal detection, and insight generation.
AI Governance Summary
Customer Data: CompeteIQ does not use customer data to train or fine-tune AI models. AI features process data only to deliver results to the customer who owns that data.
Human Oversight: AI-generated outputs are designed to assist human decision-making, not replace it. Users maintain control over how AI insights are applied.
Third-Party Models: Where third-party AI services are used, data is processed under contractual terms that prohibit model training on customer data.
Change Notification: Material changes to AI capabilities or data processing practices are communicated to customers in advance.
For our full AI policy, see the AI Policy page.
Responsible Disclosure
CompeteIQ welcomes responsible disclosure of security vulnerabilities. If you believe you have discovered a vulnerability in our platform, please report it so we can address it promptly.
Disclosure Guidelines
Email your findings to info@competeiq.io with "Security Disclosure" in the subject line.
Include a clear description of the vulnerability and steps to reproduce.
Allow reasonable time for investigation and remediation before public disclosure.
Do not access, modify, or delete customer data during testing.
We will acknowledge receipt within 2 business days and provide a resolution timeline.
A machine-readable version of this policy is available at /.well-known/security.txt.
Frequently Asked Questions
CompeteIQ is built on the principle of data minimization. The most secure data is the data that never leaves your environment. Below are the questions security teams ask us most often.
Does CompeteIQ use OAuth tokens to access my Salesforce data?
No. CompeteIQ uses secure API private key integration instead of OAuth tokens. This removes the risk associated with OAuth token compromise — a common attack vector in modern SaaS integrations.
Does CompeteIQ "pull" or "scrape" data from my CRM?
No. We operate on a Push-Only Methodology: CompeteIQ pushes competitive intelligence into your CRM. We do not pull broad data sets, which means our integration cannot be used to scrape or access unauthorized business records.
Is my CRM data ever copied into CompeteIQ's systems?
No. We follow a Zero-Extraction Policy — we do not pull sensitive CRM data into CompeteIQ. Your business intelligence stays protected within your own systems. The most secure data is the data that never leaves your environment.
Where does competitive reporting actually run?
All competitive reporting occurs natively within your Salesforce instance. CompeteIQ provides the insights; you retain full custody of the data at all times.
Security Contact
For security inquiries, vendor questionnaires, or to request documentation for your security review:
info@competeiq.io
For vulnerability reports, vendor security assessments, and compliance documentation requests.
Additional security documentation is available under NDA upon request.
See also: Terms of Service | Privacy Policy | AI Policy