Snapshot 74357
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Trust Center Compliance engineered for the Cloud HowardCRM holds its own HIPAA and SOC 2 Type II attestations. It also runs on the Salesforce platform, which carries an extensive set of certifications of its own. Both matter to your agency, but they are not the same thing, so we list them separately below. HowardCRM Platform-Specific Credentials Our certifications are the result of rigorous, independent third-party testing and analysis to ensure our platform meets or exceeds current industry security standards. Our SOC 2 Type II report is available under NDA. Request a copy. Why this matters for your book of business You handle protected health information every day, and the CRM you keep it in is part of your compliance posture rather than separate from it. We wrote about what agents should actually check in HIPAA and your Medicare CRM, and the features page covers what the system does with the data it protects. Salesforce Industry Standard Credentials HowardCRM is built on Salesforce. The certifications below belong to Salesforce’s infrastructure and apply to HowardCRM because we run on it. They are not audits of HowardCRM itself. ASIP Santé HDS Enables certified companies to host French personal health data ASP/SaaS Information Disclosure Certification System for organizations in Japan C5 (ISAE 3000) ISAE 3000 Report on the Cloud Computing Compliance Controls Catalogue (C5) CS Gold Mark CS Gold Mark certifies our security level to be equivalent to the ISO/IEC 27017 standard Disaster Recovery & BCP Business Continuity and Disaster Recovery DoD IL2 Cloud computing security requirements for the US Department of Defense for Impact Level 2 DoD IL4 Cloud computing security requirements for the US Department of Defense for Impact Level 4 External Security Assessments Attestation of penetration tests and security assessments performed by third parties FedRAMP High U.S. government program providing a standard approach to security, authorization and monitoring FedRAMP Moderate U.S. government program providing a standard approach to security, authorization and monitoring Financial Services Compliance How Salesforce helps support financial service institutions with regulatory requirements GDPR How Salesforce helps support our customers on their GDPR compliance journeys HIPAA U.S. Privacy requirements for personal health information held by covered entities HITRUST Comprehensive, flexible and efficient approach to regulatory compliance and risk management IRAP Security assessment for Australian government customers IRS 1075 U.S. government program providing guidance to protect the confidentiality of Federal Tax Information (FTI) ISMAP Japanese government program to assess and register cloud services that meet government security requirements ISO 27001 Compliance with specific information security and risk management requirements ISO 27017 Adherence with ISO/IEC 27002 Code of Practice controls for cloud services ISO 27018 Adherence with Code of Practice controls for protection of personal information NEN 7510 Protecting health information for organizations in the Netherlands NIST SP 800-171 U.S. security requirements for protecting Controlled Unclassified Information in Nonfederal Systems and Organizations PCI DSS Validation of controls around cardholder data to reduce credit card fraud PrivacyMark Privacy-centric certification for organizations in Japan Privacy Shield A framework for complying with EU General Data Protection Regulation (GDPR) requirements Salesforce BCRs Binding Corporate Rules for the Processing of European Personal Data SOC 1 Type II report covering internal controls over financial reporting systems SOC 2 Type II report covering Security, Availability, Integrity, Confidentiality, and Privacy SOC 3 Public report of Security, Availability, Integrity, Confidentiality, and Privacy controls Standard Questionnaires, FAQ's and Whitepapers Standardised questionnaires from industry groups, answers to common questions and white papers TRUSTe APEC Processor Seal Asia-Pacific Economic Cooperation Privacy Recognition for Processors Certification TRUSTe Privacy Verified Seal Responsible data collection and processing practices consistent with regulatory expectations UK Cyber Essentials Plus UK government information security assurance scheme