Security at SalesZipper AI

Your CRM data is among your most sensitive business assets. We treat it that way — with enterprise-grade security, independent audits, and zero-tolerance for data leaks.

SOC 2 Type IIAES-256 EncryptionTLS 1.3GDPR Ready

Our Approach

Security built into every layer

SOC 2 Type II

Independently Certified

Our platform undergoes annual SOC 2 Type II audits by an accredited third-party CPA firm. Reports are available under NDA upon request.

AES-256 Encryption

Data Encrypted at Rest

All customer data — including CRM exports, user information, and analysis results — is encrypted at rest using AES-256, the same standard used by financial institutions.

TLS 1.3 in Transit

End-to-End Encryption

All data in transit is protected by TLS 1.3 — the latest and most secure transport layer protocol — between your browser and our servers.

Access Controls

Role-Based Permissions

Strict role-based access controls (RBAC) ensure that team members only see the data they are authorized to view. All access is logged and audited.

Sandboxed Processing

Isolated Environments

CSV files and CRM data are processed in isolated, sandboxed environments. Your data never mingles with another customer's data.

Automatic Backups

Daily Encrypted Backups

All data is backed up daily to geographically separate data centers. Backups are encrypted and retained for 30 days.

🔐

Found a vulnerability?

We have a responsible disclosure program. Report security issues to us and we will acknowledge within 24 hours and reward valid critical reports.

security@saleszipper.ai

Security FAQ

Q.Where is my data stored?

Your data is stored on AWS infrastructure in the us-east-1 (N. Virginia) region. Backups are replicated to us-west-2 (Oregon). All storage is SOC 2 certified.

Q.Does SalesZipper AI store raw credit card information?

No. All payments are handled by Polar (our Merchant of Record). We never see or store your payment card details.

Q.How long is my CRM data retained?

Your CRM data is retained for as long as your account is active. Upon account deletion, all data is purged within 30 days. You can also request immediate deletion by contacting security@saleszipper.ai.

Q.Do you share my data with third parties?

We do not sell or share your CRM or opportunity data with third parties. We use trusted sub-processors (e.g., AWS, Vercel) bound by data processing agreements, solely to operate the Service.

Q.How do I report a security vulnerability?

Please disclose any security vulnerabilities responsibly to security@saleszipper.ai. We will acknowledge receipt within 24 hours and aim to resolve critical issues within 7 business days.