// Security
Security and privacy, built into every layer
Data privacy and security is embedded in every part of our business. Visit our Security Portal for the detail on the frameworks, regulations, and certifications that apply to our company and its products.
Multiple layers of protection
- SOC 2 Type 2, ISO 27001, GDPR and CCPA compliant
- Single Sign-On (SSO) included
- Data privacy and encryption at rest and in transit
- Ongoing penetration testing
// How we protect your data
The practices behind the certifications
01
Database security
We host your data in its own secure PostgreSQL database. Database access is limited to a small number of authorized engineers, for technical purposes only, through VPN servers and two-factor authentication.
02
Logical security
Each tenant is hosted in a separate database instance. All in-transit data is encrypted with 256 bit SSL, and all our operations run on Google Cloud Platform and Kubernetes.
03
Physical security
We follow the Google security model. All our operations run on Google Cloud Platform and Kubernetes, and backups are stored on Google Cloud Storage.
04
Encryption
We encrypt sensitive data both at rest and in transit over public networks. All in-transit data is encrypted with 256 bit SSL.
05
Data privacy
We only use customer data to provide our services. We do not share it with any third party, and we never use it for marketing purposes.
06
Data ownership
Your data is yours, 100%. We won't delete data within your account without informing you and giving you time to export it.
07
Data usage
We don't mine or access your data for commercial purposes, and only access it to provide our services.
08
Salesforce security review
Chili Piper has successfully completed the Salesforce.com Security Review.
09
Integrated services
We use OAuth tokens that are stored using native encryption.
10
Data recovery
We regularly back up your data and provide a maximum 12-hour RTO and RPO.
11
Privacy and safety features
We offer you the ability to control privacy impacting features.
12
Penetration testing
We run ongoing penetration testing, and our software is developed using OWASP secure coding practices with verification by independent auditors.
// Certifications
Audited, certified, and independently verified
- SOC 2 Type 2
- Audited controls for security, availability, and confidentiality, verified by an independent auditor.
- ISO 27001
- Certified information security management across our systems and processes.
- GDPR
- We have taken the necessary measures to be GDPR compliant. See Exhibit A of our terms and conditions for the detail.
- CCPA
- Compliant with the California Consumer Privacy Act, including how personal information is collected and shared.
Reports, policies, and the current status of every control live in our Security Portal. trust.chilipiper.com ↗
// Security Portal
Everything a security review needs
Our controls are monitored continuously and published in the portal, alongside the documents most questionnaires ask for.
- Security policies
- Information Security Policy, Incident Response Plan, Secure Development Policy, Asset Management, Data Management, and the rest of our policy set.
- Penetration test report
- Our most recent third-party penetration test, available on request along with the SOC 2 and ISO 27001 reports.
- Continuously monitored controls
- Infrastructure, organizational, product, and internal security controls, each monitored continuously rather than checked once a year.
- Subprocessors and data handling
- The current subprocessor list, including Google Cloud Platform for app hosting and AWS for website hosting, plus our data retention and deletion procedures.
- Continuity and insurance
- Business continuity and disaster recovery plans, tested on a schedule, and maintained cybersecurity insurance.
Frequently asked questions
Who owns the data we store in Chili Piper? Will you use our data to build advertising products?
As a Chili Piper customer, you own and control your data. Your calendar and Salesforce remain a system of record. We do not use your data for anything other than providing you with the service to which you have subscribed.
Do you offer privacy controls in your service?
We commit to a number of privacy and security measures in the data processing terms of your agreement.
Where is our data stored?
Chili Piper servers are currently hosted in multiple Google Cloud servers across the United States.
Is our data encrypted?
Yes. Sensitive customer data is encrypted at rest and when traversing over public networks, using 256 bit SSL in transit.
What is your approach to security and which security features do you offer to protect your service from external attacks?
Security is one of the most important design principles and features of Chili Piper. Our focus on security spans hardware, software development using OWASP secure coding practices, policies and controls, and verification by independent auditors. When it comes to security features, there are broadly two categories: built-in security and customer controls. Built-in security represents all the measures that we take on behalf of all our customers to protect your information and run a highly available service. Customer controls are features that enable you to customize Chili Piper to meet the specific needs of your organization.
Can we get our data out of your service?
You own your data and retain all rights, title, and interest in the data you store with Chili Piper. During and for 30 days after your subscription, you may migrate your data at any time and for any reason, without assistance from Chili Piper.
Will you inform us when things change in the service, and will you let us know if our data is compromised?
We do inform you if there are any important changes to the service with respect to security, privacy, and compliance. This information is delivered via our in-app notification system. We also promptly notify you via email if your data has been accessed improperly.
Are you transparent with the way you use and access our data?
We share important aspects of data storage, such as where your data resides geographically, who at Chili Piper can access it, and what we do with that information internally. The data processing terms of your agreement also cover how we are allowed to use your data in detail. Access to customer data is strictly controlled and logged, and sample audits are performed by both Chili Piper and third parties to attest that access is only for appropriate business purposes.
What kind of commitments do you have with respect to security and privacy?
Chili Piper includes data processing terms in our customer agreements. We are also attached to an EU Data Protection Addendum, including model clauses, through Google Cloud.
How do you ensure that your service is reliable?
We apply best practices in design and operations, such as redundancy, resiliency, distributed services, and monitoring, to name a few.
Is our data backed up? Are there disaster recovery tools in place?
All data you store in Chili Piper is fully backed up with tested and certified disaster recovery processes in place. The backup of data and disaster recovery is handled by Chili Piper. Our current RTO and RPO times are within 12 hours.
How do you connect with Salesforce?
Chili Piper connects to Salesforce via a secure API integration. Our help center documents the full Chili Piper data flow.
Where can I report incidents?
Report security incidents to security@chilipiper.com. For general product support, contact support@chilipiper.com.
Still have a security question?
Our team answers security reviews and questionnaires directly. For anything urgent, write to security@chilipiper.com.