Available on: Any Gong plan
Ideal for: Security teams, legal teams, and procurement reviewers
All Gong trust and compliance documents are available through the Gong Trust Center. Some legal documents are also published directly on gong.io.
Compliance reports and assessments
The following reports are available to download from the Trust Center:
Trust Brochure: Security, Privacy & AI Whitepaper
SOC 2 Type II + HIPAA Report: Third-party attestation covering security, availability, confidentiality, privacy, and HIPAA security requirements
PCI DSS SAQ-D: Self-Assessment Questionnaire covering Gong's PCI DSS scope
Penetration test executive summary: Summary from Gong's independent penetration testing program
CAIQ: Cloud Security Alliance questionnaire
SIG Lite: Standardized Information Gathering questionnaire
Certifications
The following ISO certificates are available to download from the Trust Center:
ISO/IEC 27001: Information Security Management
ISO/IEC 27017:2015: Cloud Security
ISO/IEC 27018:2019: Cloud Privacy
ISO/IEC 27701: Privacy Management
ISO/IEC 42001:2023: AI Management
To learn more about each certification, see Gong compliance certifications and attestations.
Legal and privacy documents
Data breach notifications: available in the legal and privacy section of the Trust Center
Data Privacy Officer contact: available in the legal and privacy section of the Trust Center
Submit a security vulnerability
To report a security vulnerability, use Gong's Vulnerability Disclosure Program at vdp.gong.io. For general security questions, contact office.ciso@gong.io.