Documentation Index

Fetch the complete documentation index at: https://help.gong.io/llms.txt

Use this file to discover all available pages before exploring further.

Gong compliance certifications and attestations

Prev Next

Available on: Any Gong plan

Ideal for: Security teams, legal teams, and procurement reviewers

This article describes Gong's compliance certifications and attestations. All certificates and reports are available to download from the Gong Trust Center.

ISO certifications

ISO/IEC 27001: ISO 27001 is a globally recognized, standards-based approach to security that outlines requirements for an organization's Information Security Management System (ISMS).

ISO/IEC 27017:2015: This standard provides guidelines on how we implement information security controls for the provision and use of cloud services.

ISO/IEC 27018:2019: This standard protects personally identifiable information (PII) in public clouds that act as PII processors. This further extends our ability to safeguard the personal and customer data we collect, process, and manage on your behalf.

ISO/IEC 27701: ISO 27701 is a globally recognized, privacy-based certification that builds upon security requirements outlined in ISO 27001 with emphasis on an organization's Privacy Information Management System (PIMS).

ISO/IEC 42001:2023 (AI Management): ISO 42001:2023 validates: Organizational AI Governance, Ethical AI System Design, Responsible AI Use & Development, Trusted Data Practices, and AI Risk & Impact Assessments.

SOC 2 Type II + HIPAA

Gong maintains our own SOC 2 Type II report with scope that spans Gong operations. The independent assessment affirms our commitment to customer data security, availability, confidentiality, and privacy. Gong's report also includes a mapping to Health Insurance Portability and Accountability Act (HIPAA) security requirements.

PCI DSS

Gong has created the mechanisms that ingest and process calls from external telephony systems in a way that is PCI-DSS compliant. Gong maintains a specific scope for PCI DSS that analyzes the calls, identifies the PCI-related data, and redacts digits set forth by customer business rules. The SAQ refers to these components and attests to the needed measures that have been taken to ensure it is compliant with PCI-DSS.

To learn more about Gong's PCI DSS scope and customer responsibilities, see Gong PCI DSS scope and responsibilities.

EU-US Data Privacy Framework

Gong is certified with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). See our public DPF profile.

CSA STAR

We documented our cloud security controls at Gong for the CSA's Security, Trust, Assurance, and Risk (STAR) Registry. Download our completed CAIQ questionnaire from the Trust Center.