---
title: "Gong security, privacy, and compliance controls"
slug: "summary-of-security-features"
updated: 2026-07-29T10:16:59Z
published: 2026-07-29T10:16:59Z
canonical: "help.gong.io/summary-of-security-features"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.gong.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Gong security, privacy, and compliance controls

> **Available on**: Any Gong plan
> 
> **Ideal for**: Security teams, legal teams, and procurement reviewers

This article summarizes Gong's platform-level security controls, compliance certifications, and privacy practices. It is the primary reference for security reviews and procurement assessments.

For downloadable certificates and reports, see [Access Gong security and privacy documents](/v1/docs/access-gong-security-and-privacy-documents). For admin configuration of data capture, privacy, and consent settings, see the **Data capture, protection, and privacy** category in Configuring Gong.

## AI management

**ISO 42001:2023** validates:

- Organizational AI Governance
- Ethical AI System Design
- Responsible AI Use & Development
- Trusted Data Practices
- AI Risk & Impact Assessments

Download our ISO certificate from the [Trust Center](https://trust.gong.io). For Gong's broader AI trust practices, see the Artificial Intelligence section at [trust.gong.io](https://trust.gong.io).

## Security certifications and compliance reports

For a detailed overview of each certification, see [Gong compliance certifications and attestations](/v1/docs/review-gong-compliance-certifications-and-attestations).

- **ISO 27701:** ISO 27701 is a globally recognized, privacy-based certification that builds upon security requirements outlined in ISO 27001 with emphasis on an organization's Privacy Information Management System (PIMS).
- **ISO 27001:** ISO 27001 is a globally recognized, standards-based approach to security that outlines requirements for an organization's Information Security Management System (ISMS).
- **ISO 27017:** This standard provides guidelines on how we implement information security controls for the provision and use of cloud services.
- **ISO 27018:** This standard protects personally identifiable information (PII) in public clouds that act as PII processors. This further extends our ability to safeguard the personal and customer data we collect, process, and manage on your behalf.
- **EU-US Data Privacy Framework (DPF):** Gong is certified with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). See our [public DPF profile](https://www.dataprivacyframework.gov/list).
- **CSA STAR:** Learn about Gong's cloud security controls, as documented in the [Cloud Security Alliance (CSA) STAR Registry](https://cloudsecurityalliance.org/star/registry/gong/services/gong/).
- **SOC 2 Type II + HIPAA:** Gong maintains our own SOC 2 Type II report with scope that spans Gong operations. The independent assessment affirms our commitment to customer data security, availability, confidentiality, and privacy. Gong's report also includes a mapping to Health Insurance Portability and Accountability Act (HIPAA) security requirements.
- **PCI DSS:** Gong has created the mechanisms that ingest and process calls from external telephony systems in a way that is PCI-DSS compliant. Gong maintains a specific scope for PCI DSS that analyzes the calls, identifies the PCI-related data, and redacts digits set forth by customer business rules. For full scope details and customer responsibilities, see [Gong PCI DSS scope and responsibilities](/v1/docs/pci-dss-compliance).
- **Penetration testing:** Gong obtains independent validation security with third-party penetration testing.

## Data security

- **Data encryption:** Customer data is encrypted in transit using at least TLS 1.2 and at rest using AES-256.
- **Key management:** Gong leverages the cloud provider's native key management service.Customers can encrypt their own data using bring your own key (BYOK). Learn more about [setting up data encryption in Gong](/v1/docs/set-up-for-data-encryption).
- **Data segregation:** Customer data is logically separated within Gong's multi-tenant environment, consistent with common SaaS practices.
- **Data retention:** Data retention is determined by the customer and can be configured at any time. Learn more about [managing data retention in Gong](/v1/docs/data-retention-policy).
- **Information redaction:** Gong offers optional numerical and PHI redaction capabilities to help protect sensitive information in call recordings and transcripts. Numeric redaction replaces digit sequences that meet a customer-defined threshold with (REDACTED), while PHI redaction removes supported personal identifiers. Redacted transcript content is replaced with (REDACTED) and the corresponding audio is muted. PHI redaction is currently available for English-language calls. Learn more about [redacting sensitive information in Gong](/v1/docs/redact-sensitive-information).
- **Data deletion:** Gong provides multiple ways of deleting data from the tenant environment and provides tools for the customer to meet DSAR requests. Learn more about [deleting personal data from Gong](/v1/docs/delete-personal-data).

## Identity and access management

- **Provisioning:** Gong supports a system for single or cross-domain Identity Management (SCIM) provisioning systems.
- **Single sign-on:** Gong supports authentication through common Identity Providers, such as Google, Microsoft (Entra ID Active Directory and Office 365), and Salesforce. Gong also supports SAML 2.0-based SSO, OAuth 2.0 authorization, and OpenID Connect, including Okta, OneLogin, Rippling, and custom providers.
- **Password policy:** Our preference is for our customers to use their Single Sign On (SSO) to inherit the rules associated with their password policy. For non-SSO users, Gong supports authentication, which enforces the following password requirements: minimum of eight characters, at least one number, at least one special character, cannot contain part of the username, cannot reuse the last four passwords.
- **Session management:** Gong supports session management for inactivity. For username/password and SAML authentication, the default timeout is 30 minutes (configurable for SAML). For identity providers such as Google, Microsoft, Salesforce, or Okta OpenID Connect, the identity provider controls the session timeout policy.
- **API authentication:** There are two ways to retrieve credentials to the Gong Public API: Basic Authorization, which requires manually obtaining an Access Key and Access Key Secret; OAuth, which generates a Bearer Token.
- **Workspaces:** You can set up workspaces in Gong to segment your Gong instance to match your business needs. This feature helps enforce principles of least privilege within your business users. This is useful if you have separate business units or geographic regions (such as offices in the United States and in EMEA), where you may want to apply different business settings, permissioning, or retention policies. Creating separate workspaces allows you to easily manage different settings between distinct business groups.
- **User roles:** Gong provides four out-of-the-box user roles that can be configured for granular permissioning: Collaborator, Standard user, Business administrator, and Technical administrator.
- **Role-based access control:** In addition to standard user roles, Gong supports granular permission profiles. Create granular permission profiles to restrict access and actions related to: calls, emails, call libraries, deals, coaching and stats pages, forecast, CRM, and exporting. Access can be restricted on an individual, team, or custom basis. Note: This is separate from consent profiles.
- **Call access controls:** Gong provides multiple options to manage access to calls. Through granular permission profiles, a technical admin can restrict access to calls, such as: determining whether users can download call media, restricting whether calls can be shared with customers, allowing users to set calls as private, letting users delete calls, and restricting whether users can export reports on calls.
- **Access to customer data:** Gong restricts and limits access to customer data to authorized personnel on a need-to-know basis. Access of customer data by Gong personnel through the Gong platform can be audited in the Audit API.

## Auditing and monitoring

Gong customers may audit both the use of the platform by their personnel as well as access of the platform by Gong personnel for troubleshooting or customer support. The Gong Audit API can be used to generate this data in standard JSON format, which can be used to feed your existing security monitoring tools.

## Data backup and recovery

- **Cloud hosting:** Gong is a SaaS application hosted in cloud infrastructure.
- **Backups and recovery:** Gong conducts regular daily backups of customer data. The backups are applied to keep the Gong environment resilient to outages or cases where we needed to recover customer data. Gong's Recovery Time Objective (RTO) and Recovery Point Objective (RPO) are each 24 hours.

## Privacy and compliance

- **Data Processing Addendum (DPA):** Gong's DPA sets out the terms that apply with regard to the Processing of Personal Data by Gong on behalf of Customers, in the course of providing the Gong Service to Customers under the Agreement. See our [Data Processing Addendum](https://www.gong.io/data-processing-addendum/).
- **Privacy policy:** You can find our privacy policy at [gong.io/legal/privacy-policy](https://www.gong.io/legal/privacy-policy/).
- **Sub-processors:** You can find our list of sub-processors at [gong.io/legal/sub-processors](https://www.gong.io/legal/sub-processors/). We recommend subscribing to stay up to date on any changes that may occur.
- **Right to be forgotten:** Gong provides mechanisms within the platform interface and Gong API to delete personal data upon request to observe DSAR requests.
- **Consent profiles:** You can create different consent profiles for different teams. Consent profiles are separate from permission profiles, and enable you to enforce multiple streams of consent based on different geographic or state privacy regulations.
- **Voice identification:** Voice identification can be enabled to identify licensed Gong users in mono telephony calls. This function is disabled by default. Technical administrators can enable this function for licensed Gong users, who must also consent to the function.

## Vulnerability management

Gong has a robust vulnerability management program that is validated as part of our SOC 2 and ISO certifications.

Gong runs an ongoing bug bounty program, as well as a Vulnerability Disclosure Program. You can submit vulnerabilities through [vdp.gong.io](https://vdp.gong.io).

## Additional security controls

Please see the [Gong Trust Center](https://trust.gong.io) for an overview of the Gong security and privacy program.

Access to this feature depends on your [assigned seat](/v1/docs/plans-and-seats).
