CRM · Security & Compliance

CRM Security & Compliance Guide

Your CRM holds your most sensitive asset: your customers' personal data. This is the plain-English guide to keeping it safe and legal — what the security badges actually mean, what to verify before you sign, and which of the CRMs we rank document each protection. No jargon left unexplained.

Reviewed by · Updated June 2026· How we vet

Why this is the criterion buyers underweight

Most CRM shopping is about pipelines, automations and price. Security feels like a box already ticked — every vendor's site says "enterprise-grade security," so people move on. That is exactly the mistake. A single breach or a mishandled data-deletion request can cost more than years of subscription savings, and the protections you need are not all switched on by default. Security and compliance is one of the five weighted criteria in our methodology, and this guide is where we make it visible.

The key idea to hold onto is that compliance is shared. The vendor gives you a certified, well-built platform; you are responsible for how you set it up and who you let in. So your job as a buyer is two-part: verify what the vendor genuinely provides, then configure your side properly. We will take each in turn, defining every term as we go.

The badges, in plain English

What to verify before you buy

SOC 2
An outside audit of their security controls

SOC 2 is a report, common in the United States, where an independent firm checks that the security practices a vendor claims are real and working. Ask specifically for the "Type II" report — it covers a stretch of months, not a single inspection day, so it is far harder to stage. If a vendor cannot share one under a non-disclosure agreement, treat that as a warning.

ISO 27001
An international security-management certificate

ISO 27001 is a globally recognised certificate showing the vendor runs a formal, audited system for managing information security — policies, risk reviews, staff training, the lot. Where SOC 2 is the American reference point, ISO 27001 is the international one. The strongest vendors hold both. For a tool that will store your customers' data, the absence of either is a real concern.

GDPR & the DPA
The contract for handling EU personal data

GDPR is the European data-protection law that applies if you hold data on people in the EU or UK — and many US firms do without realising it. The practical thing to get is a DPA, a Data Processing Agreement: the contract where the vendor commits to process that data lawfully, host it in the right region, and help you with data-subject requests such as access and deletion. Confirm EU-region hosting if your customers are European.

HIPAA & the BAA
Only relevant if you store patient health data

HIPAA is a US healthcare law covering PHI — Protected Health Information, meaning data that identifies a patient and relates to their health. If your CRM will hold any, you need the vendor to sign a BAA, a Business Associate Agreement in which it shares legal responsibility for that data. This is the sharpest dividing line in CRM compliance: many excellent, fully SOC 2-certified CRMs will not sign a BAA, or only on a specific higher edition. Never assume — confirm it in writing for your exact plan.

Encryption & access
The everyday protections that do the real work

Two basics belong on every shortlist. Encryption "in transit and at rest" simply means your data is scrambled both while travelling to the CRM and while sitting on its servers, so a thief gets gibberish. And single sign-on with two-factor login plus role-based permissions — letting you control exactly who sees what — is how you stop the most common breach of all, which is a careless or compromised internal account. All seven CRMs we rank provide these; the difference is how granular the controls get.

How our ranked CRMs document it

The compliance matrix

Here is where each of the seven CRMs in our CRM ranking stands on the four contracts and certificates that matter, verified as of June 2026. Read the HIPAA column especially carefully: a tick means a BAA is available, a tilde means only on a specific higher edition or on request, and a dash means no BAA — so it cannot lawfully hold patient health data. Editions and policies change often; always confirm the current position in writing for your exact plan.

CRM SOC 2 ISO 27001 GDPR / DPA HIPAA BAA
HubSpot
Pipedrive
Zoho CRM
Salesforce
Freshsales
monday CRM
Microsoft Dynamics 365

✓ available  ·  ∼ on a specific edition or on request  ·  — not offered. Verified June 2026 from vendor compliance documentation; confirm the current position for your exact plan before relying on it.

Green flags and red flags

What to look for, and what to walk away from

Green flags
+A public trust or security page listing SOC 2 and ISO 27001, with the reports available under an NDA
+A ready DPA and a choice of data-hosting region you can sign without a sales fight
+Granular role-based permissions, audit logs, and single sign-on with two-factor login
+If you handle PHI: a clear, written BAA for the exact edition you are buying
Red flags
"Enterprise-grade security" as a slogan with no certificate, report or detail behind it
A vendor that calls itself "HIPAA compliant" but will not actually sign a BAA — the badge is meaningless without it
No way to delete or export a contact's data on request, which makes a GDPR deletion request impossible to honour
Everyone is an admin: no role controls, so any account can see or export the entire database
Common questions
What is the difference between SOC 2 and ISO 27001?

Both are independent proofs that a vendor takes security seriously. SOC 2 is an audit report, mostly used in the United States, where an outside firm checks that the controls a vendor claims to have are actually in place — ask for the Type II report, which covers a period of months rather than a single day. ISO 27001 is an international certificate showing the vendor runs a formal information-security management system. Seeing both is reassuring; seeing neither is a red flag for a tool holding customer data.

Does a CRM being SOC 2 certified make me HIPAA compliant?

No. SOC 2 is about general security; HIPAA is a specific US healthcare law for Protected Health Information. To store PHI you need the vendor to sign a BAA — a Business Associate Agreement in which it accepts legal responsibility for that data. Many strong, SOC 2-certified CRMs will not sign a BAA, or only do so on specific higher-tier editions. Verify the BAA in writing for your exact plan before putting any patient data in the CRM.

Which of the CRMs you rank can sign a HIPAA BAA?

As of mid-2026: Zoho CRM and Microsoft Dynamics 365 offer a BAA; HubSpot and Salesforce offer one on specific higher tiers (HubSpot Enterprise with Sensitive Data settings; Salesforce on Health Cloud and select editions); Pipedrive does not offer a BAA. Freshsales and monday CRM may offer HIPAA support on certain plans but you must confirm it directly. Editions and policies change, so always get the current position in writing.

If the vendor is compliant, am I automatically compliant?

No, and this is the most expensive misunderstanding. Compliance is shared. The vendor provides the certified platform, encryption, a Data Processing Agreement and region hosting; you are responsible for how you configure it — who can see records, how long you keep data, how you capture consent, and how you handle deletion requests. A compliant CRM set up carelessly is still a breach waiting to happen.

Get the CRM shortlist

One email when the rankings move. The shortlist, the tradeoffs, the compliance changes. No filler.