{
 "name": "HelpCompare security, offline and remote-work dataset",
 "license": "CC BY 4.0",
 "publisher": "HelpCompare",
 "url": "https://helpcompare.com/security/",
 "generated": "2026-09-19",
 "notes": "Each value was recorded from the vendor's own website on the checked date. src = the page, q = the verbatim sentence. A null value means the vendor did not state it on its site, not that the feature is absent.",
 "tools": [
  {
   "slug": "1password",
   "name": "1Password",
   "category": "Password Managers",
   "checked": "2026-09-19",
   "scope": "1Password password manager, Teams Starter Pack and Business plans; Enterprise/Unified Access products not researched.",
   "profile_url": "https://helpcompare.com/tools/1password/#security-offline-remote",
   "trust_center": "https://1password.com/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://1password.com/pricing/business",
     "q": "Meet industry standards with SOC 2 Type II certification"
    },
    "iso27001": {
     "v": true,
     "src": "https://1password.com/resources/iso27001",
     "q": "1Password has achieved ISO 27001:2022, 27017:2015, 27018:2019, and 27701:2019 certifications"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701"
     ],
     "src": "https://1password.com/resources/iso27001",
     "q": "1Password has achieved ISO 27001:2022, 27017:2015, 27018:2019, and 27701:2019 certifications"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": true,
     "plan": "Business",
     "src": "https://support.1password.com/sso/",
     "q": "Be in the Owners or Administrators group in your 1Password Business account"
    },
    "scim": {
     "v": true,
     "plan": "Business",
     "src": "https://support.1password.com/scim/",
     "q": "With 1Password Business, you can automate many common administrative tasks by connecting your identity provider with your 1Password account using 1Password SCIM Bridge."
    },
    "mfa": {
     "v": true,
     "enforce": "Business",
     "src": "https://support.1password.com/manage-two-factor-authentication/",
     "q": "Choose which two-factor authentication methods are allowed and enforce two-factor authentication for everyone."
    },
    "audit_log": {
     "v": true,
     "plan": "Business",
     "src": "https://support.1password.com/activity-log/",
     "q": "The audit log is only available in 1Password Business."
    },
    "data_residency": {
     "v": [
      "US",
      "CA",
      "EU"
     ],
     "src": "https://support.1password.com/regions/",
     "q": "Secure data hosted in: United States ... Secure data hosted in: Canada ... Secure data hosted in: European Union"
    },
    "encryption": {
     "v": "End-to-end AES 256-bit encryption; Two-Key Derivation (account password + Secret Key); SRP protocol in transit",
     "src": "https://1password.com/pricing/business",
     "q": "Protect all vaults, URLs, and data with end-to-end AES 256-bit encryption"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "Items synced to a device stay available in the 1Password apps while offline; the vendor does not document offline editing.",
     "src": "https://support.1password.com/sync/",
     "q": "After everything is in sync, it'll be available even if you need to go offline for a bit."
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://1password.com/pricing/business",
     "q": "Access 1Password on macOS, iOS, watchOS, Windows, Android, and Linux"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://1password.com/pricing/business",
     "q": "Access 1Password on macOS, iOS, watchOS, Windows, Android, and Linux"
    },
    "limits": {
     "v": "Team members who unlock with SSO have no offline access unless an admin turns on biometric unlock; the admin sets the maximum offline period.",
     "plan": "Business",
     "src": "https://support.1password.com/sso-security/",
     "q": "Unless biometrics are turned on by an administrator, team members who unlock 1Password with SSO lack offline access to their items."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Business",
     "src": "https://support.1password.com/firewall-rules/",
     "q": "Create rules to allow, report, or deny sign-in attempts from certain locations or IP addresses."
    },
    "device_controls": {
     "v": true,
     "plan": "Business",
     "summary": "Auto-lock and unlock-method policies, sign-in attempt limits, Emergency Kit download control, firewall rules by country/IP/anonymous IP.",
     "src": "https://support.1password.com/team-policies/",
     "q": "Unlock and auto-lock : Manage when 1Password will automatically lock and control the unlock methods your team"
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Firewall rules in 1Password Business can allow, report or deny sign-ins by country, IP address/CIDR range, or anonymous IP type (Tor, public VPNs, proxies).",
     "src": "https://support.1password.com/firewall-rules/",
     "q": "Create rules to allow, report, or deny sign-in attempts from certain locations or IP addresses."
    },
    {
     "topic": "offline",
     "text": "Staff who unlock 1Password with SSO lose offline access unless the admin enables biometric unlock and sets a maximum offline period.",
     "src": "https://support.1password.com/sso-security/",
     "q": "The administrator determines the maximum allowed time period for offline access before a team member has to sign in with the identity provider."
    },
    {
     "topic": "remote",
     "text": "Teams can choose where data is hosted: United States (1Password.com), Canada (1Password.ca) or European Union (1Password.eu).",
     "src": "https://support.1password.com/regions/",
     "q": "Secure data hosted in: European Union"
    },
    {
     "topic": "remote",
     "text": "Business includes a free Families membership for every employee, covering personal passwords at home.",
     "src": "https://support.1password.com/link-family/",
     "q": "When you're part of a team that uses 1Password Business, you get a complimentary 1Password Families membership."
    }
   ]
  },
  {
   "slug": "activecampaign",
   "name": "ActiveCampaign",
   "category": "Marketing Automation",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/activecampaign/#security-offline-remote",
   "trust_center": "https://trust.activecampaign.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://trust.activecampaign.com/",
     "q": "ActiveCampaign has successfully completed another System and Organization Controls (SOC) 2 Type II audit."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise",
     "src": "https://trust.activecampaign.com/faq",
     "q": "ActiveCampaign offers customers on the Enterprise plan the ability to sign a Business Associate Agreement (BAA)"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://trust.activecampaign.com/",
     "q": "ActiveCampaign Data Processing Addendum"
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.activecampaign.com/hc/en-us/articles/4404715700892-Set-up-single-sign-on-for-your-ActiveCampaign-account",
     "q": "This version of SSO works with any SAML provider, including but not limited to: Okta, Auth0, Microsoft Entra ID (Azure AD)"
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Starter",
     "src": "https://help.activecampaign.com/hc/en-us/articles/360008574740-Set-up-multi-factor-authentication-for-your-ActiveCampaign-account",
     "q": "If you are an Account Admin, you can enforce account-wide multi-factor authentication"
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "APAC"
     ],
     "src": "https://www.activecampaign.com/data-centers",
     "q": "Regional data centers in the EU, US, & APAC"
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "The Forms for iPad app can collect form sign-ups offline and adds them to the account once back online; the main ActiveCampaign mobile app needs an internet connection.",
     "src": "https://help.activecampaign.com/hc/en-us/articles/115000754364-ActiveCampaign-Forms-for-iPad",
     "q": "If you are collecting subscriber information offline, the app will store contact information. Once you are back online, contacts will be added to your account"
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://help.activecampaign.com/hc/en-us/articles/360000684464-ActiveCampaign-Mobile-app-overview",
     "q": "View the ActiveCampaign mobile app in the Apple store View the ActiveCampaign mobile app in the Google Play Store"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "summary": "Idle-session timeout with customizable session length; MFA required to use the mobile app.",
     "src": "https://www.activecampaign.com/security",
     "q": "Session management Log an ActiveCampaign user out if they are idle for a predetermined period of time."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Customers are assigned to the nearest regional data center by the account's GEO IP address and cannot currently change it.",
     "src": "https://www.activecampaign.com/data-centers",
     "q": "Customers are assigned to the closest data center based on the account’s GEO IP address."
    },
    {
     "topic": "offline",
     "text": "The ActiveCampaign mobile app pulls live data and needs an internet connection.",
     "src": "https://help.activecampaign.com/hc/en-us/articles/360000684464-ActiveCampaign-Mobile-app-overview",
     "q": "This app pulls live data from your account. You’ll need an Internet connection to use it"
    },
    {
     "topic": "remote",
     "text": "Multi-factor authentication is mandatory to sign in to the ActiveCampaign mobile app.",
     "src": "https://help.activecampaign.com/hc/en-us/articles/360008574740-Set-up-multi-factor-authentication-for-your-ActiveCampaign-account",
     "q": "Multi-factor authentication is required in order to log in to the ActiveCampaign Mobile app"
    },
    {
     "topic": "office",
     "text": "The Forms for iPad app (all plans) can capture sign-ups at in-person events or front desks, even without connectivity.",
     "src": "https://help.activecampaign.com/hc/en-us/articles/115000754364-ActiveCampaign-Forms-for-iPad",
     "q": "This app is compatible with iPad 2 or higher and you must have iOS 9 or higher. This app is available for all plan levels."
    }
   ]
  },
  {
   "slug": "acuity-scheduling",
   "name": "Acuity Scheduling",
   "category": "Scheduling Software",
   "checked": "2026-09-19",
   "scope": "Acuity Scheduling by Squarespace; accounts sign in through Squarespace, and Acuity is subject to Squarespace's policies. No Acuity-specific certification page was found.",
   "profile_url": "https://helpcompare.com/tools/acuity-scheduling/#security-offline-remote",
   "trust_center": "https://www.squarespace.com/security",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Premium (or legacy Powerhouse)",
     "src": "https://help.acuityscheduling.com/hc/en-us/articles/16689567523597-Acuity-Scheduling-and-HIPAA",
     "q": "You must be on the Premium or Powerhouse plan to enable HIPAA-related services and enter into a BAA with Squarespace."
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://acuityscheduling.com/enterprise",
     "q": "Connect with Okta and MedPlum using OAuth 2.0 and SAML, the leading industry-standard protocols for provisioning and authentication."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://help.acuityscheduling.com/hc/en-us/articles/39986670495501-Why-was-my-Acuity-account-connected-to-Squarespace",
     "q": "Use Squarespace login options such as two-factor authentication or social login."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "none",
     "summary": "Acuity is web-based and needs an internet connection; no offline mode is documented.",
     "src": "https://help.acuityscheduling.com/hc/en-us/articles/16676930385933-Acuity-Scheduling-FAQ",
     "q": "Everything is web-based, so all you need is an internet connection and a web browser."
    },
    "desktop": {
     "v": [],
     "src": "https://help.acuityscheduling.com/hc/en-us/articles/16676930385933-Acuity-Scheduling-FAQ",
     "q": "Everything is web-based, so all you need is an internet connection and a web browser."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://help.acuityscheduling.com/hc/en-us/articles/16676868721165-Using-the-Acuity-Scheduling-Admin-mobile-app",
     "q": "Use our mobile admin app to view and manage appointments on the go. Download for Android Download for iOS"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "The Acuity admin mobile app takes in-person payments with a paired Stripe M2 card reader or Tap to Pay (Square also supported).",
     "src": "https://help.acuityscheduling.com/hc/en-us/articles/16676896145933-Accepting-Acuity-Scheduling-payments-in-person-with-Stripe",
     "q": "Credit card Cash Tap to Pay Using a paired Stripe M2 reader"
    }
   },
   "facts": [
    {
     "topic": "office",
     "text": "At the front desk or an event, staff can collect payments and tips in the Acuity admin mobile app.",
     "src": "https://help.acuityscheduling.com/hc/en-us/articles/16676896145933-Accepting-Acuity-Scheduling-payments-in-person-with-Stripe",
     "q": "you can collect payments and tips for appointments using the Acuity Scheduling Admin mobile app."
    },
    {
     "topic": "office",
     "text": "Tap to Pay needs a US business charging in US dollars, and an iPhone XS+ on iOS 16+ or an NFC Android 10+ phone.",
     "src": "https://help.acuityscheduling.com/hc/en-us/articles/16676896145933-Accepting-Acuity-Scheduling-payments-in-person-with-Stripe",
     "q": "Based in the US and taking payment in US dollars."
    },
    {
     "topic": "remote",
     "text": "Enterprise plan adds multi-location support with an organization-wide dashboard and individualized BAAs.",
     "src": "https://help.acuityscheduling.com/hc/en-us/articles/23612140463629-The-Acuity-Scheduling-Enterprise-plan",
     "q": "Support for multiple locations with an organization-wide dashboard."
    },
    {
     "topic": "security",
     "text": "Only Acuity, not other Squarespace features, is covered by the HIPAA Business Associate Addendum.",
     "src": "https://help.acuityscheduling.com/hc/en-us/articles/16689567523597-Acuity-Scheduling-and-HIPAA",
     "q": "Acuity is the only Squarespace feature currently designed to offer services consistent with HIPAA obligations."
    }
   ]
  },
  {
   "slug": "adespresso",
   "name": "AdEspresso",
   "category": "Paid Ads Management",
   "checked": "2026-09-19",
   "scope": "AdEspresso web app (a Hootsuite company). No product-specific security center; the help center points to Hootsuite's GDPR page.",
   "profile_url": "https://helpcompare.com/tools/adespresso/#security-offline-remote",
   "trust_center": "https://adespresso.com/privacy/",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": null
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "AdEspresso describes itself as a Canadian company in the Hootsuite family and refers GDPR questions to Hootsuite's GDPR page; it names no product-specific certifications.",
     "src": "https://support.adespresso.com/s/article/GDPR",
     "q": "We at AdEspresso, as part of the Hootsuite family, are a Canadian company, and as such are already subject to data protection laws that provide for similar standards as existing European laws."
    },
    {
     "topic": "remote",
     "text": "Subusers get per-ad-account permissions (None, Management or Analytics) and cannot see billing, change the plan or add ad accounts.",
     "src": "https://support.adespresso.com/s/article/add-remove-subusers",
     "q": "The level of access that subusers have for each ad account can be controlled with permissions."
    },
    {
     "topic": "remote",
     "text": "Onboarding requests let clients give an agency access to their Facebook ad accounts, Pages or CRMs without sharing passwords.",
     "src": "https://support.adespresso.com/s/article/approvals-onboarding",
     "q": "Onboarding requests make it easy for clients to provide access to their Facebook ad accounts, Pages, or CRMs (customer relationship management platforms) without having to share passwords."
    },
    {
     "topic": "security",
     "text": "Removing ad accounts deletes their data from AdEspresso; only the account email remains, and backups are wiped periodically.",
     "src": "https://support.adespresso.com/s/article/delete-data",
     "q": "Removing your ad accounts from AdEspresso will remove all the data concerning your ad accounts and any connection with your Facebook account from AdEspresso."
    }
   ]
  },
  {
   "slug": "adobe-acrobat-sign",
   "name": "Adobe Acrobat Sign",
   "category": "E-Signature",
   "checked": "2026-09-19",
   "scope": "Acrobat Sign Solutions (business/enterprise). E-sign inside Acrobat Standard/Pro and Acrobat Sign for Government (FedRAMP Moderate) have different controls.",
   "profile_url": "https://helpcompare.com/tools/adobe-acrobat-sign/#security-offline-remote",
   "trust_center": "https://www.adobe.com/trust/compliance/compliance-list.html",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.adobe.com/trust/compliance/compliance-list.html",
     "q": "Adobe Document Cloud - Acrobat Sign Solutions for enterprise SOC 2–Type 2 (Security, Availability, & Confidentiality)"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.adobe.com/trust/compliance/compliance-list.html",
     "q": "ISO 27001:2022"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO 22301",
      "ISO 9001",
      "C5",
      "FedRAMP Tailored",
      "IRAP",
      "ISMAP",
      "PCI DSS 4.0 (service provider)",
      "CSA STAR Level 2",
      "QTSP (time stamps)"
     ],
     "src": "https://www.adobe.com/trust/compliance/compliance-list.html",
     "q": "C5 Certified (Germany) FedRAMP Tailored IRAP Assessed [8] (Australia) ISMAP Registered (Japan)"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Acrobat Sign for enterprise or business",
     "src": "https://helpx.adobe.com/sign/web/guidance-for-regulatory-demands/overview.html",
     "q": "The HIPAA readiness capability is only available through an Adobe Acrobat Sign for enterprise or business subscription plan."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.adobe.com/acrobat/business/trust-center/general-data-protection-regulation.html",
     "q": "We’ve updated Adobe’s Data Processing Agreement to account for GDPR requirements."
    },
    "sso_saml": {
     "v": true,
     "src": "https://helpx.adobe.com/sign/web/settings-configuration/saml-settings/enable-saml-single-sign-on.html",
     "q": "Adobe Acrobat Sign includes SAML authentication for customers that desire a federated log in system."
    },
    "scim": {
     "v": true,
     "plan": "Document Cloud for enterprise (Adobe Admin Console)",
     "src": "https://helpx.adobe.com/business/enterprise/identity-sso/integrate-with-microsoft-entra/add-microsoft-entra-id-sync.html",
     "q": "Add Microsoft Entra ID Sync (formerly Azure Sync) to any directory in the Adobe Admin Console to automate user management. It uses the SCIM protocol"
    },
    "mfa": {
     "v": true,
     "enforce": "Adobe Admin Console (Enterprise ID and Adobe ID users; plan not stated)",
     "src": "https://helpx.adobe.com/enterprise/using/authentication-settings.html",
     "q": "As a System Admin, you can enforce this requirement organization-wide, preventing users from turning it off."
    },
    "audit_log": {
     "v": true,
     "src": "https://helpx.adobe.com/sign/web/administers/admin-reports/settings-activity-audit.html",
     "q": "The Settings Activity Audits report is a particular type of report to allow administrators to have visibility of (and an auditable record of) any changes in settings"
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://helpx.adobe.com/sign/how-to/sign-in-person-using-signature-app.html",
     "q": "Log in to the Acrobat Sign app for iOS or Android on your tablet or phone."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Acrobat Sign Solutions",
     "src": "https://helpx.adobe.com/sign/web/settings-configuration/security-settings/allowed-ip-ranges.html",
     "q": "Allowed IP Ranges let administrators limit access to Adobe Acrobat Sign to trusted networks only."
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Allowed IP ranges limit only account users and integrations; recipients can still open and sign agreements from any network.",
     "src": "https://helpx.adobe.com/sign/web/settings-configuration/security-settings/allowed-ip-ranges.html",
     "q": "This setting does not affect the recipients of the agreement."
    },
    {
     "topic": "remote",
     "text": "Senders who use the Acrobat Sign mobile apps are also covered by the account IP allowlist.",
     "src": "https://helpx.adobe.com/sign/web/settings-configuration/security-settings/allowed-ip-ranges.html",
     "q": "The Acrobat Sign mobile applications fall within the scope of Certified Applications and are impacted by the controls that allow or deny access to the Acrobat Sign service."
    },
    {
     "topic": "remote",
     "text": "Acrobat Sign isn't hosted in China, and Adobe doesn't support use cases that involve access from China.",
     "src": "https://helpx.adobe.com/sign/faq.html",
     "q": "Adobe does not host Acrobat Sign on a server located in China to serve Chinese users."
    },
    {
     "topic": "security",
     "text": "Your Acrobat Sign data center is picked during deployment, but Adobe's hosting page doesn't list the available countries.",
     "src": "https://helpx.adobe.com/sign/using/adobesign-data-centers.html",
     "q": "when choosing an Acrobat Sign data center during deployment"
    }
   ]
  },
  {
   "slug": "adobe-express",
   "name": "Adobe Express",
   "category": "Design Tools",
   "checked": "2026-09-19",
   "scope": "Adobe Express web and mobile (Free, Premium, Teams, Enterprise). Adobe publishes compliance and security documents for 'Creative Cloud for enterprise (including Adobe Express)' and 'Adobe Express for enterprise'; coverage of individual and Teams plans is not stated separately.",
   "profile_url": "https://helpcompare.com/tools/adobe-express/#security-offline-remote",
   "trust_center": "https://www.adobe.com/trust.html",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.adobe.com/trust/compliance/compliance-list.html",
     "q": "Adobe Creative Cloud for enterprise [2] (including Adobe Express and Adobe Firefly) SOC 2–Type 2 (Security, Availability, & Confidentiality)"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.adobe.com/trust/compliance/compliance-list.html",
     "q": "ISO 9001:2015 ISO 27001:2022 ISO 27017:2015 ISO 27018:2019 ISO 22301:2019"
    },
    "other_certs": {
     "v": [
      "SOC 3",
      "ISO 9001:2015",
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO 22301",
      "FedRAMP Tailored",
      "CSA STAR Level 2"
     ],
     "src": "https://www.adobe.com/trust/compliance/compliance-list.html",
     "q": "SOC 3 (Security, Availability, & Confidentiality) ISO 9001:2015 ISO 27001:2022 ISO 27017:2015 ISO 27018:2019 ISO 22301:2019 FedRAMP Tailored GLBA ready [1] FERPA ready [1] CSA Star Level 2"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.adobe.com/privacy/eudatatransfers.html",
     "q": "If you are an Adobe business customer (with Enterprise Licensing) and want to enter into a DPA with Adobe, please request those documents from us."
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://business.adobe.com/products/express-business/pricing.html",
     "q": "Manage users' authentication credentials using Federated ID with single sign-on (SSO) and Enterprise ID models."
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.adobe.com/express/pricing",
     "q": "User directory sync Automate Adobe user management process when synched with Microsoft Azure or Google Admin Console."
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.adobe.com/cc-shared/assets/pdf/trust-center/ungated/whitepapers/creative-cloud/adobe-express-for-enterprise-security-overview.pdf",
     "q": "Administrators can view a 90-day rolling history of their organization’s content log to gain insight into how users are working with their assets through the Adobe Admin Console."
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "JP"
     ],
     "plan": "Enterprise",
     "src": "https://www.adobe.com/trust/creative-cloud-hosting-locations.html",
     "q": "hosted on Amazon Web Services (AWS) through continuously active data centers in multiple geographic locations, including North America, Europe, and Japan."
    },
    "encryption": {
     "v": "TLS 1.2+ in transit; AES-256 at rest (Express for enterprise); customer-managed keys available on Enterprise",
     "src": "https://www.adobe.com/cc-shared/assets/pdf/trust-center/ungated/whitepapers/creative-cloud/adobe-express-for-enterprise-security-overview.pdf",
     "q": "All data is encrypted in transit over HTTPS using TLS 1.2 or greater. At Rest – User-generated content stored by Express for enterprise is encrypted at rest using AES 256-bit encryption."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [],
     "src": "https://helpx.adobe.com/express/web/adobe-express-subscription/premium.html",
     "q": "Access Adobe Express on the web or install it as a Progressive Web App (PWA) on your desktop."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://helpx.adobe.com/express/mobile/get-started/install.html",
     "q": "Android iOS Open Google Play. Select Install."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Content is stored in the regional data store assigned when an admin provisions the user, and stays there whatever the user's location. For distributed teams, region depends on provisioning, not travel.",
     "src": "https://www.adobe.com/trust/creative-cloud-hosting-locations.html",
     "q": "content created by a user in the US will always be stored in the US data center, regardless of the user’s location when they upload the content."
    },
    {
     "topic": "remote",
     "text": "Teams and Enterprise include 24x7 technical support in multiple languages, with a dedicated line for admins.",
     "src": "https://www.adobe.com/express/pricing?tab=2",
     "q": "24x7 technical support Available in multiple languages from customer care team, dedicated line for admins."
    },
    {
     "topic": "security",
     "text": "Express for enterprise records a content log of creation, read, update, sharing and deletion events, with user ID and IP address, viewable by admins for 90 days.",
     "src": "https://www.adobe.com/cc-shared/assets/pdf/trust-center/ungated/whitepapers/creative-cloud/adobe-express-for-enterprise-security-overview.pdf",
     "q": "Express for enterprise generates content logs, which record asset creation, read, updating, sharing and deletion events and log the user’s ID, IP address, timestamp, filename, and event type."
    },
    {
     "topic": "remote",
     "text": "All plans, Free included, support real-time co-editing and commenting on shared designs.",
     "src": "https://www.adobe.com/express/pricing",
     "q": "Real-time co-editing and commenting"
    }
   ]
  },
  {
   "slug": "ahrefs",
   "name": "Ahrefs",
   "category": "SEO Software",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/ahrefs/#security-offline-remote",
   "trust_center": "https://ahrefs.com/faq",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://ahrefs.com/legal/data-processing-addendum",
     "q": "This Data Processing Addendum and its annexures (\"DPA\") reflect the agreement between Ahrefs and Customer"
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.ahrefs.com/en/articles/6713450-saml-sso-configuration",
     "q": "SAML SSO is available on Enterprise plans and can be set up by the workspace owner or admins."
    },
    "scim": {
     "v": true,
     "src": "https://ahrefs.com/faq",
     "q": "SCIM provisioning is available via Ahrefs support."
    },
    "mfa": {
     "v": true,
     "enforce": "Workspace owner/admin setting (plan not stated)",
     "src": "https://help.ahrefs.com/en/articles/8755828-two-factor-authentication-2fa",
     "q": "If you are the workspace owner or admin, you can enforce 2FA for your workspace members."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "Encrypted at rest (AWS RDS) and in transit (TLS)",
     "src": "https://ahrefs.com/faq",
     "q": "The Security Measures page documents encryption at rest (AWS RDS) and in transit (TLS), access controls, defense-in-depth practices, and incident response."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": null
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Ahrefs says SOC 2 certification is in progress and not yet complete.",
     "src": "https://ahrefs.com/faq",
     "q": "SOC 2 certification is in progress but not yet complete."
    },
    {
     "topic": "security",
     "text": "SAML SSO is Enterprise-only; Lite, Standard and Advanced plans do not include it.",
     "src": "https://ahrefs.com/faq",
     "q": "Yes, Ahrefs supports SAML 2.0 single sign-on, but only on the Enterprise plan. Lite, Standard, and Advanced don’t include it."
    },
    {
     "topic": "security",
     "text": "Admins can make SAML the only login method, but owners and admins keep email/password access as a fail-safe.",
     "src": "https://ahrefs.com/faq",
     "q": "Admins can enforce SAML as the sole login method by switching Authentication method to Only SAML SSO."
    },
    {
     "topic": "security",
     "text": "When 2FA is enforced, members without it are signed out until they set it up, and new invitees must set it up before joining.",
     "src": "https://help.ahrefs.com/en/articles/8755828-two-factor-authentication-2fa",
     "q": "Once enabled, every member who hasn't set up 2FA will be signed out and required to set up 2FA to continue accessing their accounts."
    }
   ]
  },
  {
   "slug": "apollo",
   "name": "Apollo.io",
   "category": "Sales Intelligence & B2B Data",
   "checked": "2026-09-19",
   "scope": "Apollo.io web app (app.apollo.io); the native mobile app was retired on August 28, 2026.",
   "profile_url": "https://helpcompare.com/tools/apollo/#security-offline-remote",
   "trust_center": "https://trust.apollo.io/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://trust.apollo.io/",
     "q": "SOC 2 Type 2 Report (Security, Availability, Confidentiality): Validated by independent auditors, this new report confirms the effectiveness of our controls over time."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.apollo.io/company/privacy-center",
     "q": "We are ISO 27001 certified by A-LIGN, a leading third party cybersecurity and compliance firm."
    },
    "other_certs": {
     "v": [
      "CASA Tier 2"
     ],
     "src": "https://trust.apollo.io/",
     "q": "Compliance CASA Tier 2 CCPA CPRA EU-US DPF GDPR ISO/IEC 27001 ISO/IEC 27001 SoA SOC 2"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.apollo.io/dpa",
     "q": "This Data Processing Addendum (the \"DPA\") between you and Apollo (each a \"Party\" and collectively the \"Parties\") is incorporated into and will form part of the Agreement."
    },
    "sso_saml": {
     "v": true,
     "plan": "Organization",
     "src": "https://knowledge.apollo.io/hc/en-us/articles/12667892496141-Use-Single-Sign-On-SSO-on-Apollo",
     "q": "Apollo supports both SP and IdP-initiated SSO through SAML and SCIM integrations."
    },
    "scim": {
     "v": true,
     "plan": "Organization",
     "src": "https://knowledge.apollo.io/hc/en-us/articles/15570877535757-Configure-SCIM-User-Provisioning-for-SSO",
     "q": "Apollo supports SCIM provisioning with Okta and Microsoft Entra ID when SAML single sign-on is active."
    },
    "mfa": {
     "v": true,
     "enforce": "Basic (any paid plan)",
     "src": "https://knowledge.apollo.io/hc/en-us/articles/20439872853645-Configure-Advanced-Security-Protocols-on-Apollo",
     "q": "If you are an admin user on an Apollo paid plan , you can make it mandatory for users to provide at least one extra verification method"
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://trust.apollo.io/",
     "q": "Google Cloud United States Secure cloud hosting of production systems"
    },
    "encryption": {
     "v": "Encrypted in transit and at rest (algorithms not stated publicly)",
     "src": "https://www.apollo.io/company/privacy-center",
     "q": "Both idle and active data is encrypted over public networks and in our databases."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [],
     "src": "https://knowledge.apollo.io/hc/en-us/articles/40459457015821-Access-Apollo-From-a-Mobile-Browser",
     "q": "Apollo retired the mobile app on August 28, 2026. You can no longer install or use the app"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Organization",
     "src": "https://knowledge.apollo.io/hc/en-us/articles/20439872853645-Configure-Advanced-Security-Protocols-on-Apollo",
     "q": "When you activate IP allowlisting in Apollo, you can choose the specific IP addresses or ranges you consider trustworthy and only give those IPs access to your account."
    },
    "device_controls": {
     "v": true,
     "plan": "Organization",
     "summary": "Admin-set session timeout (1 to 30 days) and a cap on failed login attempts per 24 hours.",
     "src": "https://knowledge.apollo.io/hc/en-us/articles/20439872853645-Configure-Advanced-Security-Protocols-on-Apollo",
     "q": "You can choose a session timeout period of between 1 and 30 days."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Since August 28, 2026 Apollo has no mobile app; reps on phones must use app.apollo.io in a mobile browser.",
     "src": "https://knowledge.apollo.io/hc/en-us/articles/40459457015821-Access-Apollo-From-a-Mobile-Browser",
     "q": "Sign in to Apollo at app.apollo.io from a mobile or desktop browser instead."
    },
    {
     "topic": "security",
     "text": "Apollo's SCIM provisioning only works with Okta or Microsoft Entra ID SAML, not with Google or Microsoft OAuth sign-in.",
     "src": "https://knowledge.apollo.io/hc/en-us/articles/15570877535757-Configure-SCIM-User-Provisioning-for-SSO",
     "q": "SCIM provisioning isn't available with Google or Microsoft OAuth single sign-on."
    },
    {
     "topic": "security",
     "text": "Advanced security settings (IP allowlisting, SSO, login controls) are listed on Apollo's Organization plan.",
     "src": "https://www.apollo.io/pricing",
     "q": "Advanced Security Configurations Single Sign-on (SSO)"
    }
   ]
  },
  {
   "slug": "asana",
   "name": "Asana",
   "category": "Project Management",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/asana/#security-offline-remote",
   "trust_center": "https://asana.com/trust",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://asana.com/trust",
     "q": "SOC 2 (Type 2) Security, availability, confidentiality, and privacy trust services criteria"
    },
    "iso27001": {
     "v": true,
     "src": "https://asana.com/trust",
     "q": "ISO/IEC 27001:2022 Global standard for information security management systems"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "CSA STAR Level 1",
      "SOC 3"
     ],
     "src": "https://asana.com/trust",
     "q": "ISO/IEC 27701:2019 Privacy information management standard supporting compliance with global privacy laws"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise+",
     "src": "https://help.asana.com/s/article/hipaa-compliance?language=en_US",
     "q": "HIPAA compliance for Asana is governed by Asana’s Business Associate Addendum (BAA)."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://asana.com/terms/data-processing",
     "q": "Asana Data Processing Addendum"
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.asana.com/s/article/authentication-and-access-management-options-for-paid-plans?language=en_US",
     "q": "To set up SAML, you must: Belong to an organization or division on Asana Enterprise, Enterprise+, or Legacy Enterprise."
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.asana.com/s/article/provisioning-and-deprovisioning-users-with-scim?language=en_US",
     "q": "An Asana organization on an Enterprise plan or better, with a member account that has admin permissions."
    },
    "mfa": {
     "v": true,
     "enforce": "Enterprise",
     "src": "https://help.asana.com/s/article/mandatory-two-factor-authentication?language=en_US",
     "q": "Available on Asana Enterprise and Enterprise+ tiers, as well as legacy tier Legacy Enterprise."
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise+ (or Enterprise with Compliance Management add-on)",
     "src": "https://developers.asana.com/docs/audit-log-events",
     "q": "only Service Accounts belonging to organizations on the Asana Enterprise+ tier, legacy tier Legacy Enterprise, or an Enterprise domain with the Compliance Management Add-on can access audit log API endpoints."
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "JP",
      "AU"
     ],
     "plan": "Enterprise (add-on); included in Enterprise+",
     "src": "https://help.asana.com/s/article/data-residency-for-asana?language=en_US",
     "q": "Data residency is available to be purchased as an add-on in Enterprise organizations and divisions and is included in Enterprise+ tiers."
    },
    "encryption": {
     "v": "256-bit encryption at rest and in transit",
     "src": "https://asana.com/pricing",
     "q": "256-bit encryption at rest and in-transit Data is encrypted in transit and at rest"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "The iOS app works offline for checking notifications, commenting, changing due dates or assignees, completing tasks and adding tasks; pending actions sync when you are back online.",
     "src": "https://help.asana.com/s/article/asana-for-ios?language=en_US",
     "q": "You can use Asana for iOS offline to check your notifications, comment on tasks, change due dates or assignees, and complete tasks on the go."
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://help.asana.com/s/article/asana-desktop-app?language=en_US",
     "q": "Available for both Mac and Windows (not supported on Linux)"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://asana.com/pricing",
     "q": "Asana offers desktop apps for macOS and Windows for optimal performance, plus iOS and Android apps for managing work on the go."
    },
    "limits": {
     "v": "Tasks and conversations in projects never opened on the device are not visible offline (new tasks can still be added to them)",
     "src": "https://help.asana.com/s/article/asana-for-ios?language=en_US",
     "q": "Tasks and conversations within a project that have never been opened on your app will not be visible offline, but you can add tasks to these projects offline."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise+",
     "src": "https://help.asana.com/s/article/ip-allowlisting-in-asana?language=en_US",
     "q": "IP Allowlisting enhances your organization's security by restricting access to your Asana organization from only specified IP addresses or ranges."
    },
    "device_controls": {
     "v": true,
     "plan": "Enterprise",
     "summary": "SAML session timeout (1 hour to 30 days) plus an optional mobile session timeout; mobile app controls (limit downloads, screenshots, copy/paste) are sold as a Permissions Management add-on.",
     "src": "https://help.asana.com/s/article/authentication-and-access-management-options-for-paid-plans?language=en_US",
     "q": "Super admins can set SAML session timeout between 1 hour and 30 days in the admin console."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Asana's IP allowlist can be applied to all users, only organization members, or only guests, and optionally to API traffic.",
     "src": "https://help.asana.com/s/article/ip-allowlisting-in-asana?language=en_US",
     "q": "User-level restrictions: Apply IP restrictions to all users, only organization members, or only guests."
    },
    {
     "topic": "security",
     "text": "Mandatory 2FA on Enterprise tiers can be enforced for guests as well as domain members, useful for outside collaborators not on your SSO.",
     "src": "https://help.asana.com/s/article/mandatory-two-factor-authentication?language=en_US",
     "q": "Admins can enforce two-factor authentication (2FA) for all domain members and guests, enhancing security."
    },
    {
     "topic": "remote",
     "text": "With data residency, all of an organization's Asana data must sit in one region (US, Frankfurt, Tokyo or Sydney).",
     "src": "https://help.asana.com/s/article/data-residency-for-asana?language=en_US",
     "q": "Customers must store all Asana data in a single region"
    },
    {
     "topic": "security",
     "text": "Mobile app controls that limit downloads, screenshots and copy/paste are listed on the pricing page as a Permissions Management add-on.",
     "src": "https://asana.com/pricing",
     "q": "Mobile app controls Manage the ways your team can use Asana on mobile devices, such as limiting downloads, screenshots, and copy/paste."
    }
   ]
  },
  {
   "slug": "backblaze",
   "name": "Backblaze",
   "category": "Business Backup",
   "checked": "2026-09-19",
   "scope": "Backblaze Computer Backup - Business Backup (Groups) with optional Enterprise Control; B2 Cloud Storage not researched.",
   "profile_url": "https://helpcompare.com/tools/backblaze/#security-offline-remote",
   "trust_center": "https://www.backblaze.com/company/trust-center",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.backblaze.com/cloud-storage/compliance",
     "q": "Backblaze has achieved Service Organization Control (SOC) 2 Type 2 compliance by an independent third-party firm."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "GovRAMP Progressing Snapshot",
      "TX-RAMP Provisional",
      "TPN Blue Shield"
     ],
     "src": "https://www.backblaze.com/cloud-storage/compliance",
     "q": "Backblaze holds or supports the following compliance certifications and frameworks: SOC 2 Type 2, HIPAA, GDPR and UK GDPR, CCPA/CPRA, PCI-DSS, GovRAMP Progressing Snapshot, TX-RAMP Provisional"
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://www.backblaze.com/cloud-storage/compliance",
     "q": "Backblaze can provide a Business Associate Agreement (BAA) upon request for business customers who are Covered Entities under the Health Insurance Portability and Accountability Act (HIPAA)."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.backblaze.com/cloud-storage/compliance",
     "q": "Data Processing Agreement Addendums (DPAs) for EEA/EU and UK residents are available for compliance standards."
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise Control (add-on; OIDC, SAML not mentioned)",
     "src": "https://www.backblaze.com/computer-backup/docs/enable-and-disable-single-sign-on-sso-for-a-group",
     "q": "Open ID (Enterprise Control only)"
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://www.backblaze.com/cloud-backup/security",
     "q": "Two-factor verification (2FA) via SMS or ToTP authenticator apps available for all users"
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US",
      "EU"
     ],
     "src": "https://www.backblaze.com/cloud-backup/security",
     "q": "Regions: U.S. West (California & Arizona), U.S. East (Virginia), & EU Central (Amsterdam)."
    },
    "encryption": {
     "v": "AES-128 data keys secured by 2048-bit RSA key pair; HTTPS in transit; optional private encryption key (PEK)",
     "src": "https://www.backblaze.com/cloud-backup/pricing",
     "q": "Default 2048 bit public / private keys secure symmetric AES-128 key for all data; option to additionally encrypt all data with a private key."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://www.backblaze.com/cloud-backup/pricing",
     "q": "Native Mac and Windows clients–no Java or middleware"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.backblaze.com/cloud-backup/features/restore",
     "q": "Use the Backblaze mobile app for iOS or Android to browse and download your backed up files."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "plan": "Enterprise Control",
     "summary": "Silent deployment via MSI, Jamf, Munki and MDM tools; Enterprise Control adds enhanced backup lockdown (prevents users changing/removing backups), restricted restore access and Legal Hold.",
     "src": "https://www.backblaze.com/cloud-backup/pricing",
     "q": "Enhanced backup lockdown"
    },
    "office_hardware": {
     "v": "Backs up Mac/Windows computers and attached external drives; NAS and network drives are excluded, and large restores can be shipped on a USB drive.",
     "src": "https://www.backblaze.com/computer-backup/docs/supported-backup-data",
     "q": "Network-mounted drives, network-attached storage (NAS) devices, remotely mounted computers or volumes, and shared volumes are currently excluded from Backblaze Computer Backup"
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Backblaze positions Business Backup for remote and distributed teams, deployed through MDM tools such as Jamf, Iru (Kandji), Addigy and Intune.",
     "src": "https://www.backblaze.com/cloud-backup/business",
     "q": "Automatic backup for Macs and PCs, wherever your employees work."
    },
    {
     "topic": "office",
     "text": "Office file servers and NAS cannot be protected with Computer Backup; Backblaze directs server/NAS backup to B2 Cloud Storage integrations.",
     "src": "https://www.backblaze.com/computer-backup/docs/backblaze-groups",
     "q": "If you need to back up a server or network-attached storage (NAS), view our Backblaze B2 Integrations"
    },
    {
     "topic": "remote",
     "text": "Large restores can be shipped worldwide on an encrypted USB drive, prepared and shipped from the U.S.",
     "src": "https://www.backblaze.com/computer-backup/docs/international-customers",
     "q": "All USB restores are prepared and shipped from the U.S. even if your data is stored in a non-U.S. data center."
    },
    {
     "topic": "security",
     "text": "With a private encryption key, Backblaze itself cannot access backed-up data, and a lost key cannot be recovered.",
     "src": "https://www.backblaze.com/cloud-backup/security",
     "q": "Personal Encryption Key (PEK): PEK option available for all users. With a PEK, Backblaze cannot access your data"
    }
   ]
  },
  {
   "slug": "bitwarden",
   "name": "Bitwarden",
   "category": "Password Managers",
   "checked": "2026-09-19",
   "scope": "Bitwarden Password Manager, Teams and Enterprise organizations (cloud); self-hosted option noted.",
   "profile_url": "https://helpcompare.com/tools/bitwarden/#security-offline-remote",
   "trust_center": "https://bitwarden.com/compliance/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://bitwarden.com/compliance/",
     "q": "Bitwarden is SOC2 Type II and SOC3 certified. SOC2 Reports available upon request."
    },
    "iso27001": {
     "v": true,
     "src": "https://bitwarden.com/compliance/",
     "q": "Bitwarden is ISO 27001 certified and in compliance with ISO 27001 control sets surrounding data security."
    },
    "other_certs": {
     "v": [
      "SOC 3",
      "HIPAA"
     ],
     "src": "https://bitwarden.com/compliance/",
     "q": "Bitwarden adheres to industry security standards with an ISO 27001 certification, SOC2 and SOC3 certifications, and HIPAA compliance."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://bitwarden.com/help/about-sso/",
     "q": "SAML 2.0 and OIDC configuration options that support integration with a wide variety of IdPs."
    },
    "scim": {
     "v": true,
     "plan": "Teams",
     "src": "https://bitwarden.com/help/about-scim/",
     "q": "Teams and Enterprise organizations can use SCIM ."
    },
    "mfa": {
     "v": true,
     "enforce": "Teams (via Duo); Enterprise (two-step login policy)",
     "src": "https://bitwarden.com/pricing/business/",
     "q": "Organization two-step login via Duo Enable and enforce organization-wide two-factor authentication through Duo MFA."
    },
    "audit_log": {
     "v": true,
     "plan": "Teams",
     "src": "https://bitwarden.com/pricing/business/",
     "q": "View detailed records of over 50 types of events with timestamps, client type, IP addresses, and user, all retained indefinitely and easily exportable."
    },
    "data_residency": {
     "v": [
      "US",
      "EU"
     ],
     "src": "https://bitwarden.com/help/server-geographies/",
     "q": "The Bitwarden cloud is available globally with data storage in both United States and European Union regions."
    },
    "encryption": {
     "v": "Zero-knowledge, end-to-end encryption of all vault data, decryptable only with the master password",
     "src": "https://bitwarden.com/compliance/",
     "q": "Bitwarden uses end-to-end encryption for all vault data, which only your master password can decrypt."
    },
    "self_host": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://bitwarden.com/pricing/business/",
     "q": "Self-host option Run the Bitwarden server application on your own network or server. Compatible with all Bitwarden end-clients."
    },
    "mode": {
     "v": "partial",
     "summary": "Any unlocked Bitwarden app works offline in read-only mode; items, attachments and Sends cannot be added or edited until reconnected.",
     "src": "https://bitwarden.com/help/using-bitwarden-offline/",
     "q": "Any unlocked Bitwarden app can be used offline in read-only mode"
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://bitwarden.com/download/",
     "q": "Install Bitwarden on macOS, Windows, and Linux desktops with native applications."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://bitwarden.com/download/",
     "q": "Take your password manager on the go with mobile apps for your phone or tablet."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "plan": "Enterprise",
     "summary": "Enterprise policies including session timeout, require SSO, single organization and centralized item ownership.",
     "src": "https://bitwarden.com/help/policies/",
     "q": "The Single organization policy must be turned on before activating the following policies: Account recovery administration Require single sign-on authentication Default URI match detection Session timeout"
    },
    "office_hardware": {
     "v": "Two-step login supports up to 10 hardware security keys and Yubico OTP; no other office hardware documented.",
     "src": "https://bitwarden.com/pricing/business/",
     "q": "Up to 10 hardware security keys, Yubico OTP, Duo, Email, Authentication app"
    }
   },
   "facts": [
    {
     "topic": "offline",
     "text": "Bitwarden apps work offline only in read-only mode: you can view but not add or edit items without a connection.",
     "src": "https://bitwarden.com/help/using-bitwarden-offline/",
     "q": "Most functions of Bitwarden are accessible in offline mode, however you won't be able to make edits to or add vault items, attachments, or sends or import new vault items."
    },
    {
     "topic": "office",
     "text": "The desktop app can be installed on air-gapped/offline machines from the GitHub release installer and asset bundle, though it will not auto-update.",
     "src": "https://bitwarden.com/help/using-bitwarden-offline/",
     "q": "Customers occasionally wish to install Bitwarden on offline machines, for example in air-gapped environments."
    },
    {
     "topic": "security",
     "text": "Enterprise customers can self-host Bitwarden on their own servers behind a proxy or firewall for data-residency control.",
     "src": "https://bitwarden.com/pricing/business/",
     "q": "You can place your Bitwarden installation behind a proxy, firewall, and other safeguards for enhanced data security."
    },
    {
     "topic": "remote",
     "text": "Cloud accounts live in either the US or EU region, chosen at sign-up; an account exists only in the region where it was created.",
     "src": "https://bitwarden.com/help/server-geographies/",
     "q": "Bitwarden server regions are separate, and your account or organization only exists in the region where it was first created."
    }
   ]
  },
  {
   "slug": "buffer",
   "name": "Buffer",
   "category": "Social Media Management",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/buffer/#security-offline-remote",
   "trust_center": "https://buffer.com/legal",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://buffer.com/legal",
     "q": "We have created a legal agreement that users and external parties can receive from us, promising the protection all personally identifiable information that we collect and store."
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Team",
     "src": "https://support.buffer.com/en-us/articles/best-practices-for-buffer-account-security-GH1k1HJ9ws",
     "q": "Admins on Team plans can also require 2FA for every member of their organization from their Team Settings ."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://buffer.com/legal",
     "q": "Amazon Web Services (AWS), Inc Cloud (hosting) service USA"
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://buffer.com/mobile",
     "q": "Get the Buffer app on Google Play Get the Buffer app on the iOS App Store"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Buffer says it is SOC 2 compliant (on a Buffer-owned blog post), without stating the report type.",
     "src": "https://buffer.com/resources/every-team-feature-in-buffer-built-for-agencies/",
     "q": "Buffer is also SOC 2 compliant, which covers the rest of the security conversation that tends to come up when an agency is selling into bigger clients."
    },
    {
     "topic": "remote",
     "text": "Team owners and admins can require every team member to turn on two-factor authentication before using Buffer; the 2FA article says this is on the web for Team and Essentials users with Beta features enabled.",
     "src": "https://support.buffer.com/en-us/articles/using-two-factor-authentication-in-buffer-FClTl67lZB",
     "q": "If you're a team owner or admin, you can require that every team member enable 2FA before they can use Buffer."
    },
    {
     "topic": "remote",
     "text": "Buffer recommends an authenticator app over SMS codes for people working without cell reception, for example on a plane.",
     "src": "https://support.buffer.com/en-us/articles/best-practices-for-buffer-account-security-GH1k1HJ9ws",
     "q": "We recommend using an authentication app instead of SMS/text"
    },
    {
     "topic": "remote",
     "text": "Support is by email on every plan, including Free; the pricing page does not list phone or live chat.",
     "src": "https://buffer.com/pricing.md",
     "q": "World-class customer support: Fast and helpful support via email."
    }
   ]
  },
  {
   "slug": "calendly",
   "name": "Calendly",
   "category": "Scheduling Software",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/calendly/#security-offline-remote",
   "trust_center": "https://calendly.com/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://calendly.com/security",
     "q": "SOC 2 (Type 2) SOC 3 CSA STAR PCI COMPLIANT ISO/IEC 27001"
    },
    "iso27001": {
     "v": true,
     "src": "https://calendly.com/security",
     "q": "SOC 2 (Type 2) SOC 3 CSA STAR PCI COMPLIANT ISO/IEC 27001"
    },
    "other_certs": {
     "v": [
      "SOC 3",
      "CSA STAR",
      "PCI compliant"
     ],
     "src": "https://calendly.com/security",
     "q": "SOC 2 (Type 2) SOC 3 CSA STAR PCI COMPLIANT ISO/IEC 27001"
    },
    "hipaa": {
     "v": "Not supported",
     "src": "https://calendly.com/legal/customer-terms-conditions",
     "q": "the Customer Data does not contain: (x) protected health information or information subject to Health Insurance Portability and Accountability Act"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://calendly.com/legal/data-processing-addendum",
     "q": "This Data Processing Addendum, including the exhibits to it"
    },
    "sso_saml": {
     "v": true,
     "plan": "Teams (SSO add-on)",
     "src": "https://calendly.com/help/saml-single-sign-on-sso-overview",
     "q": "Be on the Teams plan with the SSO add-on or the Enterprise plan"
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.calendly.com/hc/en-us/articles/4403420585623-SCIM-user-provisioning-overview",
     "q": "You'll need to be on the Enterprise plan and be a Calendly owner or admin."
    },
    "mfa": {
     "v": true,
     "src": "https://help.calendly.com/hc/en-us/articles/26682031653399-How-to-set-up-two-factor-authentication-2FA",
     "q": "Add an extra layer of protection to your Calendly account by enabling two-factor authentication (2FA)."
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://calendly.com/help/the-activity-log",
     "q": "Calendly owners and admins on our Enterprise plan have access to this log."
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://calendly.com/help/data-storage-and-international-data-transfers",
     "q": "Calendly stores user and invitee data in U.S.-based data centers managed by Google Cloud Services (GCS) and Amazon Web Services (AWS)"
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2+ in transit",
     "src": "https://calendly.com/security",
     "q": "Encryption in transit (TLS 1.2+) Encryption at rest (AES-256) and in transit"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://calendly.com/help/calendly-mobile-app-overview",
     "q": "Get the app for your device from the Apple App Store for iOS or Google Play for Android"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Calendly detects each invitee's time zone and shows your availability in their local time.",
     "src": "https://help.calendly.com/hc/en-us/articles/14078163170071-Time-Zones-overview",
     "q": "Calendly detects your invitee’s time zone automatically. It shows your availability in their local time."
    },
    {
     "topic": "security",
     "text": "Calendly data is hosted in US data centers on Google Cloud and AWS, with no customer-selectable region stated.",
     "src": "https://calendly.com/help/data-storage-and-international-data-transfers",
     "q": "Calendly stores user and invitee data in U.S.-based data centers managed by Google Cloud Services (GCS) and Amazon Web Services (AWS)"
    },
    {
     "topic": "security",
     "text": "Calendly's customer terms bar protected health information, so it is not for HIPAA-regulated intake.",
     "src": "https://calendly.com/legal/customer-terms-conditions",
     "q": "the Customer Data does not contain: (x) protected health information or information subject to Health Insurance Portability and Accountability Act"
    }
   ]
  },
  {
   "slug": "canva",
   "name": "Canva",
   "category": "Design Tools",
   "checked": "2026-09-19",
   "scope": "Canva web, desktop and mobile apps (Free, Pro, Business, Enterprise). Affinity by Canva not covered.",
   "profile_url": "https://helpcompare.com/tools/canva/#security-offline-remote",
   "trust_center": "https://trust.canva.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.canva.com/security/",
     "q": "Canva is SOC2 Type II compliant and is ISO 27001 certified, which requires us to have periodic external audits of our information security management system and security controls."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.canva.com/security/",
     "q": "Canva has attained SOC2 Type II compliance and is ISO 27001 certified."
    },
    "other_certs": {
     "v": [
      "SOC 3",
      "PCI DSS",
      "EU-US Data Privacy Framework"
     ],
     "src": "https://www.canva.com/security/",
     "q": "Certifications Learn more ISO 27001 AICPA SOC 2 AICPA SOC 3 PCI DSS Data Privacy Framework"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.canva.com/policies/data-processing-addendum/",
     "q": "This Addendum applies where and to the extent that Canva is acting as a Processor or Service Provider (as applicable) of Customer Personal Data under the Agreement."
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.canva.com/help/set-up-sso/",
     "q": "This guide is for Canva Enterprise administrators and owners who will manage their team’s SSO settings."
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.canva.com/pricing/",
     "q": "It includes everything in Business, plus enterprise-level features like advanced brand governance, security with SSO and SCIM, custom apps and integrations, and admin controls."
    },
    "mfa": {
     "v": true,
     "src": "https://www.canva.com/security/",
     "q": "We provide SSO and MFA options for users and enterprises to secure their accounts."
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.canva.com/help/admin-controls-for-enterprise/",
     "q": "Organization Admin Full platform control, assign admins, configure System for Cross-domain Identity Management (SCIM), single sign-on (SSO), and audit logs"
    },
    "data_residency": {
     "v": [
      "US",
      "EU"
     ],
     "plan": "Enterprise",
     "src": "https://www.canva.com/help/data-residency/",
     "q": "Under Data residency, select your preferred region from the dropdown: No Preference United States European Union"
    },
    "encryption": {
     "v": "AES-256 at rest; TLS/SSL in transit",
     "src": "https://www.canva.com/security/",
     "q": "In transit, designs are only accessible via TLS/SSL, and at rest, designs are encrypted with AES256."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "In desktop browsers, the Canva desktop app and the Android app, designs you mark 'available offline' can be edited for up to 14 days without internet (no new designs, templates, AI, sharing or exporting); changes sync automatically when you reconnect.",
     "src": "https://www.canva.com/help/set-up-offline-access/",
     "q": "You can only edit existing designs (no new designs offline)"
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://www.canva.com/download/",
     "q": "Your favorite design tool available as a desktop app for Macs with Intel and Apple chips. Download Canva for Mac Also available on Windows, iOS, Android, and Chromebook."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.canva.com/download/",
     "q": "Also available on Windows, iOS, Android, and Chromebook."
    },
    "limits": {
     "v": "Per device only; up to 14 days offline; not in the iOS/iPad apps or private/incognito browsing. The pricing table shows Canva Offline on every plan, Free included.",
     "src": "https://www.canva.com/help/set-up-offline-access/",
     "q": "Not supported: iOS and iPad apps Firefox (versions 149, 150, and 151 ) Private or incognito mode"
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "offline",
     "text": "Offline designs stay on the device where you enabled them. The iOS and iPad apps do not support offline editing, so plan for laptops or Android devices when travelling.",
     "src": "https://www.canva.com/help/set-up-offline-access/",
     "q": "Designs enabled for offline are available on the device only, and won’t be available on other devices."
    },
    {
     "topic": "remote",
     "text": "Canva Business bills pay-as-you-grow: you pay only for invited members who accept. Monthly plans adjust at renewal; annual plans are billed quarterly for members added.",
     "src": "https://www.canva.com/pricing/",
     "q": "Canva Business operates on pay-as-you-grow model. This means you only pay for the team members who accept your invitation."
    },
    {
     "topic": "security",
     "text": "Customer-chosen data residency (US or EU) is limited to Enterprise, Campus and District plans; existing data can take 30 days or more to migrate.",
     "src": "https://www.canva.com/help/data-residency/",
     "q": "Once you apply the setting, new data will be stored in your selected region. Supported existing data migrates automatically and may take 30 days or more."
    },
    {
     "topic": "security",
     "text": "Canva Shield indemnification, including AI output indemnity, applies only to Enterprise customers with more than 100 seats.",
     "src": "https://www.canva.com/security/",
     "q": "enterprise customers with over 100 seats have an extra layer of protection with indemnification."
    }
   ]
  },
  {
   "slug": "carbonite",
   "name": "Carbonite",
   "category": "Business Backup",
   "checked": "2026-09-19",
   "scope": "Carbonite Safe Backup Pro (Core) and Safe Pro + Safe Server Backup bundles (Power, Ultimate); OpenText enterprise backup products not researched.",
   "profile_url": "https://helpcompare.com/tools/carbonite/#security-offline-remote",
   "trust_center": "https://support.carbonite.com/articles/Data-Security-for-Carbonite-Safe-and-Safe-Backup-Pro",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://prod-cms.carbonite.com/globalassets/resource-media/whitepaper/pdf-files/carbonite_securityandcompliance_wp.pdf",
     "q": "Carbonite can provide a SOC 2 Type 2 report to customers upon request and under NDA, to attest to security, confidentiality and availability controls."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Core",
     "src": "https://support.carbonite.com/articles/Appliance-Pro-Server-HIPAA",
     "q": "Carbonite's Business Associate Agreement (BAA) is based on the federal government’s standard"
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://support.carbonite.com/articles/Personal-Pro-Mac-Windows-Introduction-to-2-Step-Verification",
     "q": "You can secure your Carbonite Safe account with two factor authentication."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://support.carbonite.com/articles/Data-Security-for-Carbonite-Safe-and-Safe-Backup-Pro",
     "q": "Carbonite has multiple state-of-the-art facilities in the United States that are designed to protect the security and integrity of your data."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2 in transit; optional private key (Windows only)",
     "src": "https://support.carbonite.com/articles/Data-Security-for-Carbonite-Safe-and-Safe-Backup-Pro",
     "q": "Carbonite encrypts users files using AES-256 bit encryption."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://www.carbonite.com/professional/backup/",
     "q": "Windows 7+ or OS X 10.10+ Support"
    },
    "mobile": {
     "v": [],
     "src": "https://apps.apple.com/us/app/carbonite-mobile/id347953228",
     "q": "This is the companion app that pairs with consumer Carbonite Safe® only."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "plan": "Core",
     "summary": "Admin-defined backup policies by group, role or device; admins add and remove computers and assign them to users.",
     "src": "https://www.carbonite.com/professional/backup/",
     "q": "Create and manage policies by group, role, device or any other criteria you choose"
    },
    "office_hardware": {
     "v": "Backs up office NAS devices and external drives on all plans; Power/Ultimate add Windows servers (2008+) with cloud and onsite server backup targets.",
     "src": "https://www.carbonite.com/professional/backup/",
     "q": "Cloud and onsite server backup targets"
    }
   },
   "facts": [
    {
     "topic": "office",
     "text": "NAS drives are included only on Safe Backup Pro plans, and a NAS whose path changes or whose selecting Windows admin stops signing in is dropped from the backup within 60 days.",
     "src": "https://support.carbonite.com/articles/Pro-Windows-Mac-Retention-of-Deleted-Files",
     "q": "NAS drive support is included only with Safe Backup Pro plans (Core, Power, and Ultimate)."
    },
    {
     "topic": "remote",
     "text": "Courier Recovery (a shipped restore drive) is available only to Safe Backup Pro subscribers living in the United States.",
     "src": "https://support.carbonite.com/articles/Pro-Mac-Windows-Courier-Recovery-Service",
     "q": "Courier Recovery is only available to Carbonite Safe Backup Pro subscribers who live in the United States."
    },
    {
     "topic": "security",
     "text": "Private encryption key management is not available for Mac users.",
     "src": "https://support.carbonite.com/articles/Data-Security-for-Carbonite-Safe-and-Safe-Backup-Pro",
     "q": "Carbonite does not support private encryption key management for Mac users."
    },
    {
     "topic": "remote",
     "text": "Phone and email support is weekday business hours only (Eastern time), not 24/7.",
     "src": "https://www.carbonite.com/professional/backup/",
     "q": "Support hours: Mon-Fri- 9am-6pm ET"
    }
   ]
  },
  {
   "slug": "chatgpt",
   "name": "ChatGPT",
   "category": "AI Assistants",
   "checked": "2026-09-19",
   "scope": "ChatGPT Business and Enterprise workspaces (team buyer view); excludes the OpenAI API Platform, Edu and ChatGPT for Healthcare.",
   "profile_url": "https://helpcompare.com/tools/chatgpt/#security-offline-remote",
   "trust_center": "https://trust.openai.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "plan": "Business",
     "src": "https://openai.com/enterprise-privacy/",
     "q": "ChatGPT Business successfully completed a SOC 2 Type 2 audit."
    },
    "iso27001": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://trust.openai.com/",
     "q": "This certificate documents OpenAI's operation an Information Security Management System that conforms to the requirements of ISO/IEC 27001:2022 for OpenAI's API, ChatGPT Enterprise, and ChatGPT Edu services."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "ISO/IEC 42001",
      "SOC 3",
      "PCI DSS v4.0.1",
      "CSA STAR",
      "FedRAMP 20x",
      "TX-RAMP"
     ],
     "src": "https://trust.openai.com/",
     "q": "PCI DSS v4.0.1 CCPA CSA STAR GDPR ISO/IEC 27001:2022 ISO/IEC 27017:2015 ISO/IEC 27018:2019 ISO/IEC 27701:2019 SOC 2 SOC 2 Type 2 SOC 3 TX-RAMP FedRAMP 20x ISO/IEC 42001:2023"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise",
     "src": "https://help.openai.com/en/articles/20001069-hipaa-eligible-products-and-functionality",
     "q": "OpenAI makes the following HIPAA eligible products available with a Business Associates Agreement (BAA): ChatGPT for Enterprise with Regulated Workspace"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://trust.openai.com/",
     "q": "Legal Subprocessors Cyber Insurance Data Processing Agreement"
    },
    "sso_saml": {
     "v": true,
     "plan": "Business",
     "src": "https://help.openai.com/en/articles/11489188-sso-for-chatgpt-business-faq",
     "q": "SSO and domain verification are included with ChatGPT Business. Business supports Security Assertion Markup Language (SAML) and OpenID Connect (OIDC)."
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.openai.com/en/articles/11489188-sso-for-chatgpt-business-faq",
     "q": "A standalone ChatGPT Business plan does not include SCIM, synchronized groups, or automatic directory provisioning."
    },
    "mfa": {
     "v": true,
     "plan": "Business",
     "src": "https://chatgpt.com/pricing",
     "q": "Secure workspace with SAML, SSO, and MFA"
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://openai.com/enterprise-privacy/",
     "q": "workspace admins can access an audit log of conversations and GPTs through the Enterprise Compliance API"
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "UK",
      "JP",
      "CA",
      "KR",
      "SG",
      "IN",
      "AU",
      "AE"
     ],
     "plan": "Enterprise",
     "src": "https://help.openai.com/en/articles/9903489-data-residency-and-inference-residency-for-chatgpt",
     "q": "Data residency for ChatGPT is currently available in the following regions: Australia Canada Europe (EEA + Switzerland) India Japan Singapore South Korea United Arab Emirates United Kingdom United States"
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2+ in transit",
     "src": "https://openai.com/enterprise-privacy/",
     "q": "Data encryption at rest (AES-256) and in transit between our customers and us, and between us and our service providers (TLS 1.2+)"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "macOS",
      "Windows"
     ],
     "src": "https://chatgpt.com/download",
     "q": "Download ChatGPT Classic for Mac and Windows"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://chatgpt.com/pricing",
     "q": "Access on web, iOS, Android"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.openai.com/en/articles/12111596-ip-allowlisting-for-chatgpt",
     "q": "IP Allowlisting is an optional security feature available for ChatGPT Enterprise and Edu workspaces."
    },
    "device_controls": {
     "v": true,
     "plan": "Enterprise",
     "summary": "Enterprise: Intune for iOS (pricing table) and Workspace Blocking via a ChatGPT-Allowed-Workspace-Id HTTP header on the corporate network; not ticked for Business.",
     "src": "https://help.openai.com/en/articles/20001323-corporate-network-controls-in-chatgpt-enterprise",
     "q": "Workspace Blocking is a feature that allows ChatGPT Enterprise customers to restrict access to specific ChatGPT workspaces"
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Business data residency is rolling out gradually; if a non-US region is chosen, a copy of every prompt and response is still stored in the US for a limited time for abuse monitoring.",
     "src": "https://help.openai.com/en/articles/20001418-where-your-chatgpt-business-content-is-stored",
     "q": "If you choose a region outside the United States, a copy of every prompt and response is also stored in the United States for a limited time"
    },
    {
     "topic": "remote",
     "text": "In Business workspaces admins can view, access, export and delete member conversations, though by default they cannot see all private member chats in the product.",
     "src": "https://openai.com/enterprise-privacy/",
     "q": "Workspace admins have control over workspaces and can view, access, export, and delete end user conversations in the workspace."
    },
    {
     "topic": "remote",
     "text": "Self-serve Business can't pay by invoice, PO, ACH or wire; organisations needing those must buy a contracted plan such as Enterprise.",
     "src": "https://help.openai.com/en/articles/8792536-managing-billing-and-seats-in-chatgpt-business",
     "q": "Invoice billing, bank transfer, wire, ACH, purchase orders, and net terms are not available for self-serve Business workspaces."
    }
   ]
  },
  {
   "slug": "claude",
   "name": "Claude",
   "category": "AI Assistants",
   "checked": "2026-09-19",
   "scope": "Claude apps for work (Team and Enterprise plans); consumer Free/Pro/Max noted where relevant. Claude API/Console not researched.",
   "profile_url": "https://helpcompare.com/tools/claude/#security-offline-remote",
   "trust_center": "https://trust.anthropic.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://privacy.claude.com/en/articles/10015870-what-certifications-has-anthropic-obtained",
     "q": "SOC 2 Type I & Type II"
    },
    "iso27001": {
     "v": true,
     "src": "https://privacy.claude.com/en/articles/10015870-what-certifications-has-anthropic-obtained",
     "q": "ISO 27001:2022 (Information Security Management)"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 42001",
      "HIPAA"
     ],
     "src": "https://privacy.claude.com/en/articles/10015870-what-certifications-has-anthropic-obtained",
     "q": "HIPAA-ready configuration (BAA available) ISO 27001:2022 (Information Security Management) ISO/IEC 42001:2023 (AI Management Systems)"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise",
     "src": "https://support.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customers",
     "q": "Anthropic provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://privacy.claude.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa",
     "q": "Anthropic’s DPA with Standard Contractual Clauses (SCCs) is automatically incorporated into our Commercial Terms of Service"
    },
    "sso_saml": {
     "v": true,
     "plan": "Team",
     "src": "https://support.claude.com/en/articles/13132885-set-up-single-sign-on-sso",
     "q": "Single sign-on is available for Team plans, Enterprise plans, and Console organizations."
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.claude.com/en/articles/13133195-set-up-jit-or-scim-provisioning",
     "q": "SCIM is not available for Team plans or Console organizations joined to a Team plan's parent organization."
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.claude.com/en/articles/9970975-access-audit-logs",
     "q": "Audit logs are available for Enterprise organizations only."
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://privacy.claude.com/en/articles/7996890-where-are-your-servers-located-do-you-host-your-models-on-eu-servers",
     "q": "Note that data is stored in the US."
    },
    "encryption": {
     "v": "Encrypted in transit and at rest; customer-managed encryption keys (AWS KMS, Google Cloud KMS, Azure Key Vault) for eligible Enterprise organizations",
     "src": "https://privacy.claude.com/en/articles/10458704-how-does-anthropic-protect-the-personal-data-of-claude-users",
     "q": "Encryption : Your data is automatically encrypted both while in transit, and stored (at rest)."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "none",
     "summary": "Anthropic states Cowork needs an active internet connection throughout a session; no offline mode is documented for Claude chat on any app.",
     "src": "https://support.claude.com/en/articles/13345190-get-started-with-claude-cowork",
     "q": "Active internet connection: Required throughout the session."
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://support.claude.com/en/articles/10065433-install-claude-desktop",
     "q": "Claude Desktop is available on macOS, Windows, and Linux (beta)."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.claude.com/en/articles/11101966-use-voice-mode",
     "q": "Claude Mobile (iOS and Android)"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.claude.com/en/articles/13200993-restrict-access-to-claude-with-ip-allowlisting",
     "q": "IP allowlisting is available for Enterprise plans only."
    },
    "device_controls": {
     "v": true,
     "plan": "Enterprise",
     "summary": "Enterprise admins can shorten session length (1, 7, 14 or 28 days); Team and Enterprise get enterprise deployment for the desktop app and admin controls for remote and local connectors.",
     "src": "https://support.claude.com/en/articles/13163631-configuring-session-security-settings",
     "q": "Session duration controls allow Enterprise and Console Admins to set a maximum session length for all users in their organization."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "On Enterprise, admins can restrict access to approved CIDR ranges such as office locations and VPN exit points; requests from other IPs are blocked.",
     "src": "https://support.claude.com/en/articles/13200993-restrict-access-to-claude-with-ip-allowlisting",
     "q": "compile a list of all necessary CIDR ranges for your organization, including office locations, VPN exit points, and any other approved access points."
    },
    {
     "topic": "security",
     "text": "Customer data is stored in the US; by default traffic may be routed to select countries in the US, Europe, Asia and Australia.",
     "src": "https://privacy.claude.com/en/articles/7996890-where-are-your-servers-located-do-you-host-your-models-on-eu-servers",
     "q": "By default, we may route customer traffic to select countries in the US, Europe, Asia and Australia, unless otherwise agreed upon or at your instructions."
    },
    {
     "topic": "offline",
     "text": "Cowork runs tasks in an isolated virtual machine on the user's computer and can read and write only folders the user connects.",
     "src": "https://support.claude.com/en/articles/10065433-install-claude-desktop",
     "q": "Cowork runs code in an isolated virtual machine on your computer. File reads and writes are limited to folders you connect"
    },
    {
     "topic": "remote",
     "text": "Team usage limits are per member, so one person hitting a limit does not affect colleagues.",
     "src": "https://support.claude.com/en/articles/9266767-what-is-the-team-plan",
     "q": "Usage limits on Team plans are per-member, rather than applied to the team as a whole."
    }
   ]
  },
  {
   "slug": "clickfunnels",
   "name": "ClickFunnels",
   "category": "Funnel Building & Agency Software",
   "checked": "2026-09-19",
   "scope": "Current ClickFunnels platform (formerly ClickFunnels 2.0); ClickFunnels Classic not researched",
   "profile_url": "https://helpcompare.com/tools/clickfunnels/#security-offline-remote",
   "trust_center": null,
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.clickfunnels.com/dpa",
     "q": "THIS DATA PROCESSING ADDENDUM (this “DPA”) supplements and is a part of the ClickFunnels Subscriber Terms of Service"
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://support.myclickfunnels.com/docs/enable-two-factor-authentication-2fa-in-clickfunnels-account",
     "q": "You can use an authenticator app such as Google Authenticator or Authy to scan the QR code."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://www.clickfunnels.com/dpa",
     "q": "When you store End User Personal Data on our systems, it is automatically transferred outside of your country of residence to the United States."
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": null
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Workspaces that process live payments are prompted to turn on 2FA at every login until it is enabled.",
     "src": "https://support.myclickfunnels.com/docs/enable-two-factor-authentication-2fa-in-clickfunnels-account",
     "q": "If your workspace has a payment gateway set up to process live transactions, you need to activate the “Two-Factor Authentication” feature to enhance security."
    },
    {
     "topic": "security",
     "text": "ClickFunnels' DPA says inactive sessions time out and accounts lock after repeated failed logins.",
     "src": "https://www.clickfunnels.com/dpa",
     "q": "Inactive sessions are subject to automatic timeout, and accounts are locked after multiple sequential failed login attempts."
    }
   ]
  },
  {
   "slug": "clickup",
   "name": "ClickUp",
   "category": "Project Management",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/clickup/#security-offline-remote",
   "trust_center": "https://clickup.com/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://clickup.com/security",
     "q": "Our continued SOC 1 Type 2, SOC 2 Type 2, and SOC 3 certifications ensures our organizational and technology controls are independently audited at least annually."
    },
    "iso27001": {
     "v": true,
     "src": "https://clickup.com/security",
     "q": "the ISO 27001:2022, ISO 27017:2015, ISO 27018:2019, and ISO 27701:2019 certifications confirm that ClickUp meets the highest international standards"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "ISO/IEC 42001",
      "SOC 1 Type 2",
      "SOC 3"
     ],
     "src": "https://clickup.com/security",
     "q": "ClickUp is proud to be among the first platforms to achieve ISO 42001 certification"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise",
     "src": "https://clickup.com/faqs",
     "q": "ClickUp supports HIPAA compliance on the Enterprise plan with a signed Business Associate Agreement (BAA)."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://clickup.com/terms/dpa",
     "q": "Data Protection Addendum For an executable copy, please reach out to support@clickup.com"
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.clickup.com/hc/en-us/articles/6305027039767-Configure-custom-SAML-single-sign-on",
     "q": "Custom SAML is only available on the Enterprise Plan."
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.clickup.com/hc/en-us/articles/6305052795287-Okta-SCIM-ClickUp-configuration-guide",
     "q": "Before you can set up provisioning, you need to have Okta SSO enabled for your Workspace. Okta SSO is only available to Workspaces on the Enterprise Plan."
    },
    "mfa": {
     "v": true,
     "enforce": "Business",
     "src": "https://help.clickup.com/hc/en-us/articles/6327741965591-Activate-and-manage-two-factor-authentication",
     "q": "Requiring 2FA for everyone in a Workspace is available on our Business Plan and above."
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.clickup.com/hc/en-us/articles/25324213764119-Audit-Logs-feature-availability-and-limits",
     "q": "Audit Logs are available for the following plans and user roles: Plan User Role Enterprise only"
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "AU",
      "SG"
     ],
     "plan": "Enterprise",
     "src": "https://clickup.com/security",
     "q": "ClickUp customers who are on the Enterprise Plan have the option to host their core Workspace data in ClickUp’s US, European, or Asia Pacific data centers at no additional cost."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2 in transit",
     "src": "https://clickup.com/security",
     "q": "All data for ClickUp is encrypted at rest using AES-256 encryption."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "On web, desktop and mobile you can create new tasks (and reminders, except on mobile) and view previously opened tasks and notes offline, but cannot edit existing tasks or notes; new items sync on reconnect.",
     "src": "https://help.clickup.com/hc/en-us/articles/6308895791127-Offline-Mode",
     "q": "You can continue to create tasks and reminders while offline. When you reconnect, new tasks and reminders automatically sync with your Workspace."
    },
    "desktop": {
     "v": [
      "macOS",
      "Windows",
      "Linux"
     ],
     "src": "https://help.clickup.com/hc/en-us/articles/6311182548887-ClickUp-Apps-across-all-devices",
     "q": "Launch ClickUp from your Mac, Windows, or Linux computer and enjoy a seamless experience between the Web and Desktop."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://clickup.com/faqs",
     "q": "ClickUp's mobile app is available on iOS and Android"
    },
    "limits": {
     "v": "Available on all plans; existing tasks and notes can't be edited offline, subtasks can't be created, and reminders can't be created offline in the mobile app",
     "plan": "All plans",
     "src": "https://help.clickup.com/hc/en-us/articles/6308895791127-Offline-Mode",
     "q": "Offline Mode is available on all ClickUp plans."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise (early version; request access via account manager)",
     "src": "https://feedback.clickup.com/feature-requests/p/ip-restrictions",
     "q": "we do have early version of IP restriction controls available to Enterprise customers today!"
    },
    "device_controls": {
     "v": true,
     "plan": "Enterprise",
     "summary": "Session duration and idle timeout limits that apply to every account with access to the Workspace.",
     "src": "https://help.clickup.com/hc/en-us/articles/6327732937751-Session-management",
     "q": "Session management is available on the Enterprise Plan."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "A ClickUp staff reply on its feedback board says the early-access full-traffic IP restriction limits all traffic, not just login, to allowed ranges such as an office network or VPN.",
     "src": "https://feedback.clickup.com/feature-requests/p/ip-restrictions",
     "q": "Full traffic IP restriction – Restricts all traffic (not just login) based on allowed IP ranges."
    },
    {
     "topic": "security",
     "text": "If someone belongs to several Workspaces that enforce session management, the strictest (shortest) limit applies to their account.",
     "src": "https://help.clickup.com/hc/en-us/articles/6327732937751-Session-management",
     "q": "If you've joined more than one Workspace where session management is enforced, the strictest limits (shortest duration) will apply to your account."
    },
    {
     "topic": "offline",
     "text": "ClickUp stores tasks pinned to the Tray offline automatically.",
     "src": "https://help.clickup.com/hc/en-us/articles/6308895791127-Offline-Mode",
     "q": "ClickUp automatically stores data offline for all tasks in your Tray!"
    },
    {
     "topic": "security",
     "text": "Audit log history is kept for 60 days.",
     "src": "https://help.clickup.com/hc/en-us/articles/25324213764119-Audit-Logs-feature-availability-and-limits",
     "q": "Historical data in the audit log will be available for 60 days."
    }
   ]
  },
  {
   "slug": "clockify",
   "name": "Clockify",
   "category": "Time Tracking",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/clockify/#security-offline-remote",
   "trust_center": "https://trust.cake.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://clockify.me/security",
     "q": "SOC 2 Type II Report An annual audit that demonstrates our ongoing commitment to security and data privacy."
    },
    "iso27001": {
     "v": true,
     "src": "https://clockify.me/security",
     "q": "ISO/IEC 27001:2022 The world's best-known standard for information security management systems."
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://cake.com/dpa",
     "q": "This Data Processing Addendum, including its Exhibits (this “ Addendum ”), forms integral part of the Terms of Use"
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://clockify.me/help/getting-started/single-sign-on-sso",
     "q": "This is a paid feature, which you can enable by upgrading your workspace to Enterprise plan ."
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://clockify.me/pricing",
     "q": "Automatically manage and sync members and groups in Clockify through your identity provider (IdP)."
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://clockify.me/help/administration/audit-log",
     "q": "The Audit Log is a paid feature available on the Enterprise plan ."
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "UK",
      "AU"
     ],
     "plan": "Pro",
     "src": "https://clockify.me/help/getting-started/data-regions",
     "q": "Clockify offers data regions in the following locations: USA (United States) EU (Germany) UK (United Kingdom) AU (Australia)"
    },
    "encryption": {
     "v": "256-bit SSL/TLS in transit; hosted on AWS",
     "src": "https://clockify.me/help/troubleshooting/how-clockify-handles-your-data",
     "q": "All connections between you and Clockify are encrypted using 256-bit SSL encryption, the same standard used in online banking."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "full",
     "summary": "Mobile and desktop apps track time offline (the Windows app has a 'Force offline' mode) and sync automatically once back online.",
     "src": "https://clockify.me/pricing",
     "q": "Track time on mobile or desktop, even if you’re offline."
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://clockify.me/pricing",
     "q": "DESKTOP Windows Mac Linux"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://clockify.me/pricing",
     "q": "MOBILE Android iOS"
    },
    "limits": {
     "v": "Available on all plans including Free.",
     "plan": "Free",
     "src": "https://clockify.me/pricing",
     "q": "Mobile & desktop app Track time on mobile or desktop, even if you’re offline."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "Clockify's kiosk turns a shared device into a clock-in/clock-out station (PIN from Basic, QR code from Standard, photo capture on Pro); kiosk-only 'limited' users are billed at a lower seat rate.",
     "plan": "Basic",
     "src": "https://clockify.me/pricing",
     "q": "Set up a shared time clock device from which employees can clock in and out."
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "On Pro and Enterprise, admins can optionally turn on GPS location tracking for field staff and screenshots every 5 minutes; users are notified when these are enabled.",
     "src": "https://clockify.me/help/troubleshooting/how-clockify-handles-your-data",
     "q": "Screenshots and location tracking are only collected if explicitly enabled by an admin. All users are notified when these features are activated"
    },
    {
     "topic": "security",
     "text": "Workspace owners on Pro or Enterprise can store data in the US, EU (Germany), UK or Australia.",
     "src": "https://clockify.me/help/getting-started/data-regions",
     "q": "With data regions, Clockify users can choose the specific region where their workspace data is stored."
    },
    {
     "topic": "office",
     "text": "Kiosk photo capture on Pro takes a photo at kiosk login to prevent buddy punching.",
     "src": "https://clockify.me/pricing",
     "q": "Capture photos as users log into kiosk to avoid buddy punching and increase accountability."
    }
   ]
  },
  {
   "slug": "clover",
   "name": "Clover",
   "category": "POS Systems",
   "checked": "2026-09-19",
   "scope": "Clover POS bought direct from Clover.com (US); bank/reseller accounts may differ.",
   "profile_url": "https://helpcompare.com/tools/clover/#security-offline-remote",
   "trust_center": "https://www.clover.com/security",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "PCI DSS (QSA-validated; level not stated)"
     ],
     "src": "https://docs.clover.com/dev/docs/pci-dss-version-40-requirements-643-and-1161",
     "q": "Clover is compliant with applicable PCI DSS requirements, including those related to card-not-present (CNP) transactions for ecommerce merchants."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "End-to-end encryption and tokenization via Clover Security Plus",
     "plan": "Clover Security Plus (add-on)",
     "src": "https://www.clover.com/security",
     "q": "The latest end-to-end encryption and tokenization technology to help protect customer data from the moment their card is swiped."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "Clover devices with Offline Payments turned on can take card payments without internet for up to 7 days; they are stored on the device and submitted for authorization automatically on reconnection (EBT and gift cards excluded).",
     "src": "https://www.clover.com/en-US/help/accept-offline-payments",
     "q": "You can continue to take payments when you're not connected to the internet by turning on the Offline Payments option."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://play.google.com/store/apps/details?id=clover.companion.app&hl=en_US",
     "q": "Clover Go - Dashboard & POS - Apps on Google Play"
    },
    "limits": {
     "v": "Up to 7 days per device; optional per-payment limit, total offline limit and approval threshold; not for EBT or gift cards; uninstalling the app while offline deletes offline payments.",
     "src": "https://www.clover.com/en-US/help/accept-offline-payments",
     "q": "If you use more than one Clover device, you can enable or disable these options on each device you use. When enabled, devices can take offline payments for up to 7 days."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "Clover sells its own locked POS devices: Go reader ($199), Compact ($349), Flex and Flex Pocket handhelds, Mini, Station Solo, Station Duo ($1,899), Kiosk and Kitchen Display System; they cannot be used with other processors.",
     "src": "https://www.clover.com/pricing",
     "q": "While Clover POS devices may be purchased or leased from other entities, they cannot be used with other payment processors."
    }
   },
   "facts": [
    {
     "topic": "offline",
     "text": "Offline payments carry decline risk: expired or canceled cards and wrong PINs are only declined once the device reconnects.",
     "src": "https://www.clover.com/en-US/help/accept-offline-payments",
     "q": "When you take an offline payment, you accept the risk of a declined or partial payment when the device is back online."
    },
    {
     "topic": "office",
     "text": "Clover hardware bought on a 36-month subscription cannot be canceled; it can only be bought out or upgraded.",
     "src": "https://www.clover.com/pricing",
     "q": "Subscriptions are non-cancelable and ineligible for refunds."
    },
    {
     "topic": "remote",
     "text": "The customer list can be exported only from the web dashboard, not from a Clover device.",
     "src": "https://www.clover.com/en-US/help/export-customer-list",
     "q": "Clover devices do not currently support exporting or printing the full customer list directly from the device."
    },
    {
     "topic": "remote",
     "text": "Clover Go needs a WiFi or cellular connection and pairs with a phone for taking payments away from the counter.",
     "src": "https://www.clover.com/go",
     "q": "Get the power of a POS anywhere you have a WiFi or cellular internet connection."
    }
   ]
  },
  {
   "slug": "confluence",
   "name": "Confluence",
   "category": "Knowledge Management",
   "checked": "2026-09-19",
   "scope": "Confluence Cloud; self-managed Confluence Data Center not researched. SSO/SCIM come from Atlassian Guard (formerly Atlassian Access)",
   "profile_url": "https://helpcompare.com/tools/confluence/#security-offline-remote",
   "trust_center": "https://www.atlassian.com/trust/compliance/resources",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://wac-cdn.atlassian.com/misc-assets/pdfs/FY25_Mega_Audit_Atlassian_SOC_2_Bridge_Letter.pdf",
     "q": "Coalfire Controls, LLC prepared the latest SOC 2 Type II report relevant to the following Atlassian Cloud products"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.atlassian.com/trust/compliance/resources/iso27001",
     "q": "ISO/IEC 27001:2022 is a security management standard that specifies security management best practices and comprehensive security controls following the ISO/IEC 27002 best practice guidance."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27018",
      "FedRAMP Moderate",
      "CSA STAR",
      "TISAX",
      "C5",
      "IRAP"
     ],
     "src": "https://www.atlassian.com/trust/compliance/resources/fedramp",
     "q": "Jira, Confluence, & Jira Service Management FedRAMP Moderate Marketplace Listing"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Standard",
     "src": "https://www.atlassian.com/trust/compliance/resources/hipaa",
     "q": "Customers who are subject to HIPAA compliance and want to partner with Atlassian purchase a Standard, Premium, or Enterprise Plan and enter into a Business Associate Agreement (BAA)"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.atlassian.com/legal/data-processing-addendum",
     "q": "Atlassian Data Processing Addendum"
    },
    "sso_saml": {
     "v": true,
     "plan": "Any plan with Atlassian Guard Standard (add-on); included in Enterprise",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/atlassian-guard-product-and-plan-availability/",
     "q": "SAML single sign-on Atlassian Cloud: Atlassian Guard Standard Apps: Jira, Jira Service Management, Jira Product Discovery, Jira Align, Confluence, Bitbucket, Trello, Statuspage"
    },
    "scim": {
     "v": true,
     "plan": "Any plan with Atlassian Guard Standard (add-on); included in Enterprise",
     "src": "https://www.atlassian.com/software/confluence/pricing",
     "q": "Atlassian Guard Standard (SSO, SCIM, mobile app management)"
    },
    "mfa": {
     "v": true,
     "enforce": "All plans (managed accounts)",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/enforce-two-step-verification/",
     "q": "Atlassian Cloud: All plans Atlassian Government Cloud: Not available Enforce two-step verification for managed accounts"
    },
    "audit_log": {
     "v": true,
     "plan": "Any plan with Atlassian Guard Standard (add-on); included in Enterprise",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/atlassian-guard-product-and-plan-availability/",
     "q": "Audit logs for organization administration activities Atlassian Cloud: Atlassian Guard Standard"
    },
    "data_residency": {
     "v": [
      "AU",
      "CA",
      "EU",
      "DE",
      "IN",
      "JP",
      "SG",
      "KR",
      "CH",
      "UK",
      "US"
     ],
     "plan": "Standard",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/understand-data-residency/",
     "q": "Atlassian Cloud: Jira, Jira Service Management, Jira Product Discovery, Loom, and Confluence with Enterprise, Premium, and Standard plans."
    },
    "encryption": {
     "v": "AES-256 full-disk encryption at rest; TLS 1.2+ in transit",
     "src": "https://www.atlassian.com/trust/security/security-practices",
     "q": "Jira, Bitbucket Cloud, Confluence Cloud, Statuspage, Opsgenie, Trello, Loom, Compass and Rovo use full disk, industry-standard AES-256 encryption at rest."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "If the connection drops, you can keep editing pages, live docs, blog posts and slides that were already open; changes are stored locally and sync when you reconnect, but new content can't be created offline.",
     "src": "https://support.atlassian.com/confluence-cloud/docs/edit-content-offline/",
     "q": "When you go offline, Confluence preserves your changes locally and syncs them when you’re back online."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.atlassian.com/security-and-access-policies/docs/atlassian-guard-product-and-plan-availability/",
     "q": "Mobile apps: Jira Cloud, Confluence Cloud, and Opsgenie, and Rovo apps for iOS and Android"
    },
    "limits": {
     "v": "Only content opened while online; no creating new content, and Rovo/AI tools, some macros, integrations and external media need a connection",
     "src": "https://support.atlassian.com/confluence-cloud/docs/edit-content-offline/",
     "q": "Offline editing does not currently support: Creating new content items while offline."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Premium",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/specify-ip-addresses-for-product-access/",
     "q": "Plan: Premium plan for Jira, Jira Service Management, Confluence, and Compass."
    },
    "device_controls": {
     "v": true,
     "plan": "Any plan with Atlassian Guard Standard (add-on); included in Enterprise",
     "summary": "Mobile app management policies for the Confluence Cloud iOS and Android apps via Atlassian Guard Standard.",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/atlassian-guard-product-and-plan-availability/",
     "q": "Mobile app management Atlassian Cloud: Atlassian Guard Standard Mobile apps: Jira Cloud, Confluence Cloud, and Opsgenie, and Rovo apps for iOS and Android"
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Even with an IP allowlist, some Jira/Confluence information (such as notification details and Smart Links) stays visible to users outside the allowed ranges.",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/specify-ip-addresses-for-product-access/",
     "q": "Regardless of your IP allowlists, users can always see the following information types:"
    },
    {
     "topic": "security",
     "text": "On the Confluence pricing page, Guard Standard (SSO, SCIM, mobile app management) is marked 'Requires Atlassian Guard Standard subscription' on Free, Standard and Premium and 'Included' on Enterprise.",
     "src": "https://www.atlassian.com/software/confluence/pricing",
     "q": "Requires Atlassian Guard Standard subscription"
    },
    {
     "topic": "offline",
     "text": "Offline editing covers pages, live docs, blog posts and slides that were opened while online.",
     "src": "https://support.atlassian.com/confluence-cloud/docs/edit-content-offline/",
     "q": "Editing existing pages, live docs, blogs posts, and slides that were opened while you were online."
    }
   ]
  },
  {
   "slug": "constant-contact",
   "name": "Constant Contact",
   "category": "Email Marketing",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/constant-contact/#security-offline-remote",
   "trust_center": "https://knowledgebase.constantcontact.com/email-digital-marketing/articles/KnowledgeBase/5632-Security-of-my-data-on-Constant-Contact-servers?lang=en_US",
   "fields": {
    "soc2": {
     "v": "Report (type not stated)",
     "src": "https://knowledgebase.constantcontact.com/email-digital-marketing/articles/KnowledgeBase/5632-Security-of-my-data-on-Constant-Contact-servers?lang=en_US",
     "q": "Our company has a SOC 2 report available for potential and existing customers."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://knowledgebase.constantcontact.com/email-digital-marketing/articles/KnowledgeBase/21905-General-Data-Protection-Regulation-GDPR?lang=en_US",
     "q": "We have incorporated the EU Standard Contractual Clauses and the UK Addendum into our Data Processing Addendum"
    },
    "sso_saml": {
     "v": true,
     "plan": "Teams & Partners multi-account (OIDC-based, not SAML)",
     "src": "https://knowledgebase.constantcontact.com/email-digital-marketing/articles/KnowledgeBase/54082-Partners-Single-Sign-on-SSO?lang=en_US",
     "q": "Teams and Partners who use SSO can enable their Constant Contact accounts to use existing user credentials to log into subaccounts."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://knowledgebase.constantcontact.com/email-digital-marketing/articles/KnowledgeBase/5632-Security-of-my-data-on-Constant-Contact-servers?lang=en_US",
     "q": "New customer accounts are also protected with multi-factor authentication."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "TLS 1.2 over HTTPS in transit; passwords and card numbers encrypted",
     "src": "https://knowledgebase.constantcontact.com/email-digital-marketing/articles/KnowledgeBase/5632-Security-of-my-data-on-Constant-Contact-servers?lang=en_US",
     "q": "All of your account, credit card, and subscriber information and content is encrypted via TLS 1.2 connections over HTTPS."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://knowledgebase.constantcontact.com/email-digital-marketing/tutorials/KnowledgeBase/5928-Download-the-Constant-Contact-Mobile-App?lang=en_US",
     "q": "can be downloaded through the Apple App Store or Google Play Store."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Constant Contact's SSO for Teams and Partners uses OpenID Connect and works with IdPs such as Okta and Microsoft Entra.",
     "src": "https://knowledgebase.constantcontact.com/email-digital-marketing/articles/KnowledgeBase/54082-Partners-Single-Sign-on-SSO?lang=en_US",
     "q": "Constant Contact uses OpenID Connect (OIDC) as an identity authentication protocol to authenticate and authorize users for SSO."
    },
    {
     "topic": "security",
     "text": "The SOC 2 report (type not stated) is shared only under NDA via legal@constantcontact.com.",
     "src": "https://knowledgebase.constantcontact.com/email-digital-marketing/articles/KnowledgeBase/5632-Security-of-my-data-on-Constant-Contact-servers?lang=en_US",
     "q": "Our company has a SOC 2 report available for potential and existing customers."
    },
    {
     "topic": "security",
     "text": "Hosting equipment sits in physically secure facilities with badge and biometric access; the vendor does not name the country on this page.",
     "src": "https://knowledgebase.constantcontact.com/email-digital-marketing/articles/KnowledgeBase/5632-Security-of-my-data-on-Constant-Contact-servers?lang=en_US",
     "q": "The equipment hosting Constant Contact's services is located in physically secure facilities."
    }
   ]
  },
  {
   "slug": "docusign",
   "name": "DocuSign",
   "category": "E-Signature",
   "checked": "2026-09-19",
   "scope": "Docusign eSignature (Personal, Standard, Business Pro, Enhanced plans); many admin controls need a Docusign organization (Docusign Admin) with a claimed domain",
   "profile_url": "https://helpcompare.com/tools/docusign/#security-offline-remote",
   "trust_center": "https://www.docusign.com/trust",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.docusign.com/trust/compliance",
     "q": "such as enterprise-wide ISO 27001:2022 certification, PCI-DSS, and SOC 1 Type 2 and SOC 2 Type 2 reports"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.docusign.com/trust/compliance/certifications",
     "q": "Docusign is ISO 27001:2022, ISO 27017:2015 and 27018:2019 certified"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "PCI DSS v4.0",
      "C5 Type II",
      "IRAP (PROTECTED)",
      "FedRAMP Moderate",
      "DoD IL4",
      "APEC PRP",
      "Canada Protected B",
      "CSA STAR (CAIQ self-assessment)"
     ],
     "src": "https://www.docusign.com/trust/compliance/certifications",
     "q": "Docusign is ISO 27001:2022, ISO 27017:2015 and 27018:2019 certified"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enhanced plans",
     "src": "https://ecom.docusign.com/plans/esignature",
     "q": "HIPAA support through BAA"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.docusign.com/company/terms-and-conditions/data-protection-attachment",
     "q": "This Data Protection Attachment for Docusign Services (“DPA”) is incorporated into and made part of the Agreement."
    },
    "sso_saml": {
     "v": true,
     "plan": "Enhanced plans (Access Management with SSO add-on)",
     "src": "https://support.docusign.com/s/document-item?bundleId=rrf1583359212854&topicId=njp1583359138365.html&_LANG=enus&language=en_US",
     "q": "This feature is only available with the Access Management with SSO add-on. Single Sign-On requires an organization in Docusign Admin."
    },
    "scim": {
     "v": true,
     "plan": "Plan with Organization Management, or Organization Management add-on",
     "src": "https://support.docusign.com/s/document-item?language=en_US&bundleId=rrf1583359212854&topicId=mbl1746565982193.html",
     "q": "Your organization has a plan that includes Organization Management capabilities or have purchased the Organization Management add-on."
    },
    "mfa": {
     "v": true,
     "enforce": "Docusign organization with a claimed domain (plan not stated)",
     "src": "https://support.docusign.com/s/document-item?bundleId=rrf1583359212854&topicId=fnb1668218030221.html&_LANG=enus",
     "q": "Require Two-Step Verification on password logins: If enabled, all managed users must add a secondary addressable proof and activate TSV before they can log in."
    },
    "audit_log": {
     "v": true,
     "src": "https://support.docusign.com/s/document-item?bundleId=rrf1583359212854&topicId=gcj1583359203567.html&_LANG=enus",
     "q": "The organization audit log provides an easy way for administrators to view changes to the accounts linked to the organization and user management actions"
    },
    "data_residency": {
     "v": [
      "US",
      "CA",
      "EU",
      "AU",
      "JP"
     ],
     "plan": "Enhanced plans",
     "src": "https://www.docusign.com/privacy/data-residency",
     "q": "Customers working with a Docusign representative can choose their preferred data center region when setting up an account."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2 in transit",
     "src": "https://www.docusign.com/trust/privacy/data-mgmt-privacy",
     "q": "All Agreement Data is automatically encrypted using AES 256-bit encryption (or equivalent) upon upload"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "In the Docusign iOS and Android apps, a host can download envelopes that were prepared and sent online, then run in-person signing sessions without an internet connection; sending and preparing envelopes still happens online.",
     "src": "https://support.docusign.com/s/document-item?bundleId=gub1579795684748&topicId=yti1579795668049.html&_LANG=enus",
     "q": "With offline signing, you can download envelopes to your iOS device in advance, ensuring that all required documents are readily accessible during in-person signing sessions."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.docusign.com/s/document-item?bundleId=gub1579795684748&topicId=rxa1579795665285.html&_LANG=enus&language=en_US",
     "q": "Check out these resources when preparing and sending envelopes for in-person signers signing offline on Docusign for iOS or Docusign for Android."
    },
    "limits": {
     "v": "Sending or signing for offline use requires a premium account bought in the app or a web plan; only mobile-supported fields can be used.",
     "src": "https://support.docusign.com/s/document-item?bundleId=gub1579795684748&topicId=ogg1579795673336.html&_LANG=enus",
     "q": "Note: To send or sign documents for offline use, you must have a premium account that was purchased through the application or a web plan."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Docusign organization with a claimed domain",
     "src": "https://support.docusign.com/s/document-item?language=en_US&bundleId=rrf1583359212854&topicId=yor1668214161363.html&_LANG=enus",
     "q": "Organization administrators can set a domain level policy for claimed domain users and restrict login and authentication traffic by IP addresses."
    },
    "device_controls": {
     "v": true,
     "summary": "New-device email verification on password logins (can be disabled per domain), required login before opening envelopes, and SSO-only login enforcement for claimed domains.",
     "src": "https://support.docusign.com/s/document-item?bundleId=rrf1583359212854&topicId=fnb1668218030221.html&_LANG=enus",
     "q": "By default, Docusign requires users logging in from an unrecognized device to reverify their email before continuing."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "offline",
     "text": "For field or on-site signings with weak connectivity, the Android app has an Offline Mode for hosting in-person signing sessions.",
     "src": "https://support.docusign.com/s/document-item?bundleId=gub1579795684748&topicId=srh1579795684510.html&_LANG=enus",
     "q": "If your network connection is unstable or if a signer restricts network access on-site, you can use Docusign for Android in Offline Mode."
    },
    {
     "topic": "security",
     "text": "The IP range restriction applies to both password and SSO logins, with up to 30 IPv4 ranges per claimed domain.",
     "src": "https://support.docusign.com/s/document-item?language=en_US&bundleId=rrf1583359212854&topicId=yor1668214161363.html&_LANG=enus",
     "q": "This IP range restriction applies to both password login and SSO login."
    },
    {
     "topic": "remote",
     "text": "Agreement data is stored in one of five regions (US, Canada, Europe, Australia, Japan), and Docusign can't move it to another region after the account is provisioned.",
     "src": "https://www.docusign.com/privacy/data-residency",
     "q": "No, Docusign cannot move customer Agreement Data from one region to another after the initial account provisioning."
    },
    {
     "topic": "office",
     "text": "In-person signing on a tablet or phone uses a host, who must have a Docusign account, and signers, who don't need one.",
     "src": "https://support.docusign.com/s/document-item?bundleId=gub1579795684748&topicId=ogg1579795673336.html&_LANG=enus",
     "q": "Each host must have an account on Docusign."
    }
   ]
  },
  {
   "slug": "dropbox",
   "name": "Dropbox",
   "category": "Cloud Storage",
   "checked": "2026-09-19",
   "scope": "Dropbox team plans: current Business and Business Plus; legacy Standard, Advanced and Enterprise. Help articles list both sets of names.",
   "profile_url": "https://helpcompare.com/tools/dropbox/#security-offline-remote",
   "trust_center": "https://www.dropbox.com/business/trust",
   "fields": {
    "soc2": {
     "v": "Report (type not stated)",
     "src": "https://www.dropbox.com/business/trust/compliance/certifications-compliance",
     "q": "The Dropbox General Use Report is an executive summary of the SOC 2 report and includes the independent third-party auditor’s opinion"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.dropbox.com/business/trust/compliance/certifications-compliance",
     "q": "View the Dropbox Standard, Advanced, Enterprise and Education ISO 27001 certificate."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "ISO 22301",
      "CSA STAR Level 2",
      "ISMAP",
      "PCI DSS (merchant)",
      "EU Cloud Code of Conduct Level 2"
     ],
     "src": "https://www.dropbox.com/business/trust/compliance/certifications-compliance",
     "q": "Dropbox Standard, Advanced, Enterprise and Education have received both the CSA STAR Level 2 Certification and Level 2 Attestation."
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Standard / Business and above",
     "src": "https://help.dropbox.com/account-settings/business-associate-agreement",
     "q": "Dropbox team admins can sign a Business Associate Agreement (BAA) directly through the admin console."
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": true,
     "plan": "Advanced / Business Plus",
     "src": "https://help.dropbox.com/security/sso-admin",
     "q": "If you're an admin of a Dropbox team on Advanced, Business Plus, or Enterprise, you can turn on single sign-on (SSO) for your team."
    },
    "scim": {
     "v": true,
     "plan": "Standard / Business · automated provisioning via Microsoft Entra ID",
     "src": "https://help.dropbox.com/integrations/microsoft-entra-id",
     "q": "Manage provisioning and deprovisioning Dropbox team members users through Microsoft Entra ID"
    },
    "mfa": {
     "v": true,
     "enforce": "All team plans",
     "src": "https://help.dropbox.com/security/2-factor-authentication",
     "q": "Dropbox team admins can require all or some team members to use two-factor authentication."
    },
    "audit_log": {
     "v": true,
     "plan": "Standard / Business",
     "src": "https://help.dropbox.com/account-access/view-activity",
     "q": "Admins have the following events available in their team activity reports:"
    },
    "data_residency": {
     "v": [
      "US",
      "AU",
      "EU",
      "JP",
      "UK"
     ],
     "plan": "Standard / Business",
     "src": "https://help.dropbox.com/security/physical-location-data-storage",
     "q": "Additionally, storage servers are available in Australia, the European Union, Japan, and the United Kingdom for eligible Dropbox users."
    },
    "encryption": {
     "v": "AES-256 at rest; SSL/TLS in transit",
     "src": "https://www.dropbox.com/business/trust/security/architecture",
     "q": "Dropbox files and Dropbox Paper docs at rest are encrypted using 256-bit Advanced Encryption Standard (AES)."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "full",
     "summary": "In the desktop app (Windows, macOS, Linux), files marked available offline can be opened and edited in local apps with no internet connection, and the mobile apps can save files for offline use. Offline changes don't sync until the device is back online.",
     "src": "https://help.dropbox.com/sync/access-files-offline",
     "q": "When you make something available offline, you can open files in Dropbox or view and edit files in applications on your device, without being connected to the internet."
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://help.dropbox.com/installs/system-requirements",
     "q": "Dropbox works on supported versions of Windows, macOS, Linux, Android, iPhone, iPad, and most modern web browsers."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://help.dropbox.com/installs/system-requirements",
     "q": "Dropbox works on supported versions of Windows, macOS, Linux, Android, iPhone, iPad, and most modern web browsers."
    },
    "limits": {
     "v": "Whole folders offline on mobile need Plus, Family, Professional, Standard, Advanced or Enterprise; any plan can make individual files available offline.",
     "plan": "Plus",
     "src": "https://help.dropbox.com/sync/access-files-offline",
     "q": "The ability to make an entire folder available offline is only available to customers on Dropbox Plus, Family, Professional, Standard, Advanced, and Enterprise plans."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "plan": "Standard / Business",
     "summary": "Device approvals (limit which devices members use), remote wipe of linked computers (Business/Advanced and up), and web session control for dropbox.com sessions.",
     "src": "https://help.dropbox.com/account-access/device-approvals",
     "q": "Certain types of admins can use device approvals to manage what devices team members use to access their Dropbox team accounts."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "office",
     "text": "On Enterprise, network control works with your proxy or CASB to decide which Dropbox accounts can sign in and sync on the corporate network.",
     "src": "https://help.dropbox.com/security/network-control",
     "q": "With this feature, IT admins can manage which Dropbox accounts can be used on their corporate network."
    },
    {
     "topic": "offline",
     "text": "Offline edits on a device don't show up on your other devices until that device syncs with Dropbox again.",
     "src": "https://help.dropbox.com/sync/access-files-offline",
     "q": "While you're offline, changes made to your files and folders on your offline device won't sync with Dropbox."
    },
    {
     "topic": "remote",
     "text": "On mobile, offline files update only over Wi-Fi by default unless you change the setting.",
     "src": "https://help.dropbox.com/sync/access-files-offline",
     "q": "By default, your offline files don’t stay continuously updated, or synced, if you’re only connected to data."
    },
    {
     "topic": "security",
     "text": "Remote wipe removes synced files from computers. Phones and tablets can't sync files, so for them it just signs the member out.",
     "src": "https://help.dropbox.com/delete-restore/remote-wipe",
     "q": "Files can’t be synced to phones and tablet, even if they’re made available offline, so there’s no need to remote wipe them."
    }
   ]
  },
  {
   "slug": "figma",
   "name": "Figma",
   "category": "Design Tools",
   "checked": "2026-09-19",
   "scope": "Figma platform (Figma Design, FigJam, Slides, Buzz, Make, Dev Mode). Figma for Government and the standalone Figma Weave are not covered.",
   "profile_url": "https://helpcompare.com/tools/figma/#security-offline-remote",
   "trust_center": "https://compliance.figma.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.figma.com/security/",
     "q": "Figma has an SOC 2 Type 2 report that shows our commitment to protecting customer data through robust security, availability, and confidentiality controls"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.figma.com/security/",
     "q": "Figma has certified its product and services against ISO/IEC 27001:2022 and ISO/IEC 27018:2019."
    },
    "other_certs": {
     "v": [
      "SOC 3",
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "ISO/IEC 42001",
      "FedRAMP Moderate",
      "C5",
      "TISAX",
      "CSA",
      "EU Cloud Code of Conduct"
     ],
     "src": "https://compliance.figma.com/",
     "q": "Badges ISO 27001 ISO 27017 ISO 27018 ISO 27701 ISO 42001 SOC 2 Type II SOC 3 SIG CSA FedRAMP Moderate GDPR CCPA EU Cloud Code of Conduct TISAX VPAT C5"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.figma.com/legal/dpa/",
     "q": "This Data Processing Addendum (“Addendum”) forms part of the agreement(s) between Customer and Figma covering Customer’s use of the Figma Platform"
    },
    "sso_saml": {
     "v": true,
     "plan": "Organization",
     "src": "https://help.figma.com/hc/en-us/articles/360040532333-Guide-to-single-sign-on-SSO-",
     "q": "Available on the Organization and Enterprise plans"
    },
    "scim": {
     "v": true,
     "plan": "Organization",
     "src": "https://www.figma.com/pricing/",
     "q": "Setup SAML single sign-on with your existing identity management system; enforce SSO for all team members and manage provisioning via SCIM."
    },
    "mfa": {
     "v": true,
     "enforce": "Enterprise (Governance+ add-on)",
     "src": "https://www.figma.com/security/",
     "q": "the Governance+ add-on for Figma Enterprise gives you centralized controls like IP allowlisting, network restrictions, enforced 2FA, and extended idle session timeouts."
    },
    "audit_log": {
     "v": true,
     "plan": "Organization",
     "src": "https://www.figma.com/pricing/",
     "q": "Activity logs See a record of actions members have taken in Figma."
    },
    "data_residency": {
     "v": [
      "EU",
      "AU",
      "IN",
      "BR",
      "JP",
      "CA"
     ],
     "plan": "Enterprise",
     "src": "https://help.figma.com/hc/en-us/articles/15643274574871-Enable-localized-file-hosting",
     "q": "organizations on Figma's Enterprise plan can host key parts of their Figma content in a local data center"
    },
    "encryption": {
     "v": "Encrypted in transit and at rest; TLS 1.2+ in transit; customer-managed keys (EKM) with Governance+",
     "src": "https://static.figma.com/uploads/567bfcdf9030e71a9fb05ecebc492a0d03383290",
     "q": "Figma encrypts customer personal data as appropriate in transit and at rest, with the TLS 1.2+ standard used for encrypting personal data being submitted from the internet to Figma’s servers."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "In the browser and desktop app you can keep editing files already open (loaded pages only) and create one new file while offline; libraries, multiplayer and version history need a connection, and offline changes sync when you reconnect.",
     "src": "https://help.figma.com/hc/en-us/articles/360040328553-Work-offline-in-Figma",
     "q": "Figma saves any offline changes to your file(s) when your connection is restored."
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://www.figma.com/downloads/",
     "q": "Desktop app for macOS Desktop app for Windows Desktop app for Windows Arm"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.figma.com/downloads/",
     "q": "Mobile app Figma for iOS and iPad Figma for Android"
    },
    "limits": {
     "v": "Offline changes kept up to 30 days (7 days in Safari); only pages already loaded; one new file; no library components or new plugins.",
     "src": "https://help.figma.com/hc/en-us/articles/360040328553-Work-offline-in-Figma",
     "q": "Figma only stores offline changes for up to 30 days, or 7 days for Safari users."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise (Governance+ add-on)",
     "src": "https://www.figma.com/security/",
     "q": "the Governance+ add-on for Figma Enterprise gives you centralized controls like IP allowlisting, network restrictions, enforced 2FA, and extended idle session timeouts."
    },
    "device_controls": {
     "v": true,
     "plan": "Enterprise",
     "summary": "Idle session timeout, guest access controls, expiring public links (Enterprise); Governance+ adds network access restrictions, file-export restrictions for view-only users and extended idle timeouts.",
     "src": "https://www.figma.com/pricing/",
     "q": "Idle session timeout Set a custom time limit to log users out of their session if they’ve been idle."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "On paid plans, stakeholders can view, comment on and inspect files for free without a paid seat, which helps share work with clients and other teams.",
     "src": "https://www.figma.com/pricing/",
     "q": "If you're on a paid plan, you can let others view and comment on your files without purchasing extra seats."
    },
    {
     "topic": "offline",
     "text": "Figma is cloud-based: full functionality needs an internet connection, and offline work is limited to files already open.",
     "src": "https://help.figma.com/hc/en-us/articles/360040328553-Work-offline-in-Figma",
     "q": "Figma is cloud-based, so you'll need to be connected to the internet to access the full functionality of Figma."
    },
    {
     "topic": "security",
     "text": "Restricting access to office/VPN IP ranges (IP allowlist, network access restrictions) needs the Governance+ add-on on top of Enterprise.",
     "src": "https://help.figma.com/hc/en-us/articles/31825370509591-Governance-for-Figma",
     "q": "IP allowlist"
    },
    {
     "topic": "remote",
     "text": "Direct support is by email only, Monday to Friday, on paid plans; Starter users rely on the Help Center, the AI chat and the community forum.",
     "src": "https://help.figma.com/hc/en-us/articles/360041057214-Explore-Figma-s-help-and-support-resources",
     "q": "Email support is available to those on a Professional, Organization, and Enterprise plan."
    }
   ]
  },
  {
   "slug": "freshbooks",
   "name": "FreshBooks",
   "category": "Accounting & Invoicing",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/freshbooks/#security-offline-remote",
   "trust_center": "https://www.freshbooks.com/policies/security-safeguards",
   "fields": {
    "soc2": {
     "v": "Type I",
     "src": "https://www.freshbooks.com/press/releases/freshbooks-enhances-security-with-successful-completion-of-soc-2-type-1-certification",
     "q": "has announced its successful completion of the Service Organization Control (SOC) 2 Type 1 certification"
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "PCI DSS Level 1"
     ],
     "src": "https://www.freshbooks.com/policies/security-safeguards",
     "q": "FreshBooks maintains its PCI DSS Level 1 compliance and has its audit conducted by an independent third-party on an annual basis."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "All plans (2FA is required for email-and-password logins)",
     "src": "https://support.freshbooks.com/hc/en-us/articles/37113134654733-How-do-I-set-up-two-factor-authentication-for-my-login",
     "q": "For an added layer of security, two-factor authentication (2FA) is required for your FreshBooks account when logging in using an email and password."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "256-bit SSL in transit",
     "src": "https://www.freshbooks.com/policies/security-safeguards",
     "q": "All information traveling between your browser and FreshBooks is protected from eavesdroppers with 256-bit SSL encryption."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.freshbooks.com/mobile-apps",
     "q": "You can download the FreshBooks mobile accounting app from any iPhone or iPad running iOS 15 or higher and any Android device running Android 7.0 or higher."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "FreshBooks stays in sync between the web app and the mobile apps, but some features such as reporting are only available on desktop.",
     "src": "https://www.freshbooks.com/mobile-apps",
     "q": "Some features (like reporting) are only available from your desktop though"
    },
    {
     "topic": "security",
     "text": "FreshBooks hosts its application on Google Cloud Platform.",
     "src": "https://www.freshbooks.com/policies/security-safeguards",
     "q": "The FreshBooks Application utilizes Google Cloud Platform (GCP) for hosting requirements."
    }
   ]
  },
  {
   "slug": "freshdesk",
   "name": "Freshdesk",
   "category": "Customer Support",
   "checked": "2026-09-19",
   "scope": "Freshdesk current plans (Free, Growth, Pro, Enterprise); certifications are Freshworks-wide per the Freshworks Trust Center",
   "profile_url": "https://helpcompare.com/tools/freshdesk/#security-offline-remote",
   "trust_center": "https://trust.freshworks.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://trust.freshworks.com/",
     "q": "Available on request, usually within [1] business day(s): our SOC 1 and SOC 2 Type 2 reports and bridge letters"
    },
    "iso27001": {
     "v": true,
     "src": "https://trust.freshworks.com/",
     "q": "our ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certificates, our SOC 3 report"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27701",
      "CSA STAR Level 1",
      "Cyber Essentials Plus",
      "TX-RAMP"
     ],
     "src": "https://trust.freshworks.com/",
     "q": "our ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certificates, our SOC 3 report"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise",
     "src": "https://support.freshdesk.com/support/solutions/articles/238735-hipaa-configuration-guide",
     "q": "Freshworks may extend support to their compliance towards HIPAA by mutually executing a Business Associate Agreement (BAA)."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://trust.freshworks.com/",
     "q": "our sub-processor list, our Data Processing Agreement and technical and organisational measures"
    },
    "sso_saml": {
     "v": true,
     "plan": "Growth",
     "src": "https://www.freshworks.com/freshdesk/pricing/",
     "q": "Configure and provide SAML Single Sign On for your agents so they do not have to provide separate login credentials."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Yes, org admin policy (plan not stated)",
     "src": "https://support.freshworks.com/support/solutions/articles/50000003252-how-can-an-organization-admin-enforce-2fa-as-a-policy-for-all-or-some-users-in-the-organization-",
     "q": "organization admins can enforce 2FA as a policy for all or some users and groups."
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.freshworks.com/freshdesk/pricing/",
     "q": "Audit Log in Freshdesk serves as a one-stop for Admins to changes made to Automations, Agent profiles and more."
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "UAE",
      "IN",
      "AU"
     ],
     "src": "https://support.freshdesk.com/support/solutions/articles/235810-where-is-your-data-servers-located-",
     "q": "Our Data Centres are located in: US EEA UAE IND AU You can choose your preferred data location when you sign up for your account."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2 in transit",
     "src": "https://www.freshworks.com/security/",
     "q": "AES 256-bit encryption when data is encrypted at rest and HTTPS with TLS 1.2 encryption for data in transit."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.freshdesk.com/support/solutions/articles/206721-faqs-and-troubleshooting",
     "q": "We're currently focused on giving our users the best possible experience on iOS and Android and don't have plans for a Windows app at the moment."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.freshworks.com/freshdesk/pricing/",
     "q": "Increase helpdesk security by controlling who can log into the portal using their IP addresses."
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Day passes give occasional or temporary agents one day of access instead of a full license; the per-pass price is $2 on Growth, $7 on Pro and $12 on Enterprise.",
     "src": "https://www.freshworks.com/freshdesk/pricing/",
     "q": "Day passes provide occasional agents with temporary access for a day instead of purchasing a full license."
    },
    {
     "topic": "security",
     "text": "You pick the data center region at sign-up. Moving to another region later means contacting Freshdesk support.",
     "src": "https://support.freshdesk.com/support/solutions/articles/235810-where-is-your-data-servers-located-",
     "q": "If you have particular regulatory requirements and performance considerations and are considering migrating your data to a different data center region, contact support@freshdesk.com."
    },
    {
     "topic": "security",
     "text": "The Freshworks BAA covers only Freshdesk, Freshchat, Freshcaller and Freshdesk Omnichannel, not other Freshworks products.",
     "src": "https://support.freshdesk.com/support/solutions/articles/238735-hipaa-configuration-guide",
     "q": "The scope of BAA is limited to Freshdesk, Freshchat Freshcaller, and Freshdesk Omnichannel products that are offered by Freshworks Freshdesk suite."
    }
   ]
  },
  {
   "slug": "gemini",
   "name": "Gemini",
   "category": "AI Assistants",
   "checked": "2026-09-19",
   "scope": "Gemini as a core service of Google Workspace Business/Enterprise editions (Gemini app, Gemini in Workspace apps, Gemini Notebook). Controls are Google Workspace controls; personal-account Gemini (Google AI Plus/Pro/Ultra) has different data terms.",
   "profile_url": "https://helpcompare.com/tools/gemini/#security-offline-remote",
   "trust_center": "https://workspace.google.com/security/ai-privacy/",
   "fields": {
    "soc2": {
     "src": "https://support.google.com/a/answer/15706919?hl=en",
     "q": "Gemini has attained SOC 1/2/3, ISO 9001 , ISO/IEC 27001 , 27701 , 27017 , 27018 , and 42001 certifications."
    },
    "iso27001": {
     "v": true,
     "src": "https://support.google.com/a/answer/15706919?hl=en",
     "q": "Gemini has attained SOC 1/2/3, ISO 9001 , ISO/IEC 27001 , 27701 , 27017 , 27018 , and 42001 certifications."
    },
    "other_certs": {
     "v": [
      "SOC 1",
      "SOC 3",
      "ISO 9001",
      "ISO/IEC 27701",
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 42001",
      "FedRAMP High",
      "BSI C5"
     ],
     "src": "https://support.google.com/a/answer/15706919?hl=en",
     "q": "Gemini has attained SOC 1/2/3, ISO 9001 , ISO/IEC 27001 , 27701 , 27017 , 27018 , and 42001 certifications. Gemini has FedRAMP High authorization ."
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://support.google.com/a/answer/15706919?hl=en",
     "q": "Gemini can support HIPAA workloads. The HIPAA Included Functionality and the Google Workspace and Cloud Identity HIPAA implementation guide have been updated to reflect the inclusion of Gemini."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://support.google.com/a/answer/15706919?hl=en",
     "q": "Your use of Gemini with the Workspace app is governed by your organization's Workspace agreement, including the Cloud Data Processing Addendum ."
    },
    "sso_saml": {
     "v": true,
     "plan": "Business Starter",
     "src": "https://knowledge.workspace.google.com/admin/getting-started/editions/compare-business-editions",
     "q": "Single Sign On (SSO) using a 3rd-party IdP ✔* ✔* ✔*"
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Business Starter",
     "src": "https://support.google.com/a/answer/9176657?hl=en",
     "q": "Your users can choose their 2SV method, or you can enforce a method for certain users or groups in your organization."
    },
    "audit_log": {
     "v": true,
     "plan": "Business Starter",
     "src": "https://knowledge.workspace.google.com/admin/getting-started/editions/compare-business-editions",
     "q": "Audit and investigation tool Log event reporting ( See specific log events ) ✔* ✔* ✔*"
    },
    "data_residency": {
     "v": [
      "US",
      "EU"
     ],
     "plan": "Business Standard",
     "src": "https://support.google.com/a/answer/7630496?hl=en",
     "q": "Your location options are the United States, European Union (labeled Europe in the Google Admin console), or No preference."
    },
    "encryption": {
     "v": "AES-256 at rest and in transit (Drive/Docs files); client-side encryption available on Enterprise Plus",
     "src": "https://support.google.com/drive/answer/10519333?hl=en&co=GENIE.Platform%3DDesktop",
     "q": "All files uploaded to Drive or created in Docs, Sheets, and Slides are encrypted in transit and at rest with AES256 bit encryption."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "none",
     "summary": "Gemini's desktop apps require an internet connection to use Gemini's features; no offline mode is documented.",
     "src": "https://support.google.com/gemini/answer/17011627?hl=en",
     "q": "A stable internet connection is required to use Gemini's features."
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://support.google.com/gemini/answer/18263854?hl=en",
     "q": "A personal Google Account or a work or school Google Account with access to Gemini turned on by your administrator. A PC running Windows 10 or later ."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.google.com/a/answer/14130944?hl=en",
     "q": "The Gemini app includes: The Gemini web app at gemini.google.com Gemini mobile app on Android and iOS Gemini in Chrome Gemini on Mac"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.google.com/a/answer/15706919?hl=en",
     "q": "restricting access to only those users who are in the appropriate context (such as user's device posture, network traits)"
    },
    "device_controls": {
     "v": true,
     "plan": "Business Starter",
     "summary": "Fundamental endpoint management on all Business editions: remote account sign-out, block devices, basic mobile device management, endpoint verification; advanced mobile management and remote device wipe on Business Plus; Context-Aware Access on Enterprise.",
     "src": "https://knowledge.workspace.google.com/admin/getting-started/editions/compare-business-editions",
     "q": "Remote account sign-out ✔* ✔* ✔* Remote account wipe (mobile) ✔* ✔* ✔* Block devices ✔* ✔* ✔*"
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Gemini app chats and uploads from users with a Workspace license are not human-reviewed or used to train models; users signed in with personal Google accounts do not get this protection.",
     "src": "https://support.google.com/gemini/answer/14620100?hl=en&co=DASHER._Family%3DBusiness-Enterprise",
     "q": "Your chats and uploaded files in Gemini Apps won’t be reviewed by human reviewers or otherwise used to improve generative AI models."
    },
    {
     "topic": "remote",
     "text": "Admins can retain, hold, search and export Gemini app conversations with Google Vault regardless of user deletion settings.",
     "src": "https://knowledge.workspace.google.com/vault/retention/retain-gemini-app-messages-with-vault",
     "q": "Regardless of whether a user's action or setting causes the deletion of Gemini app conversations, admins can retain, hold, search, and export Gemini app conversations with Vault."
    },
    {
     "topic": "security",
     "text": "Gemini Notebook data is stored as separate copies and is not covered by the organization's data region settings.",
     "src": "https://support.google.com/a/answer/15706919?hl=en",
     "q": "Your organization's file sharing and data region settings do not apply to data in Gemini Notebook."
    },
    {
     "topic": "remote",
     "text": "The Gemini desktop app for Mac requires macOS Sequoia 15 or later on Apple Silicon.",
     "src": "https://support.google.com/gemini/answer/17011627?hl=en",
     "q": "A Mac running macOS Sequoia (15.0) or later with Apple Silicon, 8 GB of RAM or more, and at least 200 MB of available disk space for installation."
    }
   ]
  },
  {
   "slug": "gohighlevel",
   "name": "GoHighLevel",
   "category": "CRM & Agency Software",
   "checked": "2026-09-19",
   "scope": "HighLevel agency platform (also sold white-labeled; LeadConnector is its app brand)",
   "profile_url": "https://helpcompare.com/tools/gohighlevel/#security-offline-remote",
   "trust_center": "https://www.gohighlevel.com/privacy-and-security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.gohighlevel.com/privacy-and-security",
     "q": "HighLevel undergoes annual SOC 2 Type II assessments."
    },
    "iso27001": {
     "v": true,
     "src": "https://help.gohighlevel.com/support/solutions/articles/155000000574-highlevel-security-and-compliance-overview",
     "q": "downloadable/viewable documents including HighLevel’s Information Security Program, ISO/IEC 27001:2022 Certificate, and SOC 2 Attestation Report."
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Paid add-on (can’t be turned off once enabled)",
     "src": "https://help.gohighlevel.com/support/solutions/articles/48000983084-hipaa-compliance-with-highlevel",
     "q": "HighLevel offers an optional, account-wide HIPAA add-on that enables encryption of ePHI, Business-Associate Agreements (BAAs), audit logging, and MFA enforcement."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://help.gohighlevel.com/support/solutions/articles/155000000574-highlevel-security-and-compliance-overview",
     "q": "We also maintain a list of our sub-processors (which may change from time-to-time) within our Data Processing Agreement."
    },
    "sso_saml": {
     "v": true,
     "plan": "Agency Pro (OpenID Connect only, not SAML)",
     "src": "https://help.gohighlevel.com/support/solutions/articles/155000004387-setting-up-single-sign-on-sso-on-highlevel",
     "q": "Currently, HighLevel supports OIDC only . SAML is not yet supported, but it is part of the future roadmap."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Not plan-gated in vendor docs (portal admin setting)",
     "src": "https://help.gohighlevel.com/support/solutions/articles/155000000574-highlevel-security-and-compliance-overview",
     "q": "Portal administrators may require all users to have two-factor authentication enabled."
    },
    "audit_log": {
     "v": true,
     "src": "https://help.gohighlevel.com/support/solutions/articles/155000006667-audit-logs",
     "q": "Audit Logs are the source of truth for who did what and when across your HighLevel account."
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://help.gohighlevel.com/support/solutions/articles/155000000574-highlevel-security-and-compliance-overview",
     "q": "Our product infrastructure resides in the United States."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2+ in transit",
     "src": "https://www.gohighlevel.com/privacy-and-security",
     "q": "Encryption: TLS 1.2+ (in transit) and AES-256 (at rest)"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://help.gohighlevel.com/support/solutions/articles/155000006704-download-highlevel-leadconnector-desktop-app-for-windows-macos-linux",
     "q": "We’re excited to introduce the HighLevel Desktop App for macOS, Windows and Linux ."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://help.gohighlevel.com/support/solutions/articles/155000007191-custom-dispositions-for-voice-calls",
     "q": "Custom Dispositions are supported in the HighLevel, LeadConnector, and whitelabeled mobile apps on both iOS and Android."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "HighLevel offers SSO only over OpenID Connect (OIDC), which requires the $497 Agency Pro plan and a white-label domain.",
     "src": "https://help.gohighlevel.com/support/solutions/articles/155000004387-setting-up-single-sign-on-sso-on-highlevel",
     "q": "Before enabling SSO, two conditions must be met: Your agency must be on the $497 plan . A Whitelabel domain must already be configured."
    },
    {
     "topic": "security",
     "text": "HighLevel's HIPAA add-on cannot be disabled once purchased, and accounts are not HIPAA compliant by default.",
     "src": "https://help.gohighlevel.com/support/solutions/articles/48000983084-hipaa-compliance-with-highlevel",
     "q": "HighLevel accounts are NOT HIPAA compliant by default . Once HIPAA is purchased and enabled, it applies to all location accounts within your account and cannot be deactivated ."
    },
    {
     "topic": "security",
     "text": "Audit log entries are kept for 60 days.",
     "src": "https://help.gohighlevel.com/support/solutions/articles/155000006667-audit-logs",
     "q": "how long data is retained (60 days)"
    },
    {
     "topic": "office",
     "text": "HighLevel says it is not PCI-DSS compliant itself and relies on PCI-compliant payment processors.",
     "src": "https://help.gohighlevel.com/support/solutions/articles/155000000574-highlevel-security-and-compliance-overview",
     "q": "HighLevel does not store, process, or collect credit card information submitted to us by customers, and we are not PCI-DSS compliant."
    }
   ]
  },
  {
   "slug": "google-drive",
   "name": "Google Drive",
   "category": "Cloud Storage",
   "checked": "2026-09-19",
   "scope": "Google Drive in paid Google Workspace editions; admin features vary by edition (Business Starter to Enterprise Plus)",
   "profile_url": "https://helpcompare.com/tools/google-drive/#security-offline-remote",
   "trust_center": "https://workspace.google.com/security/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://cloud.google.com/security/compliance/soc-2",
     "q": "The core Google Cloud and Google Workspace SOC 2 Type II reports are issued quarterly and can be downloaded via the Compliance Reports Manager."
    },
    "iso27001": {
     "v": true,
     "src": "https://cloud.google.com/security/compliance/iso-27001",
     "q": "Google Cloud, Google Workspace, and Apigee ISO/IEC 27001 certificates may be requested using the Compliance Reports Manager."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "FedRAMP",
      "BSI C5",
      "MTCS (Singapore)"
     ],
     "src": "https://workspace.google.com/learn-more/security/security-whitepaper/page-5/",
     "q": "Google also participates in sector and country-specific frameworks, such as FedRAMP (US government), BSI C5 (Germany), MTCS (Singapore), and many others."
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://support.google.com/a/answer/3407054?hl=en",
     "q": "Administrators must review and accept a BAA before using PHI in Google services."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://workspace.google.com/terms/dpa_terms.html",
     "q": "This Cloud Data Processing Addendum (including its appendices, the “Addendum”) is incorporated into the Agreement(s) (as defined below) between Google and Customer."
    },
    "sso_saml": {
     "v": true,
     "src": "https://support.google.com/a/answer/12032922?hl=en",
     "q": "Google Workspace supports both SAML-based and OIDC-based SSO."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Admins can require 2SV (edition not stated)",
     "src": "https://support.google.com/a/answer/9176657?hl=en",
     "q": "Your users can choose their 2SV method, or you can enforce a method for certain users or groups in your organization."
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise Standard (Drive log events)",
     "src": "https://support.google.com/a/answer/4579696?hl=en",
     "q": "Supported editions for this feature: Frontline Standard and Frontline Plus; Enterprise Standard and Enterprise Plus; Education Standard and Education Plus"
    },
    "data_residency": {
     "v": [
      "US",
      "EU"
     ],
     "plan": "Business Standard",
     "src": "https://support.google.com/a/answer/7630496?hl=en",
     "q": "Your location options are the United States, European Union (labeled Europe in the Google Admin console), or No preference."
    },
    "encryption": {
     "v": "All customer data encrypted in transit; stored data encrypted at rest",
     "src": "https://workspace.google.com/learn-more/security/security-whitepaper/page-4/",
     "q": "Second, we encrypt all customer data while it is “in transit”—traveling over the Internet and across the Google network between data centers."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "full",
     "summary": "Docs, Sheets and Slides files you've made available offline can be viewed and edited in Chrome or Edge with the Docs Offline extension, or in the Docs, Sheets and Slides mobile apps. Drive for desktop keeps mirrored and offline-marked files on the computer. Offline edits are applied once you're back online.",
     "src": "https://support.google.com/drive/answer/2375012?hl=en",
     "q": "If you aren't connected to the Internet, you can still view and edit files, including: Google Docs Google Sheets Google Slides"
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://support.google.com/drive/answer/2375012?hl=en",
     "q": "Drive for desktop is an application for Windows and macOS that lets you quickly access content directly from your desktop"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.google.com/drive/answer/2375012?hl=en&co=GENIE.Platform%3DAndroid",
     "q": "If you aren't connected to a Wi-Fi or mobile network, you can still view and edit files, including: Google Docs Google Sheets Google Slides"
    },
    "limits": {
     "v": "Offline use in the browser needs Chrome or Edge with the Google Docs Offline extension and doesn't work in private browsing. On iPhone and iPad, offline editing happens in the Docs, Sheets and Slides apps.",
     "src": "https://support.google.com/drive/answer/2375012?hl=en",
     "q": "You must use the Google Chrome or Microsoft Edge browser. Don't use private browsing."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise Standard (Context-Aware Access)",
     "src": "https://support.google.com/a/answer/9275380?hl=en",
     "q": "you can create granular access control security policies for apps based on attributes, such as user identity, location, device security status, and IP address."
    },
    "device_controls": {
     "v": true,
     "plan": "Enterprise Standard (Context-Aware Access)",
     "summary": "Context-Aware Access can limit app access by device security status, company-owned devices, encrypted storage and network location.",
     "src": "https://support.google.com/a/answer/9275380?hl=en",
     "q": "Allow access to apps only from company-issued devices Allow access to Drive only if a user storage device is encrypted"
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "offline",
     "text": "Edits made offline are applied when you reconnect. Newer changes overwrite older ones, and earlier versions stay in version history.",
     "src": "https://support.google.com/drive/answer/2375012?hl=en",
     "q": "Changes are implemented when you’re back online. New changes overwrite previous changes."
    },
    {
     "topic": "offline",
     "text": "If a Drive for desktop account is disconnected, streamed files that were saved offline are removed; mirrored files stay on the computer.",
     "src": "https://support.google.com/drive/answer/2375012?hl=en",
     "q": "If you disconnect your Google Drive account, offline streamed files are removed. Mirrored files remain."
    },
    {
     "topic": "office",
     "text": "On Enterprise Standard and above, Context-Aware Access can block app access from outside the corporate network.",
     "src": "https://support.google.com/a/answer/9275380?hl=en",
     "q": "Restrict access to apps from outside the corporate network"
    },
    {
     "topic": "remote",
     "text": "With a work account, the organization may block Drive for desktop or need to install it for users.",
     "src": "https://support.google.com/drive/answer/10838124?hl=en",
     "q": "If you use a work or school account, you might not be able to use Google Drive for desktop or your organization might have to install it for you."
    }
   ]
  },
  {
   "slug": "google-meet",
   "name": "Google Meet",
   "category": "Video Conferencing",
   "checked": "2026-09-19",
   "scope": "Google Meet as part of Google Workspace business/enterprise editions; certifications and DPA are Google Workspace-level. Personal (free) Google accounts are not covered by Workspace admin controls.",
   "profile_url": "https://helpcompare.com/tools/google-meet/#security-offline-remote",
   "trust_center": "https://workspace.google.com/security/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://cloud.google.com/security/compliance/soc-2",
     "q": "The core Google Cloud and Google Workspace SOC 2 Type II reports are issued quarterly"
    },
    "iso27001": {
     "v": true,
     "src": "https://workspace.google.com/learn-more/security/security-whitepaper/page-5/",
     "q": "ISO/IEC 27001 (Information Security Management)"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "SOC 3"
     ],
     "src": "https://workspace.google.com/learn-more/security/security-whitepaper/page-5/",
     "q": "ISO/IEC 27017 (Cloud Security) ISO/IEC 27018 (Cloud Privacy) ISO/IEC 27701 (Privacy) SOC 2 and SOC 3 reports"
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://knowledge.workspace.google.com/admin/compliance/hipaa-compliance-with-google-workspace-and-cloud-identity",
     "q": "must enter a Business Associate Amendment (BAA) with Google."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://cloud.google.com/terms/data-processing-addendum/",
     "q": "is incorporated into the Agreement(s) (as defined below) between Google and Customer."
    },
    "sso_saml": {
     "v": true,
     "src": "https://knowledge.workspace.google.com/admin/apps/setting-up-sso",
     "q": "Google Workspace supports both SAML-based and OIDC-based SSO."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://knowledge.workspace.google.com/admin/security/deploy-2-step-verification",
     "q": "For Enforcement , choose an option: On —Starts immediately."
    },
    "audit_log": {
     "v": true,
     "src": "https://knowledge.workspace.google.com/admin/reports/meet-log-events",
     "q": "As your organization's administrator, you can run searches and take action on Meet log events."
    },
    "data_residency": {
     "v": [
      "US",
      "EU"
     ],
     "plan": "Business Standard",
     "src": "https://knowledge.workspace.google.com/admin/compliance/choose-a-geographic-location-for-your-data",
     "q": "Your location options are the United States, European Union (labeled Europe in the Google Admin console), or No preference."
    },
    "encryption": {
     "v": "Encrypted in transit by default (DTLS/SRTP); Meet recordings in Google Drive encrypted at rest",
     "src": "https://support.google.com/meet/answer/9852160?hl=en",
     "q": "All data in Meet is encrypted in transit by default between the client and Google for video meetings on a web browser"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "none",
     "summary": "Meet is a live video service with no offline mode; Google lists a broadband internet connection as a requirement.",
     "src": "https://support.google.com/meet/answer/7317473?hl=en",
     "q": "A broadband connection to the internet."
    },
    "desktop": {
     "v": [],
     "src": "https://support.google.com/meet/answer/7317473?hl=en",
     "q": "The Meet mobile app or the Gmail mobile app or a supported web browser"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.google.com/meet/answer/9852160?hl=en",
     "q": "on the Meet Android and Apple® iOS® apps"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise Standard",
     "src": "https://knowledge.workspace.google.com/admin/security/protect-your-business-with-context-aware-access",
     "q": "Specifies an IP address range from which a user can connect to an app"
    },
    "device_controls": {
     "v": true,
     "plan": "Enterprise Standard",
     "summary": "Context-Aware Access policies by device security status, OS, IP range and country (Enterprise Standard and up, Frontline Standard, Education Standard, Cloud Identity Premium).",
     "src": "https://knowledge.workspace.google.com/admin/security/protect-your-business-with-context-aware-access",
     "q": "Using Context-Aware Access, you can create granular access control security policies for apps based on attributes, such as user identity, location, device security status, and IP address."
    },
    "office_hardware": {
     "v": "Google Meet hardware kits turn conference rooms into Meet video-conference spaces; they need a display with HDMI, DVI or DisplayPort input.",
     "src": "https://knowledge.workspace.google.com/admin/meet-hardware/google-meet-hardware-requirements",
     "q": "You need a few things to turn a room into a video conference space with Google Meet hardware."
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Google's planning figure for large organizations is about 1 Mbps out / 1.3 Mbps in per video participant; audio-only is about 12/18 Kbps.",
     "src": "https://knowledge.workspace.google.com/admin/meet/prepare-your-network-for-meet-meetings-and-live-streams",
     "q": "Average bandwidth per participant for large organizations Meeting type Outbound Inbound Video 1 Mbps 1.3 Mbps Audio only 12 Kbps 18 Kbps"
    },
    {
     "topic": "remote",
     "text": "Phone dial-in for Meet must be turned on by an administrator.",
     "src": "https://support.google.com/meet/answer/9518557?hl=en",
     "q": "Tip: An administrator needs to turn on dial-in by phone."
    },
    {
     "topic": "security",
     "text": "Data-region policies only cover users on a supported Workspace edition.",
     "src": "https://knowledge.workspace.google.com/admin/compliance/choose-a-geographic-location-for-your-data",
     "q": "Users who don't have a supported edition aren't covered by data region policies—even if you apply a data region policy to their organizational unit."
    },
    {
     "topic": "security",
     "text": "Meet recordings saved to Google Drive are encrypted at rest by default.",
     "src": "https://support.google.com/meet/answer/9852160?hl=en",
     "q": "Meet recordings stored in Google Drive are encrypted at rest by default."
    }
   ]
  },
  {
   "slug": "google-workspace",
   "name": "Google Workspace",
   "category": "Business Email & Office Suites",
   "checked": "2026-09-19",
   "scope": "Google Workspace Business editions (Starter/Standard/Plus) and Enterprise; controls are Admin console features.",
   "profile_url": "https://helpcompare.com/tools/google-workspace/#security-offline-remote",
   "trust_center": "https://workspace.google.com/security/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://cloud.google.com/security/compliance/soc-2",
     "q": "The core Google Cloud and Google Workspace SOC 2 Type II reports are issued quarterly and can be downloaded via the Compliance Reports Manager ."
    },
    "iso27001": {
     "v": true,
     "src": "https://cloud.google.com/security/compliance/iso-27001",
     "q": "Google Cloud, Google Workspace, and Apigee ISO/IEC 27001 certificates may be requested using the Compliance Reports Manager ."
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://support.google.com/a/answer/3407054?hl=en",
     "q": "Administrators must review and accept a BAA before using PHI in Google services."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://support.google.com/a/answer/15706919?hl=en",
     "q": "Your use of Gemini with the Workspace app is governed by your organization's Workspace agreement, including the Cloud Data Processing Addendum ."
    },
    "sso_saml": {
     "v": true,
     "plan": "Business Starter",
     "src": "https://knowledge.workspace.google.com/admin/getting-started/editions/compare-business-editions",
     "q": "Single Sign On (SSO) using a 3rd-party IdP ✔* ✔* ✔*"
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Business Starter",
     "src": "https://knowledge.workspace.google.com/admin/getting-started/editions/compare-business-editions",
     "q": "2-Step Verification ✔* ✔* ✔*"
    },
    "audit_log": {
     "v": true,
     "plan": "Business Starter",
     "src": "https://knowledge.workspace.google.com/admin/getting-started/editions/compare-business-editions",
     "q": "Audit and investigation tool Log event reporting ( See specific log events ) ✔* ✔* ✔*"
    },
    "data_residency": {
     "v": [
      "US",
      "EU"
     ],
     "plan": "Business Standard",
     "src": "https://support.google.com/a/answer/7630496?hl=en",
     "q": "Your location options are the United States, European Union (labeled Europe in the Google Admin console), or No preference."
    },
    "encryption": {
     "v": "AES-256 at rest and in transit for Drive/Docs files",
     "src": "https://support.google.com/drive/answer/10519333?hl=en&co=GENIE.Platform%3DDesktop",
     "q": "All files uploaded to Drive or created in Docs, Sheets, and Slides are encrypted in transit and at rest with AES256 bit encryption."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "full",
     "summary": "Docs, Sheets and Slides can be created and edited offline in Chrome or Edge once offline access and the Docs Offline extension are turned on; recently opened files are saved locally and sync when back online.",
     "src": "https://support.google.com/docs/answer/6388102?hl=en",
     "q": "If you aren't connected to the internet, you can still create, view, and edit files on: Google Docs Google Sheets Google Slides"
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://support.google.com/drive/answer/10838124?hl=en",
     "q": "Install Google Drive for desktop Install on Windows Install on macOS"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://apps.apple.com/us/app/gmail-email-by-google/id422689480",
     "q": "Gmail - Email by Google App - App Store"
    },
    "limits": {
     "v": "Offline editing needs Chrome or Edge (not private browsing) and the Google Docs Offline extension, set up while online.",
     "src": "https://support.google.com/docs/answer/6388102?hl=en",
     "q": "You must use the Google Chrome or Microsoft Edge browser. Don't use private browsing. Install and turn on Google Docs Offline Chrome extension ."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://workspace.google.com/pricing?hl=en",
     "q": "Context-aware access"
    },
    "device_controls": {
     "v": true,
     "plan": "Business Starter",
     "summary": "Fundamental endpoint management on all Business editions (remote account sign-out and mobile account wipe, block devices, endpoint verification); Business Plus adds advanced mobile management and remote device wipe; Enterprise adds context-aware access and enterprise endpoint management.",
     "src": "https://knowledge.workspace.google.com/admin/getting-started/editions/compare-business-editions",
     "q": "Remote account wipe (mobile) ✔* ✔* ✔* ... Remote device wipe [blank] [blank] ✔*"
    },
    "office_hardware": {
     "v": "Google sells Google Meet Hardware for meeting rooms as a separate add-on; room booking ('Browse and reserve conference rooms') is on all plans.",
     "src": "https://workspace.google.com/pricing?hl=en",
     "q": "Google Meet Hardware Fast, reliable, easy-to-join web meetings and video conferencing services for any size meeting room."
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Meet caps meetings at 100 participants on Business Starter, 150 on Standard, 500 on Plus and 1,000 on Enterprise, each up to 24 hours.",
     "src": "https://workspace.google.com/pricing?hl=en",
     "q": "Meet Video and voice conferencing 100 group 150 group 500 group 1000 group Meeting length (maximum) 24 hours"
    },
    {
     "topic": "offline",
     "text": "Offline editing of Docs, Sheets and Slides only works in Chrome or Edge with the Docs Offline extension, so plan for that browser on laptops used in the field.",
     "src": "https://support.google.com/docs/answer/6388102?hl=en",
     "q": "You must use the Google Chrome or Microsoft Edge browser. Don't use private browsing."
    },
    {
     "topic": "security",
     "text": "A full admin data export starts no earlier than 48 hours after it is requested and typically takes 72 hours, up to 14 days.",
     "src": "https://support.google.com/a/answer/100458?hl=en",
     "q": "The export is available no earlier than 48 hours after you start the export. ... Data export typically takes 72 hours but can take up to 14 days"
    },
    {
     "topic": "office",
     "text": "Business Starter, Standard and Plus are capped at 300 users; larger organisations need an Enterprise plan.",
     "src": "https://workspace.google.com/pricing?hl=en",
     "q": "Starter, Standard, and Plus plans can be purchased for a maximum of 300 users."
    }
   ]
  },
  {
   "slug": "gotomeeting",
   "name": "GoToMeeting",
   "category": "Video Conferencing",
   "checked": "2026-09-19",
   "scope": "GoTo Meeting commercial plans; HIPAA use is via the separate GoTo Meeting for Healthcare plan (North America only). Compliance data from GoTo's Technical and Organizational Security Measures (TOMs) document linked from goto.com/company/trust/compliance/meeting.",
   "profile_url": "https://helpcompare.com/tools/gotomeeting/#security-offline-remote",
   "trust_center": "https://www.goto.com/company/trust",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://edge.sitecorecloud.io/gototechnol00e8-mktglobalxm07e7-mktglobalpr9498-b870/media/goto/pdfs/trust-resource-center/oct-2025-gtm-w-t-toms.pdf",
     "q": "GoTo Meeting, GoTo Webinar and GoTo Training holds SOC 2 / SOC 3 Type II, BSI C5, PCI DSS, TRUSTe Enterprise Privacy certifications"
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "SOC 3",
      "BSI C5",
      "PCI DSS",
      "TRUSTe Enterprise Privacy",
      "Global CBPR",
      "Global PRP",
      "APEC CBPR",
      "APEC PRP"
     ],
     "src": "https://edge.sitecorecloud.io/gototechnol00e8-mktglobalxm07e7-mktglobalpr9498-b870/media/goto/pdfs/trust-resource-center/oct-2025-gtm-w-t-toms.pdf",
     "q": "GoTo Meeting, GoTo Webinar and GoTo Training holds SOC 2 / SOC 3 Type II, BSI C5, PCI DSS, TRUSTe Enterprise Privacy certifications"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "GoTo Meeting for Healthcare",
     "src": "https://support.goto.com/meeting/help/plan-overview-gotomeeting-for-healthcare",
     "q": "GoTo Meeting for Healthcare, in conjunction with a Business Associate Agreement (BAA), is HIPAA compatible and tailored for our customers in the healthcare industry"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.goto.com/company/legal/data-processing-addendum",
     "q": "This Data Processing Addendum includes Schedules 1 (Processing Description) and 2 (Regional Transfer Terms)."
    },
    "sso_saml": {
     "v": true,
     "src": "https://support.goto.com/meeting/help/single-sign-on-options-g2m790666",
     "q": "Set up a SAML-based single sign-on (SSO) option for your global GoTo account to provide a simplified sign-in experience for your users."
    },
    "scim": {
     "v": true,
     "src": "https://support.goto.com/meeting/help/automated-provisioning-options",
     "q": "You can have your development team build a custom solution for your organization using the SCIM APIs and Administration REST APIs."
    },
    "mfa": {
     "v": true,
     "src": "https://support.goto.com/meeting/help/how-do-i-set-up-and-use-multi-factor-authentication-for-my-goto-meeting-account",
     "q": "You can enable Multi-Factor Authentication (MFA) for your account to add a level of security on your account"
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "TLS 1.2+ in transit; AES-256 at rest for customer content",
     "src": "https://edge.sitecorecloud.io/gototechnol00e8-mktglobalxm07e7-mktglobalpr9498-b870/media/goto/pdfs/trust-resource-center/oct-2025-gtm-w-t-toms.pdf",
     "q": "In Transit - Transport Layer Security (TLS) v1.2 or higher. o At Rest - Advanced Encryption Standard (AES) 256-bit for Customer Content."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://support.goto.com/meeting/help/system-requirements",
     "q": "Windows 10 or newer macOS 12 or newer Linux/Ubuntu (web browser only)"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.goto.com/meeting/help/system-requirements",
     "q": "Apple phone or iPad: iOS 15.1 or newer Android phone or tablet: Android OS 8 (Oreo) or newer"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "GoTo no longer sells GoTo Room hardware kits or licenses; existing Poly, Logitech and Dolby kits still work, and rooms can join via SIP/H.323 audio gateways.",
     "src": "https://support.goto.com/meeting/help/how-do-i-identify-my-goto-room-hardware",
     "q": "Although the hardware still works for existing customers, we are no longer offering any GoTo Room hardware kits or licenses."
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "GoTo asks for 1 Mbps or better on computers; mobile devices need 3G or better, with WiFi recommended for VoIP audio.",
     "src": "https://support.goto.com/meeting/help/system-requirements",
     "q": "Computer: 1 Mbps or better (high-speed connection) Mobile device and Chromebook: 3G or better (WiFi recommended for VoIP audio)"
    },
    {
     "topic": "remote",
     "text": "Participants can dial into sessions by phone (PSTN).",
     "src": "https://edge.sitecorecloud.io/gototechnol00e8-mktglobalxm07e7-mktglobalpr9498-b870/media/goto/pdfs/trust-resource-center/oct-2025-gtm-w-t-toms.pdf",
     "q": "PSTN: Public switched telephone network allows users to dial into sessions via physical or IP telephones."
    },
    {
     "topic": "office",
     "text": "SIP or H.323 conference-room devices can connect to session audio via GoTo's gateway.",
     "src": "https://edge.sitecorecloud.io/gototechnol00e8-mktglobalxm07e7-mktglobalpr9498-b870/media/goto/pdfs/trust-resource-center/oct-2025-gtm-w-t-toms.pdf",
     "q": "H.323-/SIP-Gateway: Enables connection to session audio via SIP or H.323 conferencing devices."
    },
    {
     "topic": "security",
     "text": "The HIPAA-oriented Healthcare plan is North America only and turns off recording and chat.",
     "src": "https://support.goto.com/meeting/help/plan-overview-gotomeeting-for-healthcare",
     "q": "Note: GoTo Meeting for Healthcare is currently only available in North America."
    }
   ]
  },
  {
   "slug": "gusto",
   "name": "Gusto",
   "category": "Payroll & HR Software",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/gusto/#security-offline-remote",
   "trust_center": "https://trust.gusto.com/",
   "fields": {
    "soc2": {
     "v": "Report (type not stated)",
     "src": "https://gusto.com/security",
     "q": "Gusto maintains SOC 1 and SOC 2 reports which are updated annually."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "For benefits and health-insurance data",
     "src": "https://gusto.com/security",
     "q": "we maintain business associate agreements (BAAs) between employers and Gusto, along with any third parties, like insurance companies."
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": false,
     "src": "https://gusto.com/product/integrations/okta",
     "q": "The integration does not support SSO functionality. If you’re interested in SSO between OKTA and Gusto, please let us know"
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Primary admin setting; applies to admins only (plan not stated)",
     "src": "https://support.gusto.com/article/106622317100000/set-up-manage-and-troubleshoot-2-step-verification",
     "q": "If you’re a Primary admin, you can require all other admins to use 2-step verification."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://gusto.com/security",
     "q": "The principal region for running the application is AWS region US-West-2 (Oregon), with AWS region US-East-1 (Virginia)"
    },
    "encryption": {
     "v": "AES-256 at rest (AWS); TLS 1.2 in transit",
     "src": "https://gusto.com/security",
     "q": "Data is encrypted at rest in AWS using AES-256 key encryption."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.gusto.com/article/250325122224097/gusto-mobile-app-employer-experience",
     "q": "The app is available on iOS® and Android™ phones through the App Store® and Google Play® store."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "Time Kiosk turns any internet-connected tablet or computer into a shared clock-in station (Plus, Premium, or Time & Attendance Plus Simple add-on).",
     "src": "https://support.gusto.com/article/230223131618657/time-kiosk-for-time-tracking-for-admins",
     "q": "Any tablet or computer that has access to the internet is supported. The device must be online for the Time Kiosk to work."
    }
   },
   "facts": [
    {
     "topic": "offline",
     "text": "Gusto's Time Kiosk has no offline mode: the kiosk device must be online, so sites without Wi-Fi need a device with cellular data.",
     "src": "https://support.gusto.com/article/230223131618657/time-kiosk-for-time-tracking-for-admins",
     "q": "The device must be online for the Time Kiosk to work. When selecting a device, consider whether it'll have access to Wi-Fi."
    },
    {
     "topic": "office",
     "text": "Time Kiosk is limited to Plus, Premium, or Time & Attendance Plus Simple add-on customers who use Time Tracking.",
     "src": "https://support.gusto.com/article/230223131618657/time-kiosk-for-time-tracking-for-admins",
     "q": "Time Kiosk is available to customers on the Plus, Premium, or Time & Attendance Plus Simple add-on plans who use Time Tracking."
    },
    {
     "topic": "remote",
     "text": "On Plus and Premium, provisioning apps grant or remove team members' access to tools like Slack or Zoom from Gusto.",
     "src": "https://support.gusto.com/article/211123171454257/Set-up-provisioning-apps",
     "q": "Provisioning apps let you connect your team’s tools to Gusto, so you can quickly give or remove team member access to apps like Slack or Zoom from one place."
    },
    {
     "topic": "security",
     "text": "Gusto's SOC 1 and SOC 2 reports are updated annually and available through its Trust Center under NDA; the SOC 2 type is not stated on the security page.",
     "src": "https://gusto.com/security",
     "q": "Gusto maintains SOC 1 and SOC 2 reports, which are updated annually."
    }
   ]
  },
  {
   "slug": "harvest",
   "name": "Harvest",
   "category": "Time Tracking",
   "checked": "2026-09-19",
   "scope": "Harvest time tracking and invoicing; Harvest Forecast not researched.",
   "profile_url": "https://helpcompare.com/tools/harvest/#security-offline-remote",
   "trust_center": "https://support.getharvest.com/hc/en-us/articles/360048685851-Security-FAQ",
   "fields": {
    "soc2": {
     "src": "https://support.getharvest.com/hc/en-us/articles/360048685851-Security-FAQ",
     "q": "We rely on our server host’s audit, and they are SOC 2 compliant ."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "PCI DSS (merchant certificate)"
     ],
     "src": "https://support.getharvest.com/hc/en-us/articles/360048685851-Security-FAQ",
     "q": "Yes, Harvest has a PCI-DSS Merchant Certificate, although we don’t store any payment info."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://support.getharvest.com/hc/en-us/articles/360048685851-Security-FAQ",
     "q": "We offer a data processing agreement (DPA) that aims to help our customers meet their obligations under GDPR."
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.getharvest.com/hc/en-us/articles/31447072608397-Information-about-pricing-plans",
     "q": "The one exception to offering the full range of Harvest's features in trials is SAML-based SSO, which is offered only on the paid Enterprise plan."
    },
    "scim": {
     "v": false,
     "src": "https://support.getharvest.com/hc/en-us/articles/29972032988301-SAML-SSO-FAQ",
     "q": "Harvest will not be providing SCIM at this time."
    },
    "mfa": {
     "v": true,
     "enforce": "Teams",
     "src": "https://support.getharvest.com/hc/en-us/articles/360048685851-Security-FAQ",
     "q": "Two-factor authentication is available for all paid Harvest accounts."
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.getharvest.com/pricing",
     "q": "Activity log ? Audit trail of every time entry and edit."
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://support.getharvest.com/hc/en-us/articles/360048685851-Security-FAQ",
     "q": "No, all of our data is stored within the U.S."
    },
    "encryption": {
     "v": "TLS 1.2/1.3 in transit; backups AES-256 at rest; attachments encrypted at rest on Amazon S3",
     "src": "https://support.getharvest.com/hc/en-us/articles/360048685851-Security-FAQ",
     "q": "All data is encrypted in transit, and all connections use TLS 1.2/1.3."
    },
    "self_host": {
     "v": false,
     "src": "https://support.getharvest.com/hc/en-us/articles/360048181352-Can-I-host-Harvest-on-my-own-server",
     "q": "No, it's not possible to host Harvest on your own server."
    },
    "mode": {
     "v": "full",
     "summary": "The iPhone and Android apps track time and log expenses offline and sync when reconnected; the browser and desktop apps need an internet connection, though a running timer keeps running.",
     "src": "https://support.getharvest.com/hc/en-us/articles/360052219232-Can-I-use-Harvest-offline",
     "q": "However, you can track time and log expenses in our iPhone and Android apps while your phone is offline"
    },
    "desktop": {
     "v": [
      "macOS",
      "Windows"
     ],
     "src": "https://support.getharvest.com/hc/en-us/articles/360048181532-Members-Apps-and-browser-extensions",
     "q": "you can track time right from your desktop with our Harvest for Mac and Harvest for Windows desktop apps."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.getharvest.com/hc/en-us/articles/360048181532-Members-Apps-and-browser-extensions",
     "q": "You can also track time and expenses on the go with our mobile app for iPhone and Android ."
    },
    "limits": {
     "v": "Offline works only in the mobile apps; browser and desktop apps require a strong internet connection.",
     "src": "https://support.getharvest.com/hc/en-us/articles/360052219232-Can-I-use-Harvest-offline",
     "q": "To use Harvest in your browser or in one of our desktop apps, you’ll need to have a strong internet connection."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "When enabled, two-factor authentication is an account-wide sign-in requirement for everyone, and it is mandatory for accounts connected to Xero.",
     "src": "https://support.getharvest.com/hc/en-us/articles/10108571515917-Two-factor-authentication-2FA-FAQ",
     "q": "No. 2FA will need to be enabled account-wide as a sign-in requirement ."
    },
    {
     "topic": "remote",
     "text": "All Harvest data is stored in the U.S. (Google Cloud, with AWS backups), with no customer-selectable region.",
     "src": "https://support.getharvest.com/hc/en-us/articles/360048685851-Security-FAQ",
     "q": "All our infrastructure is hosted by Google Cloud and all data is located in the U.S. We also back up data with Amazon Web Services, also located in the U.S."
    },
    {
     "topic": "office",
     "text": "Harvest's Gusto payroll sync is only for US-based Gusto customers and must be run by an Administrator.",
     "src": "https://support.getharvest.com/hc/en-us/articles/47877340686477-Gusto",
     "q": "The Gusto integration is available for US-based Gusto customers."
    }
   ]
  },
  {
   "slug": "hootsuite",
   "name": "Hootsuite",
   "category": "Social Media Management",
   "checked": "2026-09-19",
   "scope": "Hootsuite Social OS (web + mobile). Lumen by Talkwalker listening has its own hosting.",
   "profile_url": "https://helpcompare.com/tools/hootsuite/#security-offline-remote",
   "trust_center": "https://trustcenter.hootsuite.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://trustcenter.hootsuite.com/",
     "q": "including SOC 2 Type II audits, ISO certifications (27001, 27017, 27018, and 27701), FedRAMP Authorization, and UK Cyber Essentials."
    },
    "iso27001": {
     "v": true,
     "src": "https://trustcenter.hootsuite.com/",
     "q": "ISO 27001:2022"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "FedRAMP Li-SaaS",
      "CSA STAR Level 1",
      "UK Cyber Essentials",
      "TX-RAMP",
      "SOC 3"
     ],
     "src": "https://trustcenter.hootsuite.com/",
     "q": "CCPA CSA STAR 1 Cyber Essentials FedRAMP Li-SaaS GDPR ISO 27001:2022 ISO 27017 ISO 27018 ISO 27701 PCI SOC 2 Type II SOC 3 TX-RAMP VPAT"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://trustcenter.hootsuite.com/",
     "q": "Will enter into a DPA"
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.hootsuite.com/legal/security-practices",
     "q": "Hootsuite also supports SSO capability for Enterprise customers that wish to ensure greater and more centralized access control to their accounts."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://www.hootsuite.com/legal/security-practices",
     "q": "Hootsuite also supports multi-factor authentication capability for its Customers and their Authorized Users in respect of their use of the Services"
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "Customer information encrypted at rest and in transit; TLS 1.2 or above",
     "src": "https://www.hootsuite.com/legal/security-practices",
     "q": "All Customer Information is encrypted at rest and in transit."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.hootsuite.com/hootsuite-mobile-app",
     "q": "Download Hootsuite’s iPhone or Android app to manage social media from anywhere."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Standard, Professional and Advanced customers get support via help center tickets and X/Facebook, Monday to Friday business hours in several regional time zones; languages are English, Spanish and French.",
     "src": "https://help.hootsuite.com/s/article/need-help?language=en_US",
     "q": "Monday to Friday 9:00 am - 5:00 pm (PST GMT-8, CST GMT-6, EST GMT-5, EET GMT+2, CET GMT+1, NZDT GMT+13)"
    }
   ]
  },
  {
   "slug": "hubspot",
   "name": "HubSpot",
   "category": "CRM Platforms",
   "checked": "2026-09-19",
   "scope": "HubSpot Customer Platform (Smart CRM, Sales/Marketing/Service Hubs); plan names are per-Hub tiers (Free, Starter, Professional, Enterprise)",
   "profile_url": "https://helpcompare.com/tools/hubspot/#security-offline-remote",
   "trust_center": "https://trust.hubspot.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://trust.hubspot.com/",
     "q": "Our SOC 2 Type II report continues to provide a detailed evaluation of controls related to security, availability, and confidentiality"
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "SOC 1 Type II",
      "SOC 3",
      "HIPAA attestation",
      "EU Cloud Code of Conduct",
      "TRUSTe Certified Privacy"
     ],
     "src": "https://trust.hubspot.com/",
     "q": "including our first SOC 1 report, updated SOC 2 Type II and SOC 3 reports, a refreshed HIPAA attestation, and updated Compliance FAQs."
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise",
     "src": "https://knowledge.hubspot.com/properties/store-sensitive-data",
     "q": "By identifying as a HIPAA Covered Entity or Business Associate, HubSpot can track the application of the Business Associate Agreement (BAA) and fulfill regulatory obligations."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://legal.hubspot.com/dpa",
     "q": "This HubSpot Data Processing Agreement and its Annexes (“DPA”) is incorporated into and forms part of the HubSpot Customer Terms of Service"
    },
    "sso_saml": {
     "v": true,
     "plan": "Professional",
     "src": "https://knowledge.hubspot.com/account-security/restrict-which-login-methods-users-can-use-to-access-your-account",
     "q": "Single sign-on ( Professional and Enterprise accounts only)."
    },
    "scim": {
     "v": true,
     "plan": "Professional",
     "src": "https://knowledge.hubspot.com/user-management/provision-hubspot-users-with-scim-through-okta",
     "q": "This allows you to set up SCIM to provision users from providers like Microsoft Entra ID, PingFederate, OneLogin, and JumpCloud."
    },
    "mfa": {
     "v": true,
     "enforce": "Free (optional to require); mandatory on Starter, Professional, Enterprise",
     "src": "https://knowledge.hubspot.com/account-security/set-up-two-factor-authentication-for-your-hubspot-login",
     "q": "2FA is required for all HubSpot Starter , Professional , and Enterprise accounts and can't be turned off. Accounts using HubSpot’s free tools can choose whether to require 2FA."
    },
    "audit_log": {
     "v": true,
     "plan": "Starter",
     "src": "https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history",
     "q": "Super Admins can use audit logs to review, filter, and export a record of user actions in a HubSpot account."
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "CA",
      "AU"
     ],
     "plan": "Starter",
     "src": "https://knowledge.hubspot.com/account-security/hubspot-cloud-infrastructure-and-data-hosting-frequently-asked-questions",
     "q": "hosted on Amazon Web Services (AWS) in the United States (East and West regions), Canada, Australia, and European Union (Germany)."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2 or 1.3 in transit",
     "src": "https://legal.hubspot.com/security",
     "q": "encrypted in-transit with TLS 1.2, or 1.3 and 2,048 bit keys or better."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "CRM records cannot be created, edited, or viewed in the mobile app without a connection; only Mobile Notetaker can record meetings offline and link them to CRM records once back online.",
     "src": "https://knowledge.hubspot.com/records/work-with-records-in-the-hubspot-mobile-app",
     "q": "Records cannot be created, edited, or viewed in the mobile app without internet or data connection."
    },
    "desktop": {
     "v": [],
     "src": "https://www.hubspot.com/products/crm/mac-windows",
     "q": "works seamlessly across both operating systems through web browsers, eliminating the need for platform-specific applications"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.hubspot.com/products/crm/mac-windows",
     "q": "HubSpot mobile apps for iOS and Android devices"
    },
    "limits": {
     "v": "Offline meeting recording (Mobile Notetaker) is available on Sales Hub or Service Hub Professional and Enterprise",
     "plan": "Sales Hub / Service Hub Professional",
     "src": "https://knowledge.hubspot.com/meetings-tool/use-mobile-notetaker-in-the-hubspot-mobile-app",
     "q": "Users can record when they're offline and associate the recording with the corresponding meeting and CRM record when they're back online."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Starter",
     "src": "https://knowledge.hubspot.com/account-security/limit-logins-to-trusted-ip-addresses",
     "q": "A Starter, Professional, or Enterprise subscription is required to limit logins to trusted IP addresses."
    },
    "device_controls": {
     "v": true,
     "plan": "All plans",
     "summary": "Admin-set inactive session timeout (15 minutes to 3 days); users can review and remotely log out their own sessions on other devices.",
     "src": "https://knowledge.hubspot.com/account-security/restrict-which-login-methods-users-can-use-to-access-your-account",
     "q": "If a user is inactive for the selected amount of time, they will be prompted to log in again when they next try to access their account."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "HubSpot's trusted-IP login restriction also applies to the mobile app, so reps logging in from outside the allowed range on a phone are blocked.",
     "src": "https://knowledge.hubspot.com/account-security/limit-logins-to-trusted-ip-addresses",
     "q": "limiting logins to trusted IP addresses applies to logins on both computers and mobile devices."
    },
    {
     "topic": "security",
     "text": "Each HubSpot account is hosted in one data center (US, EU, Canada or Australia); paid accounts can migrate to another region.",
     "src": "https://knowledge.hubspot.com/account-security/hubspot-cloud-infrastructure-and-data-hosting-frequently-asked-questions",
     "q": "You can change your data center if your account has a paid subscription."
    },
    {
     "topic": "remote",
     "text": "Users can see every device, browser and app where they are signed in and log out of lost devices remotely.",
     "src": "https://knowledge.hubspot.com/account-security/manage-user-login-sessions",
     "q": "Use session management to track where your user account is active and log out of devices remotely to protect your account security."
    }
   ]
  },
  {
   "slug": "idrive",
   "name": "IDrive",
   "category": "Business Backup",
   "checked": "2026-09-19",
   "scope": "IDrive cloud backup, Team and Business plans; IDrive 360, e2 and Enterprise not researched.",
   "profile_url": "https://helpcompare.com/tools/idrive/#security-offline-remote",
   "trust_center": "https://www.idrive.com/online-backup-compliance",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.idrive.com/compliance-statement",
     "q": "IDrive ® has proudly achieved SOC 2 Type 2 certification through a rigorous evaluation conducted by an independent third-party auditing firm."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.idrive.com/online-backup-compliance",
     "q": "IDrive is now ISO/IEC 27001:2022 certified — the global standard for Information Security Management Systems (ISMS)."
    },
    "other_certs": {
     "v": [
      "EU-U.S. Data Privacy Framework (incl. UK Extension, Swiss-U.S. DPF)"
     ],
     "src": "https://www.idrive.com/online-backup-compliance",
     "q": "IDrive is certified under the EU–U.S. Data Privacy Framework, the UK Extension to the EU–U.S. DPF, and the Swiss–U.S. Data Privacy Framework"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Team (with private key encryption; another paragraph says Business and Enterprise only)",
     "src": "https://www.idrive.com/online-backup-compliance",
     "q": "This agreement is available on request to IDrive Business, Team, and Enterprise users who opt for Private key encryption."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.idrive.com/dpa",
     "q": "This Data Processing Addendum (\"DPA\") forms part of IDrive Inc.’s Terms of Service Agreement"
    },
    "sso_saml": {
     "v": true,
     "plan": "Team (pricing table; SSO page says Enterprise)",
     "src": "https://www.idrive.com/single-sign-on",
     "q": "admin of an Enterprise account needs to register the IDrive application with an IdP and get the single sign-on URL, issuer URL and X.509 certificate (Base64)."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://www.idrive.com/new-design/online-backup-security",
     "q": "IDrive uses two-factor authentication (2FA) to protect your account."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://www.idrive.com/online-backup-security",
     "q": "The IDrive application is hosted at our data centers in the United States."
    },
    "encryption": {
     "v": "AES 256-bit in transfer and at rest; optional private key (not stored by IDrive)",
     "src": "https://www.idrive.com/online-backup-security",
     "q": "Your data is encrypted with 256-bit AES encryption on transfer and storage."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://www.idrive.com/pricing",
     "q": "Access files backed up from PCs, Macs, and Linux computers or synced from connected devices via web, iOS and Android devices"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.idrive.com/mobile-backup",
     "q": "IDrive® mobile backup for iphone, ipad and Android devices"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "plan": "Business",
     "summary": "Central dashboard: push and lock backup settings/policies per group, remotely change backup sets and schedules, remote client upgrades, block or delete users, legal hold on a user account.",
     "src": "https://www.idrive.com/dashboard",
     "q": "Admin can lock the particular settings for groups or users. The users or groups cannot modify those settings, till the Admin unlocks it."
    },
    "office_hardware": {
     "v": "Backs up NAS devices (Synology, Netgear, Asustor, QNAP), external/mapped drives and Windows servers; IDrive Express ships a temporary storage device for bulk backup or restore.",
     "src": "https://www.idrive.com/pricing",
     "q": "Backup NAS devices like Synology, Netgear, Asustor, QNAP with dedicated applications"
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Admins can manage backups on remote employees' computers from the web dashboard, including backup sets, schedules and client upgrades.",
     "src": "https://www.idrive.com/dashboard",
     "q": "Remotely manage your PCs, Mac, and Linux with robust reporting tools in near real-time response."
    },
    {
     "topic": "office",
     "text": "IDrive Express ships a temporary drive to seed or retrieve bulk data without using office bandwidth; free up to three times a year on Team and Business.",
     "src": "https://www.idrive.com/idrive-express",
     "q": "This service is provided FREE with Express Backup — once per year for Personal users, and up to three times per year for Team and Business users."
    },
    {
     "topic": "security",
     "text": "Admins can put a legal hold on a departing user's account: the user is blocked while the admin can still access and download the data.",
     "src": "https://www.idrive.com/dashboard-faq",
     "q": "Legal hold is a process which allows the admin to block a user account."
    },
    {
     "topic": "remote",
     "text": "Support is available around the clock by live chat, email and phone.",
     "src": "https://www.idrive.com/support",
     "q": "IDrive® support is available 24/7 via live chat, email and phone"
    }
   ]
  },
  {
   "slug": "inflow-inventory",
   "name": "inFlow Inventory",
   "category": "Inventory Management",
   "checked": "2026-09-19",
   "scope": "inFlow Inventory cloud (web, Windows, iOS, Android). inFlow On-Premise was sunset in 2024.",
   "profile_url": "https://helpcompare.com/tools/inflow-inventory/#security-offline-remote",
   "trust_center": "https://trust.archonsystems.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.inflowinventory.com/support/cloud/inflow-cloud-secure/",
     "q": "inFlow undergoes an independent SOC 2 Type II audit every year."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": false,
     "src": "https://www.inflowinventory.com/support/cloud/single-sign-on",
     "q": "Which protocols are supported? OIDC protocol. SAML is not available at this time."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "All plans (mandatory)",
     "src": "https://www.inflowinventory.com/support/cloud/2fa",
     "q": "2FA is mandatory for all inFlow accounts. 2FA will be automatically enabled once you switch from the sample data."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "256-bit SSL encryption; hosted on Microsoft Azure",
     "src": "https://www.inflowinventory.com/software-pricing-inflow",
     "q": "Your data is safely stored using 256-bit SSL encryption backed by Microsoft Azure."
    },
    "self_host": {
     "v": false,
     "src": "https://onpremise.inflowinventory.com/",
     "q": "The locally-installed version of inFlow is no longer available for sale."
    },
    "mode": {
     "v": "none",
     "summary": "inFlow Inventory's web, Windows and mobile apps all need a working internet connection; the offline-capable On-Premise edition was discontinued.",
     "src": "https://www.inflowinventory.com/support/cloud/can-view-data-inflow-cloud",
     "q": "you can access your data in three ways, as long as you have a working internet connection: the web app, the Windows app, or the mobile app."
    },
    "desktop": {
     "v": [
      "Windows"
     ],
     "src": "https://www.inflowinventory.com/download",
     "q": "Use inFlow on web, iOS, Android, and Windows"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.inflowinventory.com/download",
     "q": "Use inFlow on web, iOS, Android, and Windows"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "plan": "Mid-Size",
     "summary": "With SSO (Mid-Size+), admins can require SSO for all team members and sessions end when the browser or Windows app closes; 2FA credentials are remembered for 30 days.",
     "src": "https://www.inflowinventory.com/support/cloud/single-sign-on",
     "q": "With SSO enabled, the logout behavior will change to enhance security. You will be logged out of inFlow when you close your browser or close inFlow for Windows."
    },
    "office_hardware": {
     "v": "inFlow sells a Smartphone Scanner (Android phone with built-in laser scanner) and a Portable thermal label Printer; new customers get a one-time hardware credit.",
     "src": "https://www.inflowinventory.com/software-pricing-inflow",
     "q": "A five-foot-drop-tested Android phone with a built-in laser scanner. Great for picking and receiving in the warehouse."
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "When an admin bypasses SSO with a password, all inFlow admins get an email with the user's name, IP address and geolocation.",
     "src": "https://www.inflowinventory.com/support/cloud/single-sign-on",
     "q": "When an inFlow administrator logs in using their password instead of SSO, an email notification containing the user’s name, IP address, and geolocation is sent to all inFlow admins ."
    },
    {
     "topic": "office",
     "text": "Advanced access rights restrict team members by location and sales rep, useful for multi-warehouse teams (Mid-Size+, or $69/mo add-on on Small Business).",
     "src": "https://www.inflowinventory.com/software-pricing-inflow",
     "q": "Restrict access based on location and by sales rep. Also adds approvals for POs and the ability to lock further edits on fulfilled transactions"
    },
    {
     "topic": "remote",
     "text": "Support is in-house from Toronto and Lisbon by email and live chat during business hours; Mid-Size and Enterprise can book Zoom troubleshooting calls.",
     "src": "https://www.inflowinventory.com/software-pricing-inflow",
     "q": "All plans include in-house support (from Toronto and Lisbon) by email and live chat during business hours."
    },
    {
     "topic": "offline",
     "text": "inFlow's offline-capable On-Premise edition lost support on July 31, 2024; current apps require internet.",
     "src": "https://onpremise.inflowinventory.com/",
     "q": "We discontinued support for inFlow On-Premise (i.e. inFlow v3) on July 31, 2024."
    }
   ]
  },
  {
   "slug": "instantly",
   "name": "Instantly",
   "category": "Cold Email & Sales Engagement",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/instantly/#security-offline-remote",
   "trust_center": null,
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": "Not supported",
     "src": "https://instantly.ai/dpa",
     "q": "Subscriber acknowledges that Service Provider is not a business associate (as that term is defined under HIPAA) or a payment card processor."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://instantly.ai/dpa",
     "q": "THIS DATA PROCESSING ADDENDUM (“DPA”) to the Agreement (as defined below) is entered into as of the Addendum Effective Date"
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Not plan-gated in vendor docs (workspace owner setting)",
     "src": "https://help.instantly.ai/en/articles/10248784-two-factor-authentication",
     "q": "You can also require all team members to enable two-step authentication to access the workspace."
    },
    "audit_log": {
     "v": true,
     "src": "https://help.instantly.ai/en/articles/11867152-account-settings-overview",
     "q": "Audit Logs Workspace owners and admins can track key actions across campaigns, lists, and accounts for better security, compliance, and visibility."
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "Commercially reasonable encryption for subscriber personal data (algorithms not published)",
     "src": "https://instantly.ai/dpa",
     "q": "utilization of commercially reasonable encryption technologies for Subscriber Personal Data."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://help.instantly.ai/en/articles/8930619-unibox-app",
     "q": "Unibox app for iOS and Android"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "summary": "Owner-set re-authentication interval; sign out all sessions or force-log-out every workspace user.",
     "src": "https://help.instantly.ai/en/articles/10248784-two-factor-authentication",
     "q": "The workspace owner can set a maximum duration after which team members are required to re-authenticate to access the workspace."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Workspace owners can force every user in the workspace to log out of all devices, e.g. after a security incident.",
     "src": "https://help.instantly.ai/en/articles/10248784-two-factor-authentication",
     "q": "Log out all users from all devices of organization : Forces every user in the workspace to be logged out, useful in security-related scenarios or workspace resets."
    },
    {
     "topic": "security",
     "text": "Instantly's DPA states the service is not designed for HIPAA or PCI DSS data, so health or card data should not be put into it.",
     "src": "https://instantly.ai/dpa",
     "q": "Subscriber acknowledges that the Services are not designed to be HIPAA or PCI DSS compliant."
    },
    {
     "topic": "remote",
     "text": "The Unibox mobile app lets team members answer interested leads from their phones.",
     "src": "https://help.instantly.ai/en/articles/8930619-unibox-app",
     "q": "All your leads are accessible in your pocket, allowing you to respond from anywhere."
    }
   ]
  },
  {
   "slug": "intercom",
   "name": "Intercom",
   "category": "Customer Support",
   "checked": "2026-09-19",
   "scope": "Intercom Helpdesk and Fin AI Agent (Essential, Advanced, Expert plans)",
   "profile_url": "https://helpcompare.com/tools/intercom/#security-offline-remote",
   "trust_center": "https://trust.intercom.com",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.intercom.com/security",
     "q": "SOC 2 Type II compliant and ISO 27001 certified."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.intercom.com/security",
     "q": "SOC 2 Type II compliant and ISO 27001 certified."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "ISO/IEC 42001",
      "HIPAA"
     ],
     "src": "https://www.intercom.com/security",
     "q": "Intercom and Fin hold SOC 2 Type II and HIPAA compliance along with ISO 27001, ISO 27018, ISO 27701, and ISO 42001 certification"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Expert",
     "src": "https://www.intercom.com/help/en/articles/8827723-contacts-faqs",
     "q": "This requires subscribing to Intercom's Expert plan, as HIPAA compliance features, including the BAA, are only available at this level."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.intercom.com/help/en/articles/1385437-how-we-comply-with-gdpr",
     "q": "Our data processing agreement shares our privacy commitments and sets out the terms for Fin and our customers to meet GDPR requirements."
    },
    "sso_saml": {
     "v": true,
     "plan": "Expert",
     "src": "https://www.intercom.com/help/en/articles/3974587-integrate-with-an-identity-provider-and-log-in-with-saml-sso",
     "q": "SAML SSO is only available on Expert Intercom plan."
    },
    "scim": {
     "v": true,
     "src": "https://www.intercom.com/help/en/articles/5798401-system-for-cross-domain-identity-management-scim-provisioning",
     "q": "SCIM Provisioning is only available with certain Intercom plans."
    },
    "mfa": {
     "v": true,
     "enforce": "All plans",
     "src": "https://www.intercom.com/help/en/articles/181-protect-your-account-with-2fa-google-sign-on-or-saml-sso",
     "q": "Available on all plans Can be enforced workspace-wide"
    },
    "audit_log": {
     "v": true,
     "plan": "All plans",
     "src": "https://www.intercom.com/changes/en/4952-protect-your-workspace-with-2fa-google-sign-on-and-teammate-activity-logs",
     "q": "We’ve updated our plans to allow you to enforce strong authentication controls and have visibility into teammate activity on your workspace. All plans now include:"
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "AU"
     ],
     "src": "https://www.intercom.com/help/en/articles/6124430-regional-data-hosting",
     "q": "offering the choice to have data processed in one of the Designated Regions: the United States (US), European Union (EU), or Australia (AUS)."
    },
    "encryption": {
     "v": "TLS/SSL-only endpoints in transit; data encrypted at rest",
     "src": "https://www.intercom.com/help/en/articles/264-security-at-fin",
     "q": "Our API and application endpoints are TLS/SSL only and score an \"A+\" rating on SSL Labs' tests"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.intercom.com/help/en/articles/447-respond-to-users-and-visitors-on-the-go-with-the-intercom-conversations-app",
     "q": "Quickly reply to customer conversations on the move with the Intercom for iOS and Android mobile apps."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "src": "https://www.intercom.com/help/en/articles/8931206-restricting-access-to-your-intercom-workspace-using-ip-restrictions",
     "q": "IP Allowlisting enables you to control who can access your workspace by specifying allowed IP addresses or ranges."
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "The IP allowlist covers the web app and the mobile conversations app, but not REST API endpoints.",
     "src": "https://www.intercom.com/help/en/articles/8931206-restricting-access-to-your-intercom-workspace-using-ip-restrictions",
     "q": "This restriction currently applies only to web app and mobile conversations app access. REST API endpoints are exempt from these access restrictions."
    },
    {
     "topic": "remote",
     "text": "Regional Data Hosting (US, EU or Australia) is offered to new customers on a contract account, and existing workspace data can't be migrated directly to another region.",
     "src": "https://www.intercom.com/help/en/articles/6124430-regional-data-hosting",
     "q": "When switching to regional data hosting, please note that direct migration of your existing workspace data from one region to another is not possible."
    },
    {
     "topic": "security",
     "text": "On top of TLS/SSL-only endpoints, Intercom says it encrypts data at rest.",
     "src": "https://www.intercom.com/help/en/articles/264-security-at-fin",
     "q": "We also encrypt data at rest."
    },
    {
     "topic": "remote",
     "text": "Teammates can reply to customer conversations from the Intercom Conversations apps for iOS and Android.",
     "src": "https://www.intercom.com/help/en/articles/447-respond-to-users-and-visitors-on-the-go-with-the-intercom-conversations-app",
     "q": "The Intercom Conversations for iOS and Intercom Conversations for Android mobile apps allow you to quickly reply to conversations on the move."
    }
   ]
  },
  {
   "slug": "jira",
   "name": "Jira",
   "category": "Project Management",
   "checked": "2026-09-19",
   "scope": "Jira Cloud; self-managed Jira Data Center not researched. SSO/SCIM come from Atlassian Guard (formerly Atlassian Access)",
   "profile_url": "https://helpcompare.com/tools/jira/#security-offline-remote",
   "trust_center": "https://www.atlassian.com/trust/compliance/resources",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://wac-cdn.atlassian.com/misc-assets/pdfs/FY25_Mega_Audit_Atlassian_SOC_2_Bridge_Letter.pdf",
     "q": "Coalfire Controls, LLC prepared the latest SOC 2 Type II report relevant to the following Atlassian Cloud products"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.atlassian.com/trust/compliance/resources/iso27001",
     "q": "ISO/IEC 27001:2022 is a security management standard that specifies security management best practices and comprehensive security controls following the ISO/IEC 27002 best practice guidance."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27018",
      "FedRAMP Moderate",
      "CSA STAR",
      "TISAX",
      "C5",
      "IRAP"
     ],
     "src": "https://www.atlassian.com/trust/compliance/resources/fedramp",
     "q": "Jira, Confluence, & Jira Service Management FedRAMP Moderate Marketplace Listing"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Standard",
     "src": "https://www.atlassian.com/trust/compliance/resources/hipaa",
     "q": "Customers who are subject to HIPAA compliance and want to partner with Atlassian purchase a Standard, Premium, or Enterprise Plan and enter into a Business Associate Agreement (BAA)"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.atlassian.com/legal/data-processing-addendum",
     "q": "Atlassian Data Processing Addendum"
    },
    "sso_saml": {
     "v": true,
     "plan": "Any plan with Atlassian Guard Standard (add-on); included in Enterprise",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/atlassian-guard-product-and-plan-availability/",
     "q": "SAML single sign-on Atlassian Cloud: Atlassian Guard Standard Apps: Jira, Jira Service Management, Jira Product Discovery, Jira Align, Confluence, Bitbucket, Trello, Statuspage"
    },
    "scim": {
     "v": true,
     "plan": "Any plan with Atlassian Guard Standard (add-on); included in Enterprise",
     "src": "https://www.atlassian.com/software/jira/pricing",
     "q": "Atlassian Guard Standard (SSO, SCIM, Active Directory Sync)"
    },
    "mfa": {
     "v": true,
     "enforce": "All plans (managed accounts)",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/enforce-two-step-verification/",
     "q": "Atlassian Cloud: All plans Atlassian Government Cloud: Not available Enforce two-step verification for managed accounts"
    },
    "audit_log": {
     "v": true,
     "plan": "Any plan with Atlassian Guard Standard (add-on); included in Enterprise",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/atlassian-guard-product-and-plan-availability/",
     "q": "Audit logs for organization administration activities Atlassian Cloud: Atlassian Guard Standard"
    },
    "data_residency": {
     "v": [
      "AU",
      "CA",
      "EU",
      "DE",
      "IN",
      "JP",
      "SG",
      "KR",
      "CH",
      "UK",
      "US"
     ],
     "plan": "Standard",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/understand-data-residency/",
     "q": "Atlassian Cloud: Jira, Jira Service Management, Jira Product Discovery, Loom, and Confluence with Enterprise, Premium, and Standard plans."
    },
    "encryption": {
     "v": "AES-256 full-disk encryption at rest; TLS 1.2+ in transit",
     "src": "https://www.atlassian.com/trust/security/security-practices",
     "q": "Jira, Bitbucket Cloud, Confluence Cloud, Statuspage, Opsgenie, Trello, Loom, Compass and Rovo use full disk, industry-standard AES-256 encryption at rest."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "summary": "Atlassian's documentation does not describe an offline mode for Jira Cloud; an offline mode for the mobile apps is an open, unresolved suggestion on Atlassian's public tracker.",
     "src": "https://jira.atlassian.com/browse/JRACLOUD-78201",
     "q": "Provide an offline mode for Jira Cloud apps (Android and iOS)."
    },
    "desktop": {
     "v": [],
     "src": "https://support.atlassian.com/jira-cloud-macos/docs/use-jira-cloud-for-mac/",
     "q": "Support has ended for the Jira Cloud for Mac app Continue moving your work forward with Jira via your web browser."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.atlassian.com/security-and-access-policies/docs/atlassian-guard-product-and-plan-availability/",
     "q": "Mobile apps: Jira Cloud, Confluence Cloud, and Opsgenie, and Rovo apps for iOS and Android"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Premium",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/specify-ip-addresses-for-product-access/",
     "q": "Plan: Premium plan for Jira, Jira Service Management, Confluence, and Compass."
    },
    "device_controls": {
     "v": true,
     "plan": "Any plan with Atlassian Guard Standard (add-on); included in Enterprise",
     "summary": "Mobile app management policies for the Jira Cloud iOS and Android apps via Atlassian Guard Standard.",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/atlassian-guard-product-and-plan-availability/",
     "q": "Mobile app management Atlassian Cloud: Atlassian Guard Standard Mobile apps: Jira Cloud, Confluence Cloud, and Opsgenie, and Rovo apps for iOS and Android"
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Even with an IP allowlist, some Jira/Confluence information (such as notification details and Smart Links) stays visible to users outside the allowed ranges.",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/specify-ip-addresses-for-product-access/",
     "q": "Regardless of your IP allowlists, users can always see the following information types:"
    },
    {
     "topic": "security",
     "text": "On the Jira pricing page, Guard Standard (SSO, SCIM, AD sync) is marked 'Requires Atlassian Guard Standard subscription' on Free, Standard and Premium and 'Included' on Enterprise.",
     "src": "https://www.atlassian.com/software/jira/pricing",
     "q": "Requires Atlassian Guard Standard subscription"
    },
    {
     "topic": "offline",
     "text": "Atlassian's public tracker lists an offline mode for the Jira Cloud Android and iOS apps as an unresolved suggestion.",
     "src": "https://jira.atlassian.com/browse/JRACLOUD-78201",
     "q": "Provide an offline mode for Jira Cloud apps (Android and iOS)."
    }
   ]
  },
  {
   "slug": "kartra",
   "name": "Kartra",
   "category": "Funnel Building & Course Platforms",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/kartra/#security-offline-remote",
   "trust_center": null,
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "PCI DSS"
     ],
     "src": "https://kartra.com/gdpr/",
     "q": "Kartra adheres to, and is audited annually for compliance with, the Payment Card Industry Data Security Standard"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://kartra.com/dpa/",
     "q": "This data processing addendum (“DPA”) supplements and modifies the End-User Licensing Agreement (“EULA”) governing the use of KARTRA Software."
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "All plans (at least one MFA method must stay active)",
     "src": "https://support.kartra.com/support/solutions/articles/153000178457-multi-factor-authentication-mfa-setup-guide",
     "q": "Email MFA is turned on by default for your account."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "SSL/TLS on pages that transmit personal information; at-rest encryption not stated",
     "src": "https://kartra.com/privacy-policy/",
     "q": "Kartra and its third party providers use Secure Sockets Layer (SSL) encryption on all web pages where personal information, including financial information is transmitted."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": null
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Every Kartra login needs a one-time passcode (email or authenticator app); at least one method must remain active.",
     "src": "https://support.kartra.com/support/solutions/articles/153000178457-multi-factor-authentication-mfa-setup-guide",
     "q": "Choose either method, but you must have at least one active ."
    },
    {
     "topic": "security",
     "text": "Kartra runs on third-party cloud infrastructure such as AWS and Rackspace.",
     "src": "https://kartra.com/gdpr/",
     "q": "Kartra leverages cloud infrastructure providers like Amazon Web Services, Rackspace, as well as other services like SendGrid."
    }
   ]
  },
  {
   "slug": "keap",
   "name": "Keap",
   "category": "CRM & Sales Automation",
   "checked": "2026-09-19",
   "scope": "Keap (a Thryv brand); help docs now hosted on learn.thryv.com",
   "profile_url": "https://helpcompare.com/tools/keap/#security-offline-remote",
   "trust_center": "https://keap.com/legal/data-protection-faq",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "PCI DSS"
     ],
     "src": "https://keap.com/legal/data-protection-faq",
     "q": "We adhere to, and are audited annually for compliance with, the Payment Card Industry Data Security Standard"
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://learn.thryv.com/hc/en-us/articles/37506928781325-HIPAA-Security-Controls-for-Keap",
     "q": "Keap offers customers the opportunity to execute our standard Business Associate Agreement Addendum (or “BAA”) that satisfies the applicable subcontracting requirements under HIPAA and the HITECH Act"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://keap.com/legal/data-protection-faq",
     "q": "We offer customers a new Data Processing Addendum (DPA) in conjunction with our Terms of Service ."
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "All plans (2FA mandatory for every user)",
     "src": "https://learn.thryv.com/hc/en-us/articles/36637607815181-Two-factor-Authentication-for-Keap",
     "q": "As of August 7, 2025, two-factor authentication (2FA) is required for all Keap users, including partners who manage client accounts"
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://learn.thryv.com/hc/en-us/articles/36798275416589-Use-Keap-on-Mobile-App-and-Web-Browser-Access",
     "q": "through the Keap™ mobile app, available for both Android and iOS,"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "After a successful 2FA challenge, a recognized device is not challenged again for 90 days unless a new device signs in.",
     "src": "https://learn.thryv.com/hc/en-us/articles/36637607815181-Two-factor-Authentication-for-Keap",
     "q": "After passing a 2FA challenge on a recognized device, you will not be re-challenged for 90 days — unless a new or unrecognized device attempts to access your account"
    },
    {
     "topic": "security",
     "text": "HIPAA protections must be switched on in-app (HIPAA Security Controls) before signing Keap's BAA.",
     "src": "https://learn.thryv.com/hc/en-us/articles/37506928781325-HIPAA-Security-Controls-for-Keap",
     "q": "Once the HIPAA Security Control is enabled, review the BAA below, complete all the required fields, and sign the BAA in accordance with the instructions"
    },
    {
     "topic": "remote",
     "text": "Keap can be used from a phone through the native app or the mobile browser.",
     "src": "https://learn.thryv.com/hc/en-us/articles/36798275416589-Use-Keap-on-Mobile-App-and-Web-Browser-Access",
     "q": "or through the web version of your Keap™ account by signing in through your mobile browser as you normally would on a desktop"
    }
   ]
  },
  {
   "slug": "klaviyo",
   "name": "Klaviyo",
   "category": "Email Marketing",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/klaviyo/#security-offline-remote",
   "trust_center": "https://trust.klaviyo.com",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://trust.klaviyo.com",
     "q": "Badges | SOC 2 Type II | ISO 27001 | ISO 27017 | PCI:DSS | GDPR | CCPA"
    },
    "iso27001": {
     "v": true,
     "src": "https://trust.klaviyo.com",
     "q": "Badges | SOC 2 Type II | ISO 27001 | ISO 27017 | PCI:DSS | GDPR | CCPA"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "PCI DSS"
     ],
     "src": "https://trust.klaviyo.com",
     "q": "Badges | SOC 2 Type II | ISO 27001 | ISO 27017 | PCI:DSS | GDPR | CCPA"
    },
    "hipaa": {
     "v": "Not supported",
     "src": "https://www.klaviyo.com/legal/acceptable-use-policy",
     "q": "You may not solicit, store, process, send, or transmit any of the following types of data ... (b) medical records or health information, including Protected Health Information"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://trust.klaviyo.com",
     "q": "Will enter into a DPA"
    },
    "sso_saml": {
     "v": true,
     "plan": "Paid plans",
     "src": "https://help.klaviyo.com/hc/en-us/articles/9353860331035",
     "q": "You must have a paid plan to use SSO."
    },
    "scim": {
     "v": true,
     "plan": "Paid plans",
     "src": "https://help.klaviyo.com/hc/en-us/articles/10952782535579",
     "q": "You must have a paid plan and be an Admin or Owner to set up this feature."
    },
    "mfa": {
     "v": true,
     "enforce": "Mandatory on all paid plans; Owner can require it on free accounts",
     "src": "https://help.klaviyo.com/hc/en-us/articles/360026617692",
     "q": "All users on paid accounts must set up MFA, or have another security measure, such as SSO. For a free account, an Owner can also require MFA for all users."
    },
    "audit_log": {
     "v": true,
     "src": "https://help.klaviyo.com/hc/en-us/articles/44579125790747",
     "q": "The activity log is a self-service audit trail that provides visibility into all actions performed within your Klaviyo account."
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://www.klaviyo.com/legal/privacy-faqs",
     "q": "At this time, Klaviyo does not offer any data storage in jurisdictions other than the United States."
    },
    "encryption": {
     "v": "Encrypted at rest and in transit ('strong encryption'; algorithm not stated)",
     "src": "https://www.klaviyo.com/legal/data-processing-agreement",
     "q": "The personal data at rest is stored by Klaviyo using strong encryption"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": null
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "All Klaviyo customer data is stored in AWS us-east-1 in Northern Virginia.",
     "src": "https://www.klaviyo.com/legal/privacy-faqs",
     "q": "Klaviyo currently stores all Customer Data in the United States using the AWS-East-1 data center, located in Northern Virginia."
    },
    {
     "topic": "remote",
     "text": "Klaviyo staff in Australia, Ireland, Singapore and the UK may access (but not store) customer data to provide support across regions.",
     "src": "https://www.klaviyo.com/legal/privacy-faqs",
     "q": "our employees in Australia, Ireland, Singapore, and the United Kingdom may need to access (but not store) your data from those countries."
    },
    {
     "topic": "security",
     "text": "When SSO is enforced for all users, new users must accept the invite and log in via SSO; an exemption list lets chosen users bypass SSO.",
     "src": "https://help.klaviyo.com/hc/en-us/articles/9353860331035",
     "q": "If you enforce SSO for all users, any new user will need to accept the invitation and then log in using SSO."
    },
    {
     "topic": "security",
     "text": "The activity log is visible only to Account Owners, Admins and users with Account Settings permissions.",
     "src": "https://help.klaviyo.com/hc/en-us/articles/44579125790747",
     "q": "To ensure account security, the activity log is not visible to all users."
    }
   ]
  },
  {
   "slug": "lastpass",
   "name": "LastPass",
   "category": "Password Managers",
   "checked": "2026-09-19",
   "scope": "LastPass Teams, Business and Business Max; personal plans noted where relevant.",
   "profile_url": "https://helpcompare.com/tools/lastpass/#security-offline-remote",
   "trust_center": "https://www.lastpass.com/trust-center",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.lastpass.com/security",
     "q": "LastPass holds third-party security certifications like ISO 27001, SOC2 Type II, SOC3, BSI C5, TRUSTe, and more."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.lastpass.com/security",
     "q": "LastPass holds third-party security certifications like ISO 27001, SOC2 Type II, SOC3, BSI C5, TRUSTe, and more."
    },
    "other_certs": {
     "v": [
      "SOC 3",
      "ISO/IEC 27701",
      "IRAP",
      "BSI C5",
      "TRUSTe",
      "APEC CBPR",
      "APEC PRP",
      "EU-US DPF"
     ],
     "src": "https://compliance.lastpass.com/",
     "q": "Compliance SOC 2 SOC 3 ISO/IEC 27001 ISO/IEC 27701 IRAP BSI C5 TRUSTe APEC CBPR APEC PRP EU-US DPF"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": true,
     "plan": "Business",
     "src": "https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/FAQ_What_Is_Fed_Login.html&_LANG=enus",
     "q": "Note: This feature is only available for LastPass Business accounts."
    },
    "scim": {
     "v": true,
     "plan": "Business",
     "src": "https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/uac_directory_integrations.html&_LANG=enus",
     "q": "Restriction: Directory integration is only available for LastPass Business."
    },
    "mfa": {
     "v": true,
     "enforce": "Teams",
     "src": "https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/uac_adv_entopt_multifac_opt.html&_LANG=enus",
     "q": "For additional security measures, you can also choose to enforce various policies for your users to adhere to when using multifactor authentication when accessing their LastPass vaults."
    },
    "audit_log": {
     "v": true,
     "plan": "Teams",
     "src": "https://www.lastpass.com/pricing-business",
     "q": "Basic reporting allows admins to create shareable audit trails while advanced reporting generates automated reports on user activity and additional events, plus SIEM integrations for compliance."
    },
    "data_residency": {
     "v": [
      "US",
      "CA",
      "EU",
      "UK",
      "AU",
      "SG",
      "IN"
     ],
     "plan": "Business",
     "src": "https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/c_where_are_the_data_stored.html&_LANG=enus",
     "q": "Owners of LastPass Business accounts can request data migration from the United States to Canada, Europe, United Kingdom, Australia, Singapore, or India."
    },
    "encryption": {
     "v": "AES-256 local encryption with PBKDF2 SHA-256 hashing; zero-knowledge model",
     "src": "https://www.lastpass.com/security",
     "q": "LastPass uses AES-256 data encryption plus PBKDF2 hashing with SHA-256 salting."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "The browser extension, desktop app and mobile apps open a locally cached, read-only copy of the vault offline; new entries cannot be created until back online.",
     "src": "https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/FAQ_Permit_Offline_Access.html&_LANG=enus",
     "q": "You can access a locally cached, read-only version of your LastPass vault while offline."
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://lastpass.com/misc_download2.php",
     "q": "LastPass for Desktop If you need to access and manage your LastPass vault from your desktop without using a browser extension, this one’s for you."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://lastpass.com/misc_download2.php",
     "q": "LastPass for iPhone/iPad LastPass for Android"
    },
    "limits": {
     "v": "On Teams, Business and Business Max, admins can limit offline access by policy; clearing the local cache requires an online login to rebuild it.",
     "plan": "Teams",
     "src": "https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/FAQ_Permit_Offline_Access.html&_LANG=enus",
     "q": "Restriction: If you have a LastPass Teams, LastPass Business, or LastPass Business Max account, the ability to perform these actions may be limited due to policies set by your LastPass admin."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Business Max",
     "src": "https://www.lastpass.com/pricing-business",
     "q": "Contextual authentication policies Authenticate user logins based on their location, IP address, device, and more contextual information."
    },
    "device_controls": {
     "v": true,
     "plan": "Business Max",
     "summary": "Contextual (location/IP/device) authentication policies and workstation MFA on Business Max; travel mode and admin policies (e.g. prohibit export) on lower plans.",
     "src": "https://www.lastpass.com/pricing-business",
     "q": "Workstation MFA Enhance security for Windows/Mac workstation MFA with the LastPass Authenticator or passwordless login."
    },
    "office_hardware": {
     "v": "Hardware MFA options (standalone fingerprint scanners, card readers, hardware keys like YubiKey) on all business plans; Windows/Mac workstation MFA and a Universal Proxy for LDAP/RADIUS VPN apps on Business Max.",
     "src": "https://www.lastpass.com/pricing-business",
     "q": "Enhance security by employing standalone fingerprint scanners, card readers and hardware keys, like Yubikey."
    }
   },
   "facts": [
    {
     "topic": "offline",
     "text": "Offline, LastPass opens a cached read-only vault; you cannot create new entries until you reconnect.",
     "src": "https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/FAQ_Permit_Offline_Access.html&_LANG=enus",
     "q": "Restriction: Accessing your vault offline is a read-only mode, therefore creating new vault entries is not supported."
    },
    {
     "topic": "remote",
     "text": "Vault data is stored in the US by default; only Business accounts can request storage in Canada, Europe, UK, Australia, Singapore or India.",
     "src": "https://support.lastpass.com/s/document-item?language=en_US&bundleId=lastpass&topicId=LastPass/c_where_are_the_data_stored.html&_LANG=enus",
     "q": "If you have a LastPass Premium, LastPass Families, or LastPass Teams account, your vault data will be stored in the United States and cannot be moved."
    },
    {
     "topic": "office",
     "text": "Business Max adds MFA for legacy and VPN apps using LDAP or RADIUS through the LastPass Universal Proxy.",
     "src": "https://www.lastpass.com/pricing-business",
     "q": "Add multifactor authentication to you legacy and VPN apps that are using LDAP, RADIUS and/or LastPass Authentication servers."
    },
    {
     "topic": "security",
     "text": "LastPass's own incident notice says 2022 attackers accessed cloud backups including customer vault data; sensitive fields were encrypted but URLs were not.",
     "src": "https://blog.lastpass.com/posts/security-incident-update-recommended-actions",
     "q": "All sensitive customer vault data, other than URLs, file paths to installed LastPass Windows or macOS software, and certain use cases involving email addresses, were encrypted using our Zero knowledge model."
    }
   ]
  },
  {
   "slug": "linear",
   "name": "Linear",
   "category": "Project Management",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/linear/#security-offline-remote",
   "trust_center": "https://linear.app/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://linear.app/security",
     "q": "Linear undergoes regular Service Organization Controls audits (SOC 2 Type II)."
    },
    "iso27001": {
     "v": true,
     "src": "https://linear.app/security",
     "q": "Linear has achieved ISO/IEC 27001:2022 certification for its information security management system."
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise",
     "src": "https://linear.app/docs/security",
     "q": "For HIPAA compliance, we offer a Business Associate Agreement (BAA) to customers on our Enterprise plan."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://linear.app/docs/security",
     "q": "Refer to our Data Processing Agreement (DPA) for specific details."
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://linear.app/docs/login-methods",
     "q": "SAML authentication and IP restrictions are only available to workspaces on our Enterprise plan."
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://linear.app/docs/scim",
     "q": "Identity Management allows for the automation of user provisioning for your Linear workspace. Available to workspaces on our Enterprise plan"
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://linear.app/docs/audit-log",
     "q": "Audit logs show you a record of workspace events over the last 90 days. Available to workspaces on our Enterprise plan"
    },
    "data_residency": {
     "v": [
      "US",
      "EU"
     ],
     "src": "https://linear.app/docs/security",
     "q": "When creating a new workspace, you can choose to store data in the United States or European Union."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2 in transit",
     "src": "https://linear.app/security",
     "q": "Linear forces HTTPS on all connections and encrypts data in-transit with TLS 1.2. All data at-rest is secured using AES 256-bit encryption."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "When the desktop or web app loses connection it stores changes locally and retries them (even after a restart) once connectivity returns, but Linear describes this as a failsafe rather than a full offline feature.",
     "src": "https://linear.app/docs/get-the-app",
     "q": "Offline mode is designed as a failsafe and not a full-fledged feature."
    },
    "desktop": {
     "v": [
      "macOS",
      "Windows"
     ],
     "src": "https://linear.app/docs/get-the-app",
     "q": "Linear is available for macOS Intel, macOS Apple Silicon, and Windows."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://linear.app/docs/get-the-app",
     "q": "Linear is available on browsers, macOS, Windows, iOS and Android."
    },
    "limits": {
     "v": "No conflict check on sync: large offline edits can overwrite teammates' changes",
     "src": "https://linear.app/docs/get-the-app",
     "q": "if you make a lot of edits while in offline mode, you could overwrite changes from someone on your team"
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://linear.app/docs/login-methods",
     "q": "IP restrictions are available only on the Enterprise plan."
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Linear IP restrictions cover web, desktop and mobile access to the workspace.",
     "src": "https://linear.app/docs/login-methods",
     "q": "Once set, direct user access to the workspace, including web, desktop, and mobile access, will be limited to the set of configured IPs."
    },
    {
     "topic": "security",
     "text": "Admins can restrict which login methods members may use on Business and Enterprise plans.",
     "src": "https://linear.app/docs/login-methods",
     "q": "Login restrictions are available to workspaces on our Business and Enterprise plans."
    },
    {
     "topic": "remote",
     "text": "Even with an EU workspace, account information, API keys and usage data are always stored in the United States.",
     "src": "https://linear.app/docs/security",
     "q": "Regardless of the region you select for your workspace, the following data is always stored in the United States:"
    },
    {
     "topic": "remote",
     "text": "The data region is picked when the workspace is created and can't be changed self-serve later.",
     "src": "https://linear.app/docs/security",
     "q": "This setting isn’t self-serve to change later."
    }
   ]
  },
  {
   "slug": "madgicx",
   "name": "Madgicx",
   "category": "Paid Ads Management",
   "checked": "2026-09-19",
   "scope": "Madgicx web app (Pro Complete). No trust or security center was found; the Privacy Policy is the main security page.",
   "profile_url": "https://helpcompare.com/tools/madgicx/#security-offline-remote",
   "trust_center": "https://madgicx.com/privacy-policy",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": null
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "For personal data leaving the EEA, Madgicx relies on EU standard contractual clauses; its pages do not mention a customer DPA or any certification.",
     "src": "https://madgicx.com/privacy-policy",
     "q": "To the extent that your Personal Data is transferred outside of, or accessed from outside of, the EEA, we will ensure that approved safeguards are in place to comply with GDPR, such as the European Commission's approved standard contractual clauses."
    },
    {
     "topic": "remote",
     "text": "Workspace owners decide which ad accounts each invited team member can reach; new members join as advertisers unless made admins.",
     "src": "https://academy.madgicx.com/lessons/add-team-members",
     "q": "As a workspace owner , you control the ad accounts your team members can access."
    },
    {
     "topic": "security",
     "text": "Madgicx says its MCP connector for AI assistants (Claude, ChatGPT) works through an API rather than browser agents clicking in Meta Ads Manager, which it says Meta prohibits.",
     "src": "https://academy.madgicx.com/lessons/what-is-madgicx",
     "q": "Madgicx MCP connects directly through a secured API."
    },
    {
     "topic": "remote",
     "text": "Data may be stored outside your own country, including in the United States; no customer choice of hosting region is documented.",
     "src": "https://madgicx.com/privacy-policy",
     "q": "Depending on your location, data transfers may involve transferring and storing your information in a country other than your own, including but not limited to, the United States."
    }
   ]
  },
  {
   "slug": "mailchimp",
   "name": "Mailchimp",
   "category": "Email Marketing",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/mailchimp/#security-offline-remote",
   "trust_center": "https://mailchimp.com/about/security/",
   "fields": {
    "soc2": {
     "v": "Report (type not stated)",
     "src": "https://mailchimp.com/about/security/",
     "q": "Our SOC 2 reports cover controls around security, availability, and process integrity of customer data."
    },
    "iso27001": {
     "v": true,
     "src": "https://mailchimp.com/about/security/",
     "q": "The International Organization for Standardization 27001 Standard (ISO 27001) is an information security standard ... These certifications run for 3 years (renewal audits)"
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://mailchimp.com/about/security/",
     "q": "We may transfer data to those third parties as outlined in our Privacy Statement and Data Processing Addendum (DPA), and in accordance with data protection laws."
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Any multi-user plan (automatic once an Owner or Admin enables 2FA)",
     "src": "https://mailchimp.com/help/set-up-a-two-factor-authentication-app-at-login/",
     "q": "When an Owner or Admin enables 2-factor authentication for their login, all additional users with access to the account will also be required to set up 2-factor authentication"
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://mailchimp.com/about/security/",
     "q": "Mailchimp's owned and operated servers are located in world class data centers in the United States."
    },
    "encryption": {
     "v": "TLS 1.2+ in transit; at-rest encryption not stated",
     "src": "https://mailchimp.com/about/security/",
     "q": "The entire Mailchimp application is encrypted with TLS 1.2 or higher."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://mailchimp.com/help/about-mailchimp-for-android/",
     "q": "Mailchimp for Android will display in English, Spanish, Portuguese, German, French, Dutch, or Italian depending on the system language you set in your Android device."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Mailchimp's iOS and Android apps cover campaigns, reports, inbox replies and adding contacts, but Mailchimp says they do not replace the full web version.",
     "src": "https://mailchimp.com/help/about-mailchimp-for-ios/",
     "q": "This app can do a lot for you when you're out and about, but it's not meant to replace the full version of Mailchimp."
    },
    {
     "topic": "security",
     "text": "Mailchimp states it has SOC 2 reports but does not say on its security page whether they are Type I or Type II; reports are downloadable from the Intuit Compliance portal.",
     "src": "https://mailchimp.com/about/security/",
     "q": "Our SOC 2 reports cover controls around security, availability, and process integrity of customer data."
    },
    {
     "topic": "security",
     "text": "Mailchimp's terms leave HIPAA suitability to the customer and disclaim liability if the service does not meet HIPAA requirements.",
     "src": "https://mailchimp.com/legal/terms/",
     "q": "If you’re subject to regulations (like HIPAA) and you use the Service, then we won’t be liable if the Service doesn’t meet those requirements."
    },
    {
     "topic": "remote",
     "text": "Accounts have up to five user levels (Owner, Admin, Manager, Author, Viewer), and the number of seats depends on the pricing plan.",
     "src": "https://mailchimp.com/help/manage-user-levels-in-your-account/",
     "q": "Mailchimp accounts have up to 5 user levels: Owner, Admin, Manager, Author, and Viewer."
    }
   ]
  },
  {
   "slug": "make",
   "name": "Make",
   "category": "Workflow Automation",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/make/#security-offline-remote",
   "trust_center": "https://www.make.com/en/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.make.com/en/security",
     "q": "Along with GDPR adherence, we have completed SOC 2 Type II and SOC 3 audits."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.make.com/en/security",
     "q": "We operate under an information security program that is ISO 27001 certified and runs within an infrastructure compliant with SOC 3 and SOC 2 Type II."
    },
    "other_certs": {
     "v": [
      "SOC 3"
     ],
     "src": "https://www.make.com/en/security",
     "q": "Along with GDPR adherence, we have completed SOC 2 Type II and SOC 3 audits."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.make.com/en/privacy-and-gdpr",
     "q": "Contractual documentation: DPA and subprocessors list"
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.make.com/single-sign-on",
     "q": "this feature is available to enterprise customers"
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Enterprise",
     "src": "https://help.make.com/two-factor-authentication-enforcement",
     "q": "organization admins and owners can enforce two factor authentication (2fa) within their organization, requiring all users to enable it"
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.make.com/audit-logs",
     "q": "audit logs are available on the enterprise plan only organization owners and admins as well as team admins can access audit logs"
    },
    "data_residency": {
     "v": [
      "US",
      "EU"
     ],
     "src": "https://help.make.com/organizations",
     "q": "currently, supports two data center locations united states (us) european union (eu)"
    },
    "encryption": {
     "v": "AES-256 full-disk encryption at rest (AWS KMS keys); TLS 1.2/1.3 in transit",
     "src": "https://www.make.com/en/security",
     "q": "We use full-disk encryption within the industry-standard AES-256 encryption algorithm and AWS Key Management Service (KMS) for managing cryptographic keys."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://apps.apple.com/us/app/make-for-ios/id1177073656",
     "q": "Use the iOS app in your scenarios to connect your mobile phone or tablet to hundreds of other apps"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Each Make organization picks a US or EU data center when it is created, and this cannot be changed later.",
     "src": "https://help.make.com/organizations",
     "q": "you cannot change the location of the data center after you create the organization"
    },
    {
     "topic": "remote",
     "text": "Make's iOS and Android apps turn a phone into a trigger/action device for scenarios (e.g. call history, SMS); scenarios are built in the web app.",
     "src": "https://play.google.com/store/apps/details?id=com.integromat.android&hl=en_US",
     "q": "Connect your mobile phones or tablet to apps such as Facebook, Gmail, Instagram, Google Sheets, Google Contact, Dropbox, Trello, Slack, Zendesk, Mailchimp and many others."
    },
    {
     "topic": "security",
     "text": "Make's SSO supports both OpenID Connect and SAML 2.0, with Okta, Microsoft AD and Google as documented IdPs.",
     "src": "https://help.make.com/single-sign-on",
     "q": "supports the following protocols open id connect (oidc) saml 2 supports the following identity providers (idps) okta"
    },
    {
     "topic": "security",
     "text": "Audit logs are kept for 12 months.",
     "src": "https://help.make.com/audit-logs",
     "q": "audit logs are stored for 12 months"
    }
   ]
  },
  {
   "slug": "microsoft-365",
   "name": "Microsoft 365",
   "category": "Business Email & Office Suites",
   "checked": "2026-09-19",
   "scope": "Microsoft 365 Business Basic / Standard / Premium; identity controls come from Microsoft Entra ID in the tenant.",
   "profile_url": "https://helpcompare.com/tools/microsoft-365/#security-offline-remote",
   "trust_center": "https://www.microsoft.com/trust-center",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
     "q": "Office 365 SOC 2 Type 2 reports are relevant to system Security, Availability, Processing Integrity, Confidentiality, and Privacy."
    },
    "iso27001": {
     "v": true,
     "src": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-27001",
     "q": "Office 365—Global and Germany ISO 27001: Information Security Management Standards Certificate"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701"
     ],
     "src": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-27001",
     "q": "Office 365 - ISO 27001, 27017, 27018, 27701 Statement of Applicability (2024)"
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech",
     "q": "The Microsoft HIPAA Business Associate Agreement is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.microsoft.com/en-us/microsoft-365-copilot/business",
     "q": "all associated data handling commitments apply, including support for General Data Protection Regulation (GDPR), International Organization for Standardization (ISO)/IEC 27018, and the Microsoft Data Protection Addendum (DPA)."
    },
    "sso_saml": {
     "v": true,
     "plan": "Business Basic",
     "src": "https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-fed-saml-idp",
     "q": "your SAML 2.0 identity provider must implement to federate with Microsoft Entra ID to enable sign-on to one or more Microsoft cloud services"
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "All Business plans via security defaults; Conditional Access MFA policies need Entra ID P1 (Business Premium)",
     "src": "https://learn.microsoft.com/en-us/entra/fundamentals/licensing",
     "q": "Microsoft Entra ID Free - Security defaults (enabled for all users)"
    },
    "audit_log": {
     "v": true,
     "plan": "Business Basic",
     "src": "https://www.microsoft.com/en-us/microsoft-365/business/compare-all-microsoft-365-business-products",
     "q": "Ability to log and search for audited activities with Microsoft Purview Audit Standard Standard Standard"
    },
    "data_residency": {
     "src": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/o365-data-locations",
     "q": "Tenants in certain Local Region Geographies have access to Advanced Data Residency which provides more data residency commitments for certain in scope services."
    },
    "encryption": {
     "v": "BitLocker and per-file encryption at rest; TLS and IPsec in transit",
     "src": "https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy",
     "q": "Microsoft 365 uses service-side technologies that encrypt customer content at rest and in transit, including BitLocker, per-file encryption, Transport Layer Security (TLS), and Internet Protocol Security (IPsec)."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "full",
     "summary": "Installed Word, Excel and PowerPoint (desktop on Standard/Premium, mobile on all plans) can create, open and save files offline; cloud files must have been opened online once, and changes sync when reconnected.",
     "src": "https://support.microsoft.com/en-us/word/can-i-work-offline",
     "q": "If at any time you lose your Internet connection or turn it off, any pending changes will sync as soon as you're back online."
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "plan": "Business Standard",
     "src": "https://www.microsoft.com/en-us/microsoft-365/business/compare-all-microsoft-365-business-products",
     "q": "Number of devices Up to 5 PC or Mac, 5 tablets, and 5 mobile devices Up to 5 PC or Mac, 5 tablets, and 5 mobile devices Web and mobile apps only"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.microsoft.com/en-us/word/can-i-work-offline",
     "q": "Applies To Excel for iPad Word for iPad PowerPoint for iPad Excel for iPhone Word for iPhone PowerPoint for iPhone Word for Android tablets"
    },
    "limits": {
     "v": "Desktop Office apps only on Business Standard and Premium; Business Basic has web and mobile apps only. Extended offline activation (up to 180 days) is a Microsoft 365 Apps for enterprise feature.",
     "plan": "Business Standard",
     "src": "https://learn.microsoft.com/en-us/microsoft-365-apps/licensing-activation/overview-extended-offline-access",
     "q": "Extended offline access enables devices running Microsoft 365 Apps for enterprise to stay activated for up to six months without the need to connect to the internet"
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Business Premium",
     "src": "https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-assignment-network",
     "q": "Admins can create policies that target specific network locations as a signal along with other conditions in their decision making process."
    },
    "device_controls": {
     "v": true,
     "plan": "Business Premium",
     "summary": "Business Premium adds Intune Plan 1 endpoint management, Defender for Business device protection and Windows 11 Pro upgrade; Basic and Standard do not include Intune.",
     "src": "https://www.microsoft.com/en-us/microsoft-365/business/compare-all-microsoft-365-business-products",
     "q": "Endpoint management across devices with Intune Plan 1"
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "All three Business plans let you host Teams meetings and video calls for up to 300 people.",
     "src": "https://learn.microsoft.com/en-us/microsoftteams/limits-specifications-teams",
     "q": "you can host online meetings and video calls for up to 300 people using Microsoft Teams."
    },
    {
     "topic": "office",
     "text": "Each Business Standard or Premium user can install the Office apps on up to 5 PCs or Macs, 5 tablets and 5 phones.",
     "src": "https://www.microsoft.com/en-us/microsoft-365/business/compare-all-microsoft-365-business-products",
     "q": "Up to 5 PC or Mac, 5 tablets, and 5 mobile devices"
    },
    {
     "topic": "offline",
     "text": "On mobile, cloud files must be opened online at least once before they can be edited offline.",
     "src": "https://support.microsoft.com/en-us/word/can-i-work-offline",
     "q": "you'll need to have opened the file in online mode at least once. You can work on it offline after you have opened it."
    },
    {
     "topic": "security",
     "text": "Business Premium includes mailbox archiving with holds; Basic and Standard need the Exchange Online Archiving add-on for In-Place and Litigation Hold.",
     "src": "https://learn.microsoft.com/en-us/office365/servicedescriptions/exchange-online-archiving-service-description/exchange-online-archiving-service-description",
     "q": "Exchange Online Archiving for Exchange Online add-on adds auto-expanding archiving and In-Place Hold and Litigation Hold."
    }
   ]
  },
  {
   "slug": "microsoft-copilot",
   "name": "Microsoft 365 Copilot",
   "category": "AI Assistants",
   "checked": "2026-09-19",
   "scope": "Microsoft 365 Copilot / Copilot Chat for work accounts; identity and network controls come from the underlying Microsoft 365 / Microsoft Entra tenant.",
   "profile_url": "https://helpcompare.com/tools/microsoft-copilot/#security-offline-remote",
   "trust_center": "https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": true,
     "src": "https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy",
     "q": "Microsoft Copilot provides broad compliance offerings and certifications, including GDPR, ISO 27001, HIPAA, and the ISO 42001 standard for AI management systems."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 42001"
     ],
     "src": "https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy",
     "q": "Microsoft Copilot provides broad compliance offerings and certifications, including GDPR, ISO 27001, HIPAA, and the ISO 42001 standard for AI management systems."
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech",
     "q": "The Microsoft HIPAA Business Associate Agreement is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.microsoft.com/en-us/microsoft-365-copilot/business",
     "q": "all associated data handling commitments apply, including support for General Data Protection Regulation (GDPR), International Organization for Standardization (ISO)/IEC 27018, and the Microsoft Data Protection Addendum (DPA)."
    },
    "sso_saml": {
     "v": true,
     "plan": "Any eligible Microsoft 365 plan (sign-in via Microsoft Entra ID)",
     "src": "https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-requirements",
     "q": "Users must have Microsoft Entra ID accounts."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "All Microsoft 365 plans via Entra ID security defaults; Conditional Access policies need Entra ID P1 (included in Business Premium)",
     "src": "https://learn.microsoft.com/en-us/entra/fundamentals/licensing",
     "q": "Microsoft Entra ID Free - Security defaults (enabled for all users)"
    },
    "audit_log": {
     "v": true,
     "plan": "Copilot Chat (included)",
     "src": "https://learn.microsoft.com/en-us/copilot/privacy-and-protections",
     "q": "Before sending the response back to the user, both the prompt and response are logged and stored in Exchange for auditing/eDiscovery (Microsoft 365 tenant)."
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "BitLocker and per-file encryption at rest; TLS and IPsec in transit",
     "src": "https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy",
     "q": "Microsoft 365 uses service-side technologies that encrypt customer content at rest and in transit, including BitLocker, per-file encryption, Transport Layer Security (TLS), and Internet Protocol Security (IPsec)."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://support.microsoft.com/en-us/microsoft-365-copilot/what-is-microsoft-copilot-app",
     "q": "Desktop: The Microsoft Copilot app on Windows and Mac."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.microsoft.com/en-us/microsoft-365-copilot/what-is-microsoft-copilot-app",
     "q": "Mobile: The Microsoft Copilot app for iOS and Android."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Microsoft 365 Business Premium (Entra ID P1 Conditional Access)",
     "src": "https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-assignment-network",
     "q": "Admins can create policies that target specific network locations as a signal along with other conditions in their decision making process."
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "Copilot in Teams Phone works on VoIP and PSTN calls; no Copilot-specific room hardware is documented.",
     "src": "https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-requirements",
     "q": "Copilot in Teams Phone supports voice over Internet Protocol (VOIP) and public switched telephone network (PSTN) calls."
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "For EU customers Copilot runs inside the EU Data Boundary; customers outside the EU may have queries processed in the US, EU or other regions.",
     "src": "https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy",
     "q": "For EU customers, Microsoft Copilot is an EU Data Boundary service. Customers outside the EU may have their queries processed in the US, EU, or other regions."
    },
    {
     "topic": "security",
     "text": "Web-search queries that Copilot Chat sends to Bing fall outside the EU Data Boundary, which matters for EU teams with strict residency rules.",
     "src": "https://learn.microsoft.com/en-us/copilot/privacy-and-protections",
     "q": "Web search queries sent from Copilot Chat to Bing are not EUDB-compliant."
    },
    {
     "topic": "remote",
     "text": "Copilot in Teams is available on Windows, Mac, web, Android and iOS, so remote and in-office staff get the same meeting features.",
     "src": "https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-requirements",
     "q": "Copilot in Teams is available on Windows, Mac, web, Android, and iOS."
    },
    {
     "topic": "office",
     "text": "Even without a paid Copilot licence, Copilot Chat in Outlook can answer questions across a user's email, calendar, meetings and chats.",
     "src": "https://learn.microsoft.com/en-us/copilot/overview",
     "q": "Copilot Chat in Outlook provides additional organizational grounding for eligible users, even when they don't have a Microsoft 365 Copilot license."
    }
   ]
  },
  {
   "slug": "microsoft-teams",
   "name": "Microsoft Teams",
   "category": "Team Communication",
   "checked": "2026-09-19",
   "scope": "Microsoft Teams in Microsoft 365 / Office 365 commercial cloud. Certifications are Office 365-level with Teams in scope; identity controls (SAML federation, MFA, Conditional Access) come from Microsoft Entra ID; Conditional Access needs Entra ID P1 (e.g. Microsoft 365 Business Premium). Teams in-country data residency applies to new tenants.",
   "profile_url": "https://helpcompare.com/tools/microsoft-teams/#security-offline-remote",
   "trust_center": "https://learn.microsoft.com/en-us/microsoftteams/security-compliance-overview",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
     "q": "In addition, the Office 365 SOC 2 Type 2 attestation report addresses the requirements defined in the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM)"
    },
    "iso27001": {
     "v": true,
     "src": "https://learn.microsoft.com/en-us/microsoftteams/security-compliance-overview",
     "q": "Teams uses the following standards: ISO 27001 ISO 27018 SSAE18 SOC 1 and SOC 2 HIPAA"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "SOC 1"
     ],
     "src": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-27017",
     "q": "Microsoft Defender for Office 365, Microsoft Entra ID, Microsoft Purview portal, Microsoft Teams, MyAnalytics"
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech",
     "q": "Yes. Microsoft offers its covered entity and business associate customers a Business Associate Agreement that covers in-scope Microsoft services."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech",
     "q": "The Microsoft HIPAA Business Associate Agreement is available through the Microsoft Online Services Data Protection Addendum by default to all customers"
    },
    "sso_saml": {
     "v": true,
     "src": "https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-fed-saml-idp",
     "q": "Microsoft supports this sign-on experience as the integration of a Microsoft cloud service, such as Microsoft 365, with your properly configured SAML 2.0 profile-based IdP."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Microsoft Entra ID Free (security defaults)",
     "src": "https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults",
     "q": "Requiring all users to register for multifactor authentication"
    },
    "audit_log": {
     "v": true,
     "src": "https://learn.microsoft.com/en-us/microsoftteams/security-compliance-overview",
     "q": "Microsoft Purview Audit (Standard), Microsoft Purview Audit (Premium), and audit log search plug right into Microsoft Purview."
    },
    "data_residency": {
     "v": [
      "AU",
      "BR",
      "CA",
      "FR",
      "DE",
      "IN",
      "IT",
      "JP",
      "NO",
      "PL",
      "QA",
      "KR",
      "ZA",
      "SE",
      "CH",
      "AE",
      "UK",
      "Americas",
      "APAC",
      "EMEA"
     ],
     "src": "https://learn.microsoft.com/en-us/microsoftteams/privacy/location-of-data-in-teams",
     "q": "Data in Teams resides in the geographic region associated with your Microsoft 365 or Office 365 organization."
    },
    "encryption": {
     "v": "TLS 1.2+ with AES-256 in transit; BitLocker plus per-file encryption at rest; optional end-to-end encryption and Customer Key",
     "src": "https://learn.microsoft.com/en-us/microsoftteams/teams-encryption",
     "q": "Helps secure data in transit by using TLS 1.2 or later with AES-256, protecting information as it moves between devices and Microsoft servers."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://learn.microsoft.com/en-us/microsoftteams/teams-client-system-requirements",
     "q": "Linux users have access to Teams for Web and Teams as a progressive web app (PWA)."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://learn.microsoft.com/en-us/microsoftteams/teams-client-system-requirements",
     "q": "Android: Compatible with Android phones and tablets."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Microsoft Entra ID P1 (included in Microsoft 365 Business Premium)",
     "src": "https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-assignment-network",
     "q": "Named locations might include an organization's headquarters network ranges, VPN network ranges, or ranges you want to block."
    },
    "device_controls": {
     "v": true,
     "summary": "Microsoft Entra Conditional Access policies apply to Teams sign-ins (device compliance, location); Intune mobile application management; Conditional Access requires Entra ID P1.",
     "src": "https://learn.microsoft.com/en-us/microsoftteams/security-compliance-overview",
     "q": "Mobile application management with Microsoft Intune."
    },
    "office_hardware": {
     "v": "Microsoft Teams Rooms turn meeting spaces from huddle areas to large conference rooms into one-touch-join Teams rooms, sold as Windows and Android devices from partners.",
     "src": "https://learn.microsoft.com/en-us/microsoftteams/rooms/",
     "q": "Teams Rooms are available in Windows & Android variants from one of many partners."
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Microsoft says Teams can deliver HD video in under 1.5 Mbps; actual use varies per call.",
     "src": "https://learn.microsoft.com/en-us/microsoftteams/prepare-network",
     "q": "Teams is always conservative on bandwidth utilization and can deliver HD video quality in under 1.5 Mbps."
    },
    {
     "topic": "remote",
     "text": "Phone dial-in (Audio Conferencing) needs an add-on license for each organizer; people who dial in need none.",
     "src": "https://learn.microsoft.com/en-us/microsoftteams/audio-conferencing-in-office-365",
     "q": "Audio Conferencing requires an extra Teams add-on license for each person in your organization who is going to schedule/host an Audio Conferencing meeting."
    },
    {
     "topic": "remote",
     "text": "External guests with any business or consumer email address can be added to teams.",
     "src": "https://learn.microsoft.com/en-us/microsoftteams/guest-access",
     "q": "Anyone with a business or consumer email account, such as Outlook, Gmail, or others, can participate as a guest in Teams."
    },
    {
     "topic": "office",
     "text": "There is no native Linux desktop app; Linux users use Teams on the web or as a PWA.",
     "src": "https://learn.microsoft.com/en-us/microsoftteams/teams-client-system-requirements",
     "q": "Linux users have access to Teams for Web and Teams as a progressive web app (PWA)."
    }
   ]
  },
  {
   "slug": "monday",
   "name": "Monday.com",
   "category": "Project Management",
   "checked": "2026-09-19",
   "scope": "monday.com Work Management; security and compliance pages are shared across monday.com products",
   "profile_url": "https://helpcompare.com/tools/monday/#security-offline-remote",
   "trust_center": "https://monday.com/trustcenter",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://monday.com/trustcenter",
     "q": "SOC 1 Type II Report SOC 2 Type II Report SOC 3 Report"
    },
    "iso27001": {
     "v": true,
     "src": "https://monday.com/trustcenter",
     "q": "ISO/IEC 27001:2022 ISO/IEC 27018:2019 ISO/IEC 27017:2015"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27032",
      "ISO/IEC 27701",
      "CSA STAR",
      "TX-RAMP",
      "SOC 1 Type II",
      "SOC 3"
     ],
     "src": "https://monday.com/trustcenter",
     "q": "ISO/IEC 27017:2015 ISO/IEC 27032:2023 ISO/IEC 27701:2019 CSA Star TX RAMP"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise",
     "src": "https://support.monday.com/hc/en-us/articles/360006506699-monday-com-and-HIPAA",
     "q": "HIPAA is available on monday.com on our Enterprise plan."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://support.monday.com/hc/en-us/articles/31119344104082-Security-and-privacy-on-monday-com-FAQs",
     "q": "We process this data solely on our customers’ behalf, in accordance with the Data Processing Addendum."
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.monday.com/hc/en-us/articles/360000460605-SAML-Single-Sign-on",
     "q": "Note: SAML SSO is available on Enterprise plan only."
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.monday.com/hc/en-us/articles/360021893619-SCIM-Provisioning-API",
     "q": "Note: SCIM Provisioning is available on the Enterprise plan only."
    },
    "mfa": {
     "v": true,
     "enforce": "All plans",
     "src": "https://support.monday.com/hc/en-us/articles/360000787745-Two-Factor-Authentication",
     "q": "2FA is available on all plans, and admins are the only ones who can enable it for the account."
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.monday.com/hc/en-us/articles/360001259429-The-Audit-Log",
     "q": "Available on Enterprise plan"
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "AU"
     ],
     "src": "https://support.monday.com/hc/en-us/articles/31119344104082-Security-and-privacy-on-monday-com-FAQs",
     "q": "We offer hosting in the US, EU, and AUS Data Regions."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.3 (minimum TLS 1.2) in transit",
     "src": "https://support.monday.com/hc/en-us/articles/31119344104082-Security-and-privacy-on-monday-com-FAQs",
     "q": "Data at rest is encrypted using AES-256. Data in transit across open networks is encrypted using TLS 1.3 (at minimum TLS 1.2)."
    },
    "self_host": {
     "v": false,
     "src": "https://support.monday.com/hc/en-us/articles/31119344104082-Security-and-privacy-on-monday-com-FAQs",
     "q": "monday.com is a fully cloud-based service and does not offer an on-premises version."
    },
    "mode": {
     "v": "partial",
     "summary": "The mobile apps work offline: Android can create, rename, delete and move items and change column values, iOS can change column values, and changes upload once you reconnect.",
     "src": "https://support.monday.com/hc/en-us/articles/360017712819-Mobile-app-Offline-Mode",
     "q": "Offline mode allows you to make changes to your boards and check notifications and updates without an internet connection any time anywhere!"
    },
    "desktop": {
     "v": [
      "macOS",
      "Windows"
     ],
     "src": "https://support.monday.com/hc/en-us/articles/115005316885-monday-com-s-desktop-app",
     "q": "You can seamlessly download the desktop app to your computer by searching \"monday.com\" in your macOS or Windows app store"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.monday.com/hc/en-us/articles/115005317225-monday-com-mobile-apps-iPhone-iPad-tablet-and-Android",
     "q": "monday.com mobile apps (iPhone, iPad, tablet, and Android)"
    },
    "limits": {
     "v": "Mobile apps only; about 70% of board actions, with fewer supported on iOS than Android",
     "src": "https://support.monday.com/hc/en-us/articles/360017712819-Mobile-app-Offline-Mode",
     "q": "You can currently carry out 70% of all board actions while working offline!"
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.monday.com/hc/en-us/articles/360020408039-How-to-set-up-IP-restrictions-on-an-account",
     "q": "admins of an Enterprise plan now have the ability to pre-define specific IP addresses which will be able to join the account."
    },
    "device_controls": {
     "v": true,
     "summary": "Session duration (automatic log-out), a Panic Button that locks down the account, and tenant-level restrictions on which monday.com accounts can be reached from your network.",
     "src": "https://support.monday.com/hc/en-us/articles/34336185460498-monday-com-secure-configuration-checklist",
     "q": "Define an automatic log out for your account members at certain intervals to ensure access is secured according to any internal policies you might have."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "office",
     "text": "monday.com's IP restrictions are designed to limit account access to users on the office network or a specific VPN.",
     "src": "https://support.monday.com/hc/en-us/articles/360020408039-How-to-set-up-IP-restrictions-on-an-account",
     "q": "This can be extremely useful if you are looking to restrict account access only to users joining from a specific location (i.e. from the office), those using a certain VPN, or more!"
    },
    {
     "topic": "remote",
     "text": "IP restrictions also apply to the mobile app, so staff outside allowed IPs cannot log in from phones.",
     "src": "https://support.monday.com/hc/en-us/articles/360020408039-How-to-set-up-IP-restrictions-on-an-account",
     "q": "The mobile app is bounded by the IP restrictions, too."
    },
    {
     "topic": "remote",
     "text": "An account's data region is set automatically from the location of the first user who opens it; a different region needs a new account.",
     "src": "https://support.monday.com/hc/en-us/articles/4404392703250-Data-residency",
     "q": "Your account’s data region is set automatically based on the location of the first user who opens the account."
    },
    {
     "topic": "offline",
     "text": "Offline edits made on mobile overwrite a colleague's changes to the same item when you reconnect.",
     "src": "https://support.monday.com/hc/en-us/articles/360017712819-Mobile-app-Offline-Mode",
     "q": "If someone else has made changes to the same item, your change will override theirs as soon as you are connected to a server."
    }
   ]
  },
  {
   "slug": "n8n",
   "name": "n8n",
   "category": "Workflow Automation",
   "checked": "2026-09-19",
   "scope": "n8n Cloud researched for plan, SSO and hosting fields; the self-hosted edition runs on your own infrastructure, where you handle encryption and hosting yourself.",
   "profile_url": "https://helpcompare.com/tools/n8n/#security-offline-remote",
   "trust_center": "https://trust.n8n.io/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://trust.n8n.io/",
     "q": "SOC 2 Type 2"
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "SOC 3"
     ],
     "src": "https://n8n.io/legal/security/",
     "q": "You can download our SOC 3 report here. The report contains the auditor’s opinion, management assertion, and system description."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://trust.n8n.io/",
     "q": "Data Processing Agreement"
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://n8n.io/legal/security/",
     "q": "SSO, SAML, and LDAP are available with n8n’s Enterprise plan."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://docs.n8n.io/user-management/two-factor-auth/",
     "q": "n8n supports 2FA using an authenticator app."
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise (log streaming to your own tools)",
     "src": "https://docs.n8n.io/log-streaming/",
     "q": "Log Streaming is available on: n8n Cloud: Enterprise Self-hosted: Enterprise"
    },
    "data_residency": {
     "v": [
      "EU"
     ],
     "src": "https://n8n.io/legal/security/",
     "q": "The physical hardware powering n8n, and the data stored by the platform, is currently hosted in the European Union."
    },
    "encryption": {
     "v": "Cloud: AES-256 at rest (Azure server-side encryption, FIPS 140-2); traffic encrypted in transit",
     "src": "https://n8n.io/legal/security/",
     "q": "n8n uses Azure Storage server-side encryption (using AES256 and a FIPS-140-2 compliant implementation)."
    },
    "self_host": {
     "v": true,
     "src": "https://docs.n8n.io/hosting/",
     "q": "You can self-host n8n on your own infrastructure, on-premises, or in a private cloud, using Docker Compose, one-line setup, or other deployment methods."
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": null
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "office",
     "text": "Self-hosted n8n can run on-premises, but you must put a TLS reverse proxy in front of it and handle encryption at rest yourself.",
     "src": "https://n8n.io/legal/security/",
     "q": "Ensure data is encrypted in transit by setting up a reverse proxy in front of the n8n instance to handle TLS."
    },
    {
     "topic": "security",
     "text": "n8n Cloud runs on Microsoft Azure in the EU; n8n says it is preparing other hosting locations.",
     "src": "https://n8n.io/legal/security/",
     "q": "n8n cloud uses Microsoft Azure for hosting."
    },
    {
     "topic": "security",
     "text": "The full SOC 2 report is available to enterprise customers; others can use the public SOC 3 report.",
     "src": "https://n8n.io/legal/security/",
     "q": "Our SOC 2 report is available to enterprise customers."
    },
    {
     "topic": "remote",
     "text": "Custom session timeouts are supported on self-hosted n8n.",
     "src": "https://n8n.io/legal/security/",
     "q": "n8n supports custom session timeouts on self-hosted."
    }
   ]
  },
  {
   "slug": "notion",
   "name": "Notion",
   "category": "Knowledge Management",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/notion/#security-offline-remote",
   "trust_center": "https://www.notion.com/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.notion.com/security",
     "q": "The SOC 2 Type 2 is an audit report performed by an independent third-party certified by the American Institute of Certified Public Accountants (AICPA)"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.notion.com/security",
     "q": "Notion has achieved certifications for four ISO standards: ISO 27001, ISO 27701, ISO 27017, and ISO 27018."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27701",
      "ISO/IEC 27017",
      "ISO/IEC 27018"
     ],
     "src": "https://www.notion.com/security",
     "q": "Notion has achieved certifications for four ISO standards: ISO 27001, ISO 27701, ISO 27017, and ISO 27018."
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise",
     "src": "https://www.notion.com/help/hipaa",
     "q": "To be eligible to sign Notion’s BAA, you must subscribe to our Enterprise Plan."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.notion.com/security",
     "q": "Our Master Subscription Agreement and Data Processing Addendum describe in detail Notion’s data privacy processes"
    },
    "sso_saml": {
     "v": true,
     "plan": "Business",
     "src": "https://www.notion.com/help/saml-sso-configuration",
     "q": "Note: This feature is only available for users on the Business Plan or Enterprise Plan."
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.notion.com/help/provision-users-and-groups-with-scim",
     "q": "Note: This feature is only available for users on the Enterprise Plan."
    },
    "mfa": {
     "v": true,
     "src": "https://www.notion.com/help/two-step-verification",
     "q": "This feature is available to all plan types and can be set up easily in your account settings."
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://www.notion.com/help/audit-log",
     "q": "Note: The audit log feature is available to organization owners on the Enterprise Plan."
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "JP",
      "KR"
     ],
     "plan": "Enterprise",
     "src": "https://www.notion.com/help/data-residency",
     "q": "If you’re on an Enterprise Plan, you can request to move existing workspace data to your selected data region."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2+ in transit",
     "src": "https://www.notion.com/help/security-and-privacy",
     "q": "Encryption at rest: Customer data is encrypted at rest using AES-256."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "full",
     "summary": "In the desktop and mobile apps you can view, edit and create pages offline once they are downloaded to that device; changes save locally and sync automatically when you reconnect.",
     "src": "https://www.notion.com/help/guides/working-offline-in-notion-everything-you-need-to-know",
     "q": "All Notion users can view, edit, and create pages offline on the desktop or mobile app."
    },
    "desktop": {
     "v": [
      "macOS",
      "Windows"
     ],
     "src": "https://www.notion.com/help/notion-for-desktop",
     "q": "You can use Notion on your Mac or PC as a downloadable desktop application."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.notion.com/help/notion-for-mobile",
     "q": "You can download Notion on your iOS or Android device for easy access on the go."
    },
    "limits": {
     "v": "Pages must be marked Available offline per device; automatic download of recent and favorited pages only on Business and Enterprise; databases download the first 50 rows",
     "plan": "Business (auto-download)",
     "src": "https://www.notion.com/help/guides/working-offline-in-notion-everything-you-need-to-know",
     "q": "On the Business, and Enterprise plans, Notion also automatically downloads your recent and favorited pages, so they're ready when you need them."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "offline",
     "text": "Sharing and permission changes are unavailable offline, so set access before disconnecting.",
     "src": "https://www.notion.com/help/guides/working-offline-in-notion-everything-you-need-to-know",
     "q": "You won’t be able to share pages or change permissions while offline"
    },
    {
     "topic": "offline",
     "text": "Offline databases download only the first 50 rows automatically; other rows must be downloaded individually.",
     "src": "https://www.notion.com/help/guides/working-offline-in-notion-everything-you-need-to-know",
     "q": "When you download a database, the first 50 rows download automatically."
    },
    {
     "topic": "remote",
     "text": "Offline text edits merge automatically with collaborators' changes; non-text changes may need review.",
     "src": "https://www.notion.com/help/guides/working-offline-in-notion-everything-you-need-to-know",
     "q": "Text merges happen automatically, with non-text changes (like images) sometimes needing a quick review."
    },
    {
     "topic": "security",
     "text": "Guests cannot use SAML SSO; only workspace members can sign in with it.",
     "src": "https://www.notion.com/help/saml-sso-configuration",
     "q": "Note: Only workspace members can use SAML SSO to log in."
    }
   ]
  },
  {
   "slug": "optmyzr",
   "name": "Optmyzr",
   "category": "Paid Ads Management",
   "checked": "2026-09-19",
   "scope": "Optmyzr web platform (Search, Amazon and Social tools); no dedicated trust center was found, so security facts come from the Privacy Policy, Data Processor Agreement and help center.",
   "profile_url": "https://helpcompare.com/tools/optmyzr/#security-offline-remote",
   "trust_center": "https://www.optmyzr.com/information/data-processor-agreement/",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.optmyzr.com/information/data-processor-agreement/",
     "q": "This Data Processing Agreement (the “DPA”), entered into by the Optmyzr Customer identified on the applicable Optmyzr ordering document for Optmyzr services (“Customer”) and Optmyzr, Inc."
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.optmyzr.com/en/articles/11503410-features-available-to-enterprise-users",
     "q": "Apart from Google and Microsoft SSO, enterprise plan users have access to log in to Optmyzr using OKTA SSO."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "All plans (on by default for email/password logins; SSO-only login for a whole team on request to support)",
     "src": "https://help.optmyzr.com/en/articles/3188196-login-sign-up-options",
     "q": "2-Step Verification also known as 2-Factor Authentication, is enabled by Optmzyr for all users by default. You will not be able to disable 2FA from the interface."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "Encryption in transit and at rest",
     "src": "https://www.optmyzr.com/information/privacy-policy/",
     "q": "We use technical and organizational measures such as encryption in transit and at rest, two-factor authentication options, access controls, and monitoring"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": null
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Optmyzr's DPA commits it to provide customers each year with a third-party SSAE 18 or ISAE 3402 service-organization control report; no SOC 2 report type or certification is named on its pages.",
     "src": "https://www.optmyzr.com/information/data-processor-agreement/",
     "q": "under the Statement on Standards for Attestation Engagements (SSAE) No. 18 (“SSAE 18”) (Reporting on Controls at a Service Organization) or the International Standard on Assurance Engagements (ISAE) 3402"
    },
    {
     "topic": "remote",
     "text": "Email/password logins get a 5-digit code by email and are re-verified only every 30 days; authenticator-app codes are also supported.",
     "src": "https://help.optmyzr.com/en/articles/3074846-managing-users-team-members",
     "q": "After verification, you will only be prompted to re-verify your login session once every 30 days."
    },
    {
     "topic": "remote",
     "text": "Each team member should have their own login so the activity logs show who made changes in Google Ads; per-account access levels are Enterprise only.",
     "src": "https://help.optmyzr.com/en/articles/3074846-managing-users-team-members",
     "q": "you can give every user their own Optmyzr account so that the activity logs will correctly show who made changes in Google Ads."
    },
    {
     "topic": "remote",
     "text": "Support is by email from teams on three continents, often including weekends; screen-share calls can be requested.",
     "src": "https://help.optmyzr.com/en/articles/3072987-general-faqs",
     "q": "Our support team is ready to answer any question via email, and since we have teams on 3 continents, we almost always have someone online - even on weekends!"
    }
   ]
  },
  {
   "slug": "outreach",
   "name": "Outreach",
   "category": "Sales Engagement Platforms",
   "checked": "2026-09-19",
   "scope": "Outreach sales execution platform (outreach.io now redirects to outreach.ai). Outreach's trust center is gated (contact account executive), so plan-level availability of admin controls was not published.",
   "profile_url": "https://helpcompare.com/tools/outreach/#security-offline-remote",
   "trust_center": "https://www.outreach.ai/platform/trust",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.outreach.ai/platform/security",
     "q": "Outreach maintains SOC 2 Type II, ISO 27001, ISO 27701, EU-U.S. Privacy Shield, and TRUSTe certifications."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.outreach.ai/platform/security",
     "q": "Outreach maintains SOC 2 Type II, ISO 27001, ISO 27701, EU-U.S. Privacy Shield, and TRUSTe certifications."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27701",
      "ISO/IEC 42001",
      "HIPAA",
      "CSA STAR",
      "TRUSTe"
     ],
     "src": "https://www.outreach.ai/platform/trust",
     "q": "SOC 2 Type II ISO 27001 ISO 27701 ISO 42001 HIPAA Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR)"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.outreach.ai/platform/security",
     "q": "Many of these measures are detailed in the data processing terms and/or DPA of your agreement."
    },
    "sso_saml": {
     "v": true,
     "src": "https://www.outreach.ai/platform/security",
     "q": "The Outreach platform supports federated access via SAML 2.0 in order to provide SSO by any number of Identity Providers (IdP)."
    },
    "scim": {
     "v": true,
     "src": "https://support.outreach.io/support/solutions/articles/159000426332-outreach-single-sign-on-sso-faq",
     "q": "Outreach currently does not support a gallery app for Azure; however, we provide a SCIM API via OAuth."
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "EU"
     ],
     "src": "https://support.outreach.io/support/solutions/articles/159000426317-outreach-product-release-notes-july-2023",
     "q": "specifically for EU citizen data to reside in the EU, Outreach now offers Forecasting and Pipeline Management in its EU datacenter."
    },
    "encryption": {
     "v": "Encrypted at rest and in transit; TLS 1.2 or higher enforced for browser connections",
     "src": "https://www.outreach.ai/platform/security",
     "q": "they use a web browser over an enforced Transport Layer Security (TLS) 1.2 or higher connection."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.outreach.io/support/solutions/articles/159000425603-outreach-mobile-app-overview",
     "q": "The app is available for both iOS and Android phones."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Outreach runs an EU datacenter where prospects, accounts, meetings and call recordings for EU-hosted instances stay within EU infrastructure; where your data resides is set in the data processing terms of your agreement.",
     "src": "https://support.outreach.io/support/solutions/articles/159000425766-outreach-product-release-notes-may-2023",
     "q": "Customer-owned data associated with those Outreach instances including prospects, accounts, organizations, meetings, and call recordings will be stored and contained within the EU infrastructure."
    },
    {
     "topic": "security",
     "text": "There is no Microsoft Entra ID (Azure AD) gallery app for automatic provisioning; teams on Entra must build against Outreach's SCIM API.",
     "src": "https://support.outreach.io/support/solutions/articles/159000426332-outreach-single-sign-on-sso-faq",
     "q": "No, for automatic SCIM provisioning, Outreach currently does not support a gallery app for Azure; however, we provide a SCIM API via OAuth."
    },
    {
     "topic": "security",
     "text": "Security documentation in Outreach's trust center is not public; buyers must request access through their account executive.",
     "src": "https://www.outreach.ai/platform/trust",
     "q": "For Trust Center Access, Please Contact Your Account Executive."
    }
   ]
  },
  {
   "slug": "pandadoc",
   "name": "PandaDoc",
   "category": "E-Signature & Document Workflow",
   "checked": "2026-09-19",
   "scope": "PandaDoc Starter, Business and Enterprise plans",
   "profile_url": "https://helpcompare.com/tools/pandadoc/#security-offline-remote",
   "trust_center": "https://www.pandadoc.com/security/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.pandadoc.com/security/",
     "q": "PandaDoc is SOC 2 Type II compliant. We can provide our latest SSAE 18 SOC 2 Type II report and attestation of compliance upon request."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "HIPAA"
     ],
     "src": "https://www.pandadoc.com/security/",
     "q": "PandaDoc is compliant with HIPAA and the Privacy Rule, as well as the Administrative Safeguards, Physical Safeguards and Technical Safeguards of the Security Rule."
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise (add-on)",
     "src": "https://www.pandadoc.com/hipaa/",
     "q": "In order to transmit electronic Protected Health Information (ePHI) using PandaDoc and maintain it with HIPAA compliance, customers should sign a Business Associate Agreement (BAA) with PandaDoc."
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise (Business: paid add-on)",
     "src": "https://support.pandadoc.com/en/articles/9715050-sso-implementation",
     "q": "Availability: Enterprise plan"
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.pandadoc.com/en/articles/9715050-sso-implementation",
     "q": "PandaDoc supports SCIM (System for Cross-domain Identity Management) to automate user management for your organization."
    },
    "mfa": {
     "v": true,
     "src": "https://support.pandadoc.com/hc/en-us/articles/16804817099927-Two-factor-authentication-2FA",
     "q": "App authentication – all plans."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US",
      "EU"
     ],
     "plan": "Enterprise",
     "src": "https://www.pandadoc.com/eu-server-information/",
     "q": "PandaDoc provides the flexibility your business needs for data residency* in two equally secure locations: the U.S. and EU."
    },
    "encryption": {
     "v": "AES-256 at rest; encrypted in transit",
     "src": "https://www.pandadoc.com/security/",
     "q": "All data in each location is encrypted at rest with AES-256 and sophisticated encryption keys management."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.pandadoc.com/mobile/",
     "q": "PandaDoc Mobile App - Create & Send Docs on Android and IOS"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "PandaDoc can't enforce 2FA for a whole organization natively; the workaround is to require SSO and enforce 2FA at the identity provider.",
     "src": "https://support.pandadoc.com/hc/en-us/articles/16804817099927-Two-factor-authentication-2FA",
     "q": "No, however, you can achieve this by utilizing Single Sign-On (SSO) and enforcing 2FA on the SSO side."
    },
    {
     "topic": "security",
     "text": "On the Business plan, SSO costs extra: $20 a month or $240 a year per seat.",
     "src": "https://support.pandadoc.com/en/articles/9715050-sso-implementation",
     "q": "Business plan: available as a paid add-on ($20/month or $240/year per seat)."
    },
    {
     "topic": "remote",
     "text": "You can store document data in the US or the EU; the pricing page lists this under Enterprise.",
     "src": "https://www.pandadoc.com/eu-server-information/",
     "q": "Choose where your data gets stored and processed"
    }
   ]
  },
  {
   "slug": "paypal",
   "name": "PayPal",
   "category": "Payment Processing",
   "checked": "2026-09-19",
   "scope": "PayPal Business account, including PayPal Zettle / Point of Sale for in-person payments. Features vary by country.",
   "profile_url": "https://helpcompare.com/tools/paypal/#security-offline-remote",
   "trust_center": "https://www.paypal.com/us/security",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "PCI DSS Level 1 (Service Provider)"
     ],
     "src": "https://www.paypal.com/us/business/payment-processing",
     "q": "PayPal Enterprise Payments is a Level 1 PCI DSS compliant service provider."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.paypal.com/us/legalhub/paypal/data-protection",
     "q": "This Addendum forms part of the applicable agreement between you (“you” or “Merchant”) and PayPal"
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://www.paypal.com/us/cshelp/article/what-is-2-step-verification-help167",
     "q": "PayPal’s 2-step verification (two-factor authentication) gives you an extra layer of security when accessing your account."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "Offline card payments work only on a PayPal Reader used through a third-party POS app built on the Zettle SDK; queued payments upload when the device reconnects.",
     "src": "https://www.zettle.com/gb/help/articles/7102116-offline-payments",
     "q": "Offline payments are currently only available to sellers who use PayPal Point of Sale with third-party apps integrated via some SDK partners."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.paypal.com/us/cshelp/article/what-are-the-benefits-of-paypals-apps-and-how-do-i-download-them%E2%80%AF-help379",
     "q": "All PayPal apps are available to download from the iOS App Store or Android Play store."
    },
    "limits": {
     "v": "Reconnect within 24 hours of the first offline payment; offline mode requires a PayPal Reader on the latest software",
     "src": "https://www.zettle.com/gb/help/articles/7102116-offline-payments",
     "q": "Failing to connect to the internet within 24 hours will increase the risk of transactions being declined and therefore merchandise being lost."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "PayPal sells the Bluetooth Card Reader and the PayPal Reader for in-person chip, contactless and mobile-wallet payments through the Point of Sale app.",
     "src": "https://paypal.com/us/cshelp/article/what-is-the-the-zettle-card-reader-and-its-accessories-help609",
     "q": "The Card Reader : Connects to your device using Bluetooth. Accepts chip and PIN, contactless payments, and mobile payments including Apple Pay, Google Pay, and Samsung Pay."
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "A business account owner can add users and choose each user's account privileges from Account Settings.",
     "src": "https://www.paypal.com/us/cshelp/article/how-do-i-manage-users-on-my-business-account-help274",
     "q": "Select which account privileges you want the user to have"
    },
    {
     "topic": "offline",
     "text": "Uninstalling the POS app, clearing the device cache or factory-resetting it while offline payments are pending permanently deletes those stored payments.",
     "src": "https://www.zettle.com/gb/help/articles/7102116-offline-payments",
     "q": "Do not uninstall your POS app, clear your device cache or factory reset your device while you have unprocessed offline payments."
    }
   ]
  },
  {
   "slug": "pipedrive",
   "name": "Pipedrive",
   "category": "CRM Platforms — Small Teams",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/pipedrive/#security-offline-remote",
   "trust_center": "https://trustcenter.pipedrive.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://trustcenter.pipedrive.com/",
     "q": "SOC 2 Type 2"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.pipedrive.com/en/newsroom/pipedrive-strengthens-security-and-privacy-commitments-with-renewed-iso-certifications",
     "q": "Successfully transitioned to the new ISO/IEC 27001:2022 standard"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27701",
      "SOC 3"
     ],
     "src": "https://www.pipedrive.com/en/newsroom/pipedrive-strengthens-security-and-privacy-commitments-with-renewed-iso-certifications",
     "q": "Successfully renewed certification under ISO/IEC 27701:2019 , the international standard for Privacy Information Management Systems (PIMS)."
    },
    "hipaa": {
     "v": "Not supported",
     "src": "https://www.pipedrive.com/en/terms-of-service",
     "q": "Pipedrive Services are not designed to comply with industry-specific regulations such as the Health Insurance Portability and Accountability Act (HIPAA)"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://support.pipedrive.com/en/article/pipedrive-and-gdpr",
     "q": "This is where our Data Processing Addendum (DPA) , Terms of Service and Privacy Notice come in."
    },
    "sso_saml": {
     "v": true,
     "plan": "All plans",
     "src": "https://support.pipedrive.com/en/article/single-sign-on",
     "q": "Note: The single sign-on feature is one of the many useful features available for all Pipedrive plans."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "All plans",
     "src": "https://support.pipedrive.com/en/article/security-rules",
     "q": "Note: Enforcing of 2FA is available in all Pipedrive plans."
    },
    "audit_log": {
     "v": true,
     "src": "https://support.pipedrive.com/en/article/security-features-in-pipedrive",
     "q": "A log of all of the security-related changes made in your company account by any user in the past two months"
    },
    "data_residency": {
     "src": "https://support.pipedrive.com/en/article/how-secure-is-my-data-in-pipedrive",
     "q": "new sign-ups originating from specific regions will primarily be hosted in specific data centers"
    },
    "encryption": {
     "v": "Encrypted at rest and in transit (algorithms not specified publicly)",
     "src": "https://www.pipedrive.com/en/features/privacy-security",
     "q": "state-of-the-art encryption for all data, whether at rest or in transit over public networks"
    },
    "self_host": {
     "v": false,
     "src": "https://support.pipedrive.com/en/article/can-pipedrive-be-used-offline",
     "q": "Pipedrive doesn't have a separate desktop app and can only be used online within a web browser."
    },
    "mode": {
     "v": "full",
     "summary": "The iOS and Android apps keep working without a connection (move deals, add notes and activities) and sync changes to the web app automatically once back online; the web app needs a connection.",
     "src": "https://support.pipedrive.com/en/article/do-the-mobile-apps-work-offline",
     "q": "When your phone regains an internet connection, Pipedrive will then sync the new or updated data from your mobile app to your web app automatically."
    },
    "desktop": {
     "v": [],
     "src": "https://support.pipedrive.com/en/article/can-pipedrive-be-used-offline",
     "q": "Pipedrive doesn't have a separate desktop app and can only be used online within a web browser."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.pipedrive.com/en/article/can-pipedrive-be-used-offline",
     "q": "However, both the Pipedrive iOS and Android mobile apps allow for working offline."
    },
    "limits": {
     "v": "Mobile apps only; offline mode can't be toggled manually",
     "src": "https://support.pipedrive.com/en/article/can-pipedrive-be-used-offline",
     "q": "Offline and online modes can't be toggled on mobile apps, they will default to online mode if there is an internet connection available."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Ultimate",
     "src": "https://support.pipedrive.com/en/article/security-features-in-pipedrive",
     "q": "Note: The security rules feature is available to users of our Ultimate plan."
    },
    "device_controls": {
     "v": true,
     "plan": "Ultimate",
     "summary": "Security rules can limit access to set IP addresses and time windows; the security dashboard shows each user's device, location and login time.",
     "src": "https://support.pipedrive.com/en/article/security-features-in-pipedrive",
     "q": "Which users are accessing your account and any additional login information such as device, location and login time"
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "office",
     "text": "On Ultimate, admins can restrict non-admin users to office IP addresses and to set working hours.",
     "src": "https://support.pipedrive.com/en/article/security-rules",
     "q": "If you want your users to only access Pipedrive when they’re in specific locations, you can add IP address conditions to your advanced security rules."
    },
    {
     "topic": "security",
     "text": "Pipedrive assigns the hosting region (AU, CA, EU, UK or US) from where the account signs up; customers must ask support to confirm where their data is hosted.",
     "src": "https://support.pipedrive.com/en/article/how-secure-is-my-data-in-pipedrive",
     "q": "If you would like to know exactly where your company’s data is hosted, please reach out to our Support team ."
    },
    {
     "topic": "security",
     "text": "Pipedrive's SSO does not work alongside its own two-factor authentication, so MFA must be enforced in the identity provider when SSO is used.",
     "src": "https://support.pipedrive.com/en/article/single-sign-on",
     "q": "Note: The single sign-on feature does not work alongside Pipedrive's two-factor authentication function."
    }
   ]
  },
  {
   "slug": "quickbooks",
   "name": "QuickBooks",
   "category": "Accounting Software",
   "checked": "2026-09-19",
   "scope": "QuickBooks Online (cloud). QuickBooks Desktop is a separate installed product and was not researched except where QBO sources mention it.",
   "profile_url": "https://helpcompare.com/tools/quickbooks/#security-offline-remote",
   "trust_center": "https://www.intuit.com/compliance/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://quickbooks.intuit.com/learn-support/en-us/other-questions/2024-soc/00/1500544",
     "q": "Intuit QuickBooks Online Ecosystem - SOC 2 Type II Report 2024"
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://quickbooks.intuit.com/learn-support/en-us/help-article/security-risk/verify-account-multi-factor-authentication/L2Xp0GNiT_US_en_US",
     "q": "Multi-factor authentication can't be turned off, but you'll have verification options based on the info we have on file—like your phone and email."
    },
    "audit_log": {
     "v": true,
     "plan": "QuickBooks Online Free",
     "src": "https://quickbooks.intuit.com/learn-support/en-us/help-article/audit-log/use-audit-log-quickbooks-online/L2WoVnW6I_US_en_US",
     "q": "QuickBooks Online tracks not only financial transactions but all account activities in the audit log. This includes user sign-ins, changes to QuickBooks settings"
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "128-bit SSL encryption",
     "src": "https://quickbooks.intuit.com/r/product-update/quickbooks-online-or-desktop-data-security/",
     "q": "QuickBooks Online also uses 128-bit SSL encryption, which can help protect your data from hackers and other intruders."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "none",
     "summary": "QuickBooks Online needs an internet connection in both the browser and the mobile apps; Intuit points offline users to the separate QuickBooks Desktop product.",
     "src": "https://quickbooks.intuit.com/learn-support/en-us/other-questions/working-off-line-with-qbo/00/1215330",
     "q": "QuickBooks Online still requires an internet connection to use for both the browser and the mobile versions."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://quickbooks.intuit.com/r/product-update/quickbooks-online-or-desktop-data-security/",
     "q": "QuickBooks Online mobile app works with iPhone, iPad, and Android phones and tablets."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "QuickBooks Payments supports in-person card payments through the QuickBooks GoPayment app with a Bluetooth QuickBooks Card Reader.",
     "src": "https://quickbooks.intuit.com/learn-support/en-us/help-article/process-credit-card-payments/process-payments-gopayment-app/L0XaYTJWZ_US_en_US",
     "q": "Accept cash, checks, and cards with a Bluetooth reader."
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "QuickBooks Online is browser-based: data can be reached from any computer with a supported browser and an internet connection, with high-speed recommended.",
     "src": "https://quickbooks.intuit.com/r/product-update/quickbooks-online-or-desktop-data-security/",
     "q": "You can access your financial data from anywhere, at any time, on any other computer right away with a supported browser and an internet connection (high-speed recommended)."
    },
    {
     "topic": "security",
     "text": "The audit log keeps user sign-ins and changes for two years, which lets owners review what remote staff or outside accountants changed.",
     "src": "https://quickbooks.intuit.com/learn-support/en-us/help-article/audit-log/use-audit-log-quickbooks-online/L2WoVnW6I_US_en_US",
     "q": "Events recorded in the audit log are available for two years."
    },
    {
     "topic": "offline",
     "text": "Not every QuickBooks Online feature is available in the mobile apps or on a mobile browser.",
     "src": "https://quickbooks.intuit.com/r/product-update/quickbooks-online-or-desktop-data-security/",
     "q": "Not all features are available on the mobile apps and mobile browser."
    }
   ]
  },
  {
   "slug": "rippling",
   "name": "Rippling",
   "category": "Payroll & HR Software",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/rippling/#security-offline-remote",
   "trust_center": "https://www.rippling.com/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.rippling.com/security",
     "q": "Rippling's SOC 2 Type 2 report covers the trust services categories of Security, Confidentiality, and Availability, and is audited annually."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.rippling.com/security",
     "q": "Rippling's ISO 27001 certification demonstrates our commitment to operating a mature security program."
    },
    "other_certs": {
     "v": [
      "SOC 1 Type II",
      "SOC 3",
      "CSA STAR Level 2",
      "ISO/IEC 27018",
      "ISO/IEC 42001"
     ],
     "src": "https://www.rippling.com/security",
     "q": "Rippling has achieved CSA STAR Level 2 certification"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": true,
     "src": "https://go.rippling.com/rs/345-FHM-674/images/ds-rippling-security.pdf",
     "q": "Download audit logs of Rippling app access."
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "AES at rest; 256-bit TLS in transit",
     "src": "https://go.rippling.com/rs/345-FHM-674/images/ds-rippling-security.pdf",
     "q": "All data is transferred using 256-bit TLS encryption — the state-of-the-art used by banks and governments. • Military-grade AES encryption protects your data at rest."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "Only the Rippling time Kiosk works offline: employees can clock in and out, switch jobs, take breaks and capture photos without a connection.",
     "src": "https://www.rippling.com/blog/march-2025-product-updates",
     "q": "With Rippling Kiosk’s offline mode, employees can clock in and out, switch jobs, take breaks, and capture photos—all without an internet connection."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.rippling.com/products/hr/time-and-attendance",
     "q": "employees can easily clock in and clock out through Rippling's mobile time clock app for iOS and Android."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "summary": "Rippling IT device management (Apple and Windows MDM): remote lock and wipe, custom security policies, automated device offboarding.",
     "src": "https://www.rippling.com/products/it/device-management",
     "q": "Instantly lock or wipe computers at any time, from anywhere in the world. Or, pre-schedule as a part of routine employee offboarding."
    },
    "office_hardware": {
     "v": "Rippling Time & Attendance runs a Kiosk for shared clock-in and out, and the Kiosk has an offline mode.",
     "src": "https://www.rippling.com/blog/march-2025-product-updates",
     "q": "Never miss a clock-in with Kiosk offline mode"
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Device offboarding follows HR offboarding, so admins can schedule when a remote employee's laptop is locked and wiped.",
     "src": "https://www.rippling.com/products/it/device-management",
     "q": "Because you’re automatically in sync with HR’s offboarding flow, you can schedule the exact time you want to lock and wipe a device."
    },
    {
     "topic": "security",
     "text": "Rippling IT includes identity and access management with custom SCIM and SAML integrations for provisioning and SSO to other apps.",
     "src": "https://www.rippling.com/products/it/streamline-user-authentication",
     "q": "600+ integrations—including custom SCIM and SAML."
    },
    {
     "topic": "offline",
     "text": "The Kiosk's offline mode lets hourly staff keep clocking in and out during internet outages.",
     "src": "https://www.rippling.com/blog/march-2025-product-updates",
     "q": "employees can clock in and out, switch jobs, take breaks, and capture photos—all without an internet connection."
    }
   ]
  },
  {
   "slug": "salesforce",
   "name": "Salesforce",
   "category": "CRM Platforms — Enterprise",
   "checked": "2026-09-19",
   "scope": "Sales Cloud on the core Salesforce Platform; help-article edition names (Essentials, Professional, Enterprise, Unlimited) differ from current bundle names. Several certifications explicitly exclude Salesforce Starter / ProSuite.",
   "profile_url": "https://helpcompare.com/tools/salesforce/#security-offline-remote",
   "trust_center": "https://compliance.salesforce.com/",
   "fields": {
    "soc2": {
     "v": "Report (type not stated)",
     "src": "https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/misc/salesforce-security-privacy-and-architecture.pdf",
     "q": "undergoes an independent evaluation in the form of SOC 1 (SSAE 18 / ISAE 3402), SOC 2 or SOC 3 audits"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/misc/salesforce-security-privacy-and-architecture.pdf",
     "q": "Salesforce has achieved ISO 27001/27017/27018 certification for its ISMS from an independent third party."
    },
    "other_certs": {
     "v": [
      "SOC 1",
      "SOC 3",
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "PCI DSS Level 1",
      "HITRUST CSF",
      "C5",
      "HDS",
      "ENS High",
      "ISMAP",
      "APEC PRP",
      "EU/UK BCR for Processors"
     ],
     "src": "https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/misc/salesforce-security-privacy-and-architecture.pdf",
     "q": "Salesforce has obtained an Attestation of Compliance (“AoC”) demonstrating Level 1 compliance with the applicable Payment Card Industry (PCI) Data Security Standard (DSS)"
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://www.salesforce.com/company/legal/business-associate-addendum-restrictions/",
     "q": "Customer and Salesforce must sign a BAA that includes the HIPAA Covered Service"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.salesforce.com/company/privacy/",
     "q": "Global Privacy Resources for Salesforce Products Data Processing Addendum"
    },
    "sso_saml": {
     "v": true,
     "plan": "All editions",
     "src": "https://help.salesforce.com/s/articleView?id=xcloud.sso_saml.htm&language=en_US&type=5",
     "q": "Federated Authentication is available in: All Editions"
    },
    "scim": {
     "v": true,
     "plan": "All editions",
     "src": "https://help.salesforce.com/s/articleView?id=sf.identity_scim_overview.htm&language=en_US&type=5",
     "q": "You can provision and manage your Salesforce user identities across systems with the open standard System for Cross-Domain Identity Management (SCIM)."
    },
    "mfa": {
     "v": true,
     "enforce": "All editions",
     "src": "https://help.salesforce.com/s/articleView?id=xcloud.security_mfa_org_wide_setting.htm&language=en_US&type=5",
     "q": "Turn on multi-factor authentication (MFA) for everyone in your org with a single setting."
    },
    "audit_log": {
     "v": true,
     "plan": "Essentials",
     "src": "https://help.salesforce.com/s/articleView?id=sf.admin_monitorsetup.htm&language=en_US&type=5",
     "q": "Available in: Contact Manager, Essentials, Group, Professional, Enterprise, Performance, Unlimited, Developer, and Database.com Editions"
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "UK",
      "CA",
      "AU",
      "JP",
      "IN",
      "BR",
      "SG",
      "KR",
      "ID",
      "IL",
      "CH",
      "ZA",
      "AE"
     ],
     "src": "https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/misc/salesforce-infrastructure-and-subprocessors.pdf",
     "q": "hosted on either AWS or Salesforce infrastructure in one of the following regions, which is chosen by the Customer or an Account Executive when the org is first created."
    },
    "encryption": {
     "v": "TLS in transit (2048-bit RSA certificates); AES-256 on replication links between data centers",
     "src": "https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/misc/salesforce-security-privacy-and-architecture.pdf",
     "q": "all data, including Customer Data, is transmitted between data centers for replication purposes across encrypted links utilizing AES-256 encryption."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "full",
     "summary": "The Salesforce mobile app (iOS/Android) caches recent records for offline viewing and, when admins enable Offline Edit, lets users create, edit and delete records offline; pending changes sync automatically and conflicts are flagged on reconnect.",
     "src": "https://help.salesforce.com/s/articleView?id=sf.salesforce_app_work_offline.htm&language=en_US&type=5",
     "q": "The Salesforce mobile app automatically syncs those pending changes to Salesforce and warns the user if there are conflicts to be resolved."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://help.salesforce.com/s/articleView?id=xcloud.salesforce_app_enable_offline_access.htm&language=en_US&type=5",
     "q": "Offline access is available in Salesforce for Android and iOS only."
    },
    "limits": {
     "v": "Mobile apps only (not the browser); if users don't customize their cache, it holds up to 30 recent records for their five most recent objects",
     "src": "https://help.salesforce.com/s/articleView?id=xcloud.salesforce_app_offline.htm&language=en_US&type=5",
     "q": "Salesforce populates the user’s cache with up to 30 recently accessed records for their five most recently accessed objects."
    },
    "ip_allowlist": {
     "v": true,
     "plan": "All editions (per-profile ranges on Enterprise and up)",
     "src": "https://help.salesforce.com/s/articleView?id=sf.users_profiles_epui_login_ip_ranges.htm&language=en_US&type=5",
     "q": "When you define IP address restrictions for a profile, a login from any other IP address is denied."
    },
    "device_controls": {
     "v": true,
     "plan": "Essentials",
     "summary": "Admin-set session timeout for inactive users; option to lock sessions to the originating IP address (Enterprise and up).",
     "src": "https://help.salesforce.com/s/articleView?language=en_US&id=xcloud.admin_sessions.htm&type=5",
     "q": "The Lock sessions to the IP address from which they originated setting is available in: Enterprise, Performance, Unlimited, Developer, and Database.com Editions"
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "A Salesforce org's hosting region is fixed when the org is first created, chosen by the customer or an account executive from Hyperforce regions including the US, EU, UK, Canada, Australia, Japan and India.",
     "src": "https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/misc/salesforce-infrastructure-and-subprocessors.pdf",
     "q": "which is chosen by the Customer or an Account Executive when the org is first created."
    },
    {
     "topic": "office",
     "text": "On Professional Edition without the Edit Profiles & Page Layouts add-on, office/VPN IP ranges can only be set org-wide rather than per profile.",
     "src": "https://help.salesforce.com/s/articleView?id=sf.users_profiles_epui_login_ip_ranges.htm&language=en_US&type=5",
     "q": "Without the \"Edit Profiles & Page Layouts\" feature, you can define trusted IP ranges only at the org level on the Network Access Setup page."
    },
    {
     "topic": "security",
     "text": "Salesforce is enforcing MFA for direct username/password logins from summer 2026, after which the org-wide setting cannot be disabled; SSO logins follow the identity provider's MFA.",
     "src": "https://help.salesforce.com/s/articleView?id=xcloud.security_mfa_org_wide_setting.htm&language=en_US&type=5",
     "q": "Salesforce enforces MFA requirements in the summer of 2026."
    },
    {
     "topic": "offline",
     "text": "Field reps who go offline with an empty cache have no Salesforce data, so the mobile cache should be refreshed after each login.",
     "src": "https://help.salesforce.com/s/articleView?id=xcloud.salesforce_app_offline.htm&language=en_US&type=5",
     "q": "If the user’s device goes offline with an empty cache, no Salesforce data is available."
    }
   ]
  },
  {
   "slug": "salesloft",
   "name": "Salesloft",
   "category": "Sales Engagement Platforms",
   "checked": "2026-09-19",
   "scope": "Salesloft sales engagement platform (Salesloft+Drift, now alongside Clari); Drift-specific features excluded. Help-center plan ('Package Availability') details are not shown as text.",
   "profile_url": "https://helpcompare.com/tools/salesloft/#security-offline-remote",
   "trust_center": "https://trust.salesloft.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.salesloft.com/security-compliance",
     "q": "The Salesloft and Drift platform services undergo SOC 2 Type 2 examinations"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.salesloft.com/security-compliance",
     "q": "Our entire information security program is aligned with the ISO 27001 framework, which is audited and re-certified annually."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27701",
      "CSA (badge; STAR level not stated)"
     ],
     "src": "https://www.salesloft.com/security-compliance",
     "q": "Salesloft is certified compliant with the ISO 27701 standard."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.salesloft.com/security-compliance",
     "q": "Salesloft’s Master Subscription Agreement (MSA) incorporates our Data Processing Addendum (DPA), which includes Standard Contractual Clauses (SCCs)"
    },
    "sso_saml": {
     "v": true,
     "src": "https://help.salesloft.com/s/article/Manage-Single-Sign-On?language=en_US",
     "q": "Salesloft currently has single sign-on via SAML setup capabilities with the following IdPs:"
    },
    "scim": {
     "v": true,
     "src": "https://help.salesloft.com/s/article/Auto-User-Provisioning-Integration-with-Okta?language=en_US",
     "q": "Auto-User Provisioning Integration, aka the SCIM standard, within Okta allows for a User Provisioning Integration."
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US",
      "EU"
     ],
     "src": "https://www.salesloft.com/security-compliance",
     "q": "running on Amazon Web Service (AWS) and Google Cloud Platform (GCP) technology, in the US and the EU."
    },
    "encryption": {
     "v": "AES-256-GCM at rest; HTTPS/TLS 1.2+ in transit",
     "src": "https://www.salesloft.com/security-compliance",
     "q": "all connections, including the UI and APIs, being through standard secure web protocols (HTTPS/TLS 1.2+), and the platforms employ strong symmetric (AES-256-GCM) encryption for all data at rest"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://play.google.com/store/apps/details?id=com.salesloftmobile&hl=en_US",
     "q": "Salesloft Mobile brings the full power of Salesloft to your mobile device"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Salesloft's Okta SCIM provisioning creates, updates and deactivates users but does not assign roles or groups.",
     "src": "https://help.salesloft.com/s/article/Auto-User-Provisioning-Integration-with-Okta?language=en_US",
     "q": "Things to Note: Auto-provisioning does not include roles/groups."
    },
    {
     "topic": "security",
     "text": "The core Salesloft platform is hosted in the US and the EU, but the Drift and Clari platforms are hosted in the US only.",
     "src": "https://www.salesloft.com/security-compliance",
     "q": "The Drift platform is hosted on AWS in the US."
    },
    {
     "topic": "remote",
     "text": "Teams signing in with Google Workspace can turn on SSO via Google OpenID Connect without configuring SAML.",
     "src": "https://help.salesloft.com/s/article/Manage-Single-Sign-On?language=en_US",
     "q": "This feature can be enabled for any team that signs in to Salesloft using Gmail or G Suite email addresses."
    },
    {
     "topic": "security",
     "text": "A 2025 intrusion affected Salesloft's Drift product (March to September 2025); Mandiant's investigation concluded on September 30, 2025 and verified remediation.",
     "src": "https://trust.salesloft.com/",
     "q": "Mandiant has not identified ongoing compromise of the Drift product, and has verified the remediation activities taken during the investigation."
    }
   ]
  },
  {
   "slug": "semrush",
   "name": "Semrush",
   "category": "SEO Software",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/semrush/#security-offline-remote",
   "trust_center": "https://www.semrush.com/company/security/",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "PCI DSS Level 1"
     ],
     "src": "https://www.semrush.com/company/security/",
     "q": "Once a year, we confirm our compliance by passing an independent QSA audit. As a result, we have achieved a PCI DSS Level 1 certificate."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.semrush.com/company/security/",
     "q": "Enter into data processing addenda with our customers and vendors to reflect the respective security obligations and privacy requirements of the parties."
    },
    "sso_saml": {
     "v": true,
     "plan": "Guru",
     "src": "https://www.semrush.com/kb/1609-saml-sso",
     "q": "SSO is available to Guru and Business users."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://www.semrush.com/company/security/",
     "q": "Two-factor authentication: Our product supports two-factor authentication. This can be easily enabled to make accounts more secure."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://www.semrush.com/company/security/",
     "q": "Semrush stores its service data at physically secure data centers in the United States."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2+ in transit",
     "src": "https://www.semrush.com/company/security/",
     "q": "Data centers use AES-256 encryption for secure data storage"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.semrush.com/news/271383-position-tracking-on-the-go/",
     "q": "The app is available for both iOS and Android devices"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Semrush's mobile app is a Position Tracking companion (projects, visibility, traffic and keyword positions), not the full toolkit.",
     "src": "https://www.semrush.com/news/271383-position-tracking-on-the-go/",
     "q": "This is your mobile version of the Position Tracking tool, and all of the main features are still available."
    },
    {
     "topic": "security",
     "text": "SAML SSO is set up by request, and password login stays available until the integration is tested and you ask for it to be disabled.",
     "src": "https://www.semrush.com/kb/1609-saml-sso",
     "q": "To enable SSO, contact our team via this form."
    },
    {
     "topic": "security",
     "text": "Semrush hosts service data in the US on Amazon Web Services, Google Cloud Platform and Digital Reality data centers.",
     "src": "https://www.semrush.com/company/security/",
     "q": "Semrush stores its service data at physically secure data centers in the United States. We use Amazon Web Service, Google Cloud Platform, and Digital Reality DC."
    }
   ]
  },
  {
   "slug": "shopify",
   "name": "Shopify",
   "category": "E-commerce Platforms",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/shopify/#security-offline-remote",
   "trust_center": "https://www.shopify.com/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.shopify.com/security",
     "q": "Shopify has been issued SOC 2 Type II and SOC 3 reports for the service we provide to our customers."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "PCI DSS Level 1",
      "SOC 3"
     ],
     "src": "https://www.shopify.com/security",
     "q": "Shopify is certified Level 1 PCI DSS compliant."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.shopify.com/legal/dpa",
     "q": "supplements and is incorporated by reference into the Shopify Terms of Service."
    },
    "sso_saml": {
     "v": true,
     "plan": "Shopify Plus",
     "src": "https://help.shopify.com/en/manual/organization-settings/security/saml",
     "q": "SAML authentication is available only for organizations on the Shopify Plus plan."
    },
    "scim": {
     "v": true,
     "plan": "Shopify Plus",
     "src": "https://help.shopify.com/en/manual/your-account/users/security/advanced-security-features/scim",
     "q": "Generating SCIM tokens for users is available only to organizations on the Shopify Plus plan."
    },
    "mfa": {
     "v": true,
     "enforce": "Shopify Plus",
     "src": "https://help.shopify.com/en/manual/your-account/users/security/advanced-security-features",
     "q": "Require all users to log in using two-step authentication"
    },
    "audit_log": {
     "v": true,
     "plan": "Shopify Plus",
     "src": "https://help.shopify.com/en/manual/your-account/users/security/advanced-security-features",
     "q": "Review your user activity log for the organization"
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "The Shopify POS app can complete checkouts offline with cash, custom payment methods and (once activated) card payments on supported readers; customers, gift cards, returns and inventory/order sync need internet, and orders sync automatically on reconnect.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/selling-offline/offline-features",
     "q": "You can still accept payments by cash and manual payments set up as custom payment methods."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/pos-app-requirements",
     "q": "Shopify POS is a point of sale system available on iOS or Android that you can use to sell your products in person."
    },
    "limits": {
     "v": "Offline card payments need POS app 9.14.0+, a supported Shopify reader, a staff permission, and are capped by per-device daily and per-transaction limits.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/selling-offline/offline-payments",
     "q": "Your POS app is updated to version 9.14.0 or later"
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "Shopify POS runs on iOS/Android and supports Shopify card readers (POS Go, POS Terminal, Tap & Chip and others) plus retail hardware such as barcode scanners and cash drawers.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/pos-app-requirements",
     "q": "Connect Shopify POS to additional retail hardware, such as a barcode scanner or a cash drawer."
    }
   },
   "facts": [
    {
     "topic": "offline",
     "text": "Offline card payments are not routed to the processor until reconnection, so declines only surface later; Shopify advises reconnecting ideally within 24 hours.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/selling-offline/offline-payments",
     "q": "To reduce the risk of declined payments, reconnect to the internet as soon as possible, ideally within 24 hours"
    },
    {
     "topic": "office",
     "text": "With the POS Terminal reader, offline payments still require the store's local Wi-Fi network to be working.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/selling-offline/offline-payments",
     "q": "Your local Wi-Fi network must still be working"
    },
    {
     "topic": "offline",
     "text": "While offline, Shopify POS cannot sync orders and inventory with the Shopify admin; syncing resumes automatically on reconnect.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/selling-offline/offline-features",
     "q": "Shopify POS can't sync orders and inventory with your Shopify admin when you're offline."
    },
    {
     "topic": "security",
     "text": "SAML SSO, SCIM provisioning, mandatory two-step authentication and the organization user activity log are all Shopify Plus-only.",
     "src": "https://help.shopify.com/en/manual/your-account/users/security/advanced-security-features",
     "q": "Advanced security features are available only for organizations on the Shopify Plus plan."
    }
   ]
  },
  {
   "slug": "shopify-pos",
   "name": "Shopify POS",
   "category": "POS Systems",
   "checked": "2026-09-19",
   "scope": "Shopify POS app and Shopify card readers (US), on a Shopify plan; security controls are account-wide Shopify features.",
   "profile_url": "https://helpcompare.com/tools/shopify-pos/#security-offline-remote",
   "trust_center": "https://www.shopify.com/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.shopify.com/security",
     "q": "Shopify has been issued SOC 2 Type II and SOC 3 reports for the service we provide to our customers."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "PCI DSS Level 1",
      "SOC 3"
     ],
     "src": "https://www.shopify.com/security",
     "q": "Shopify is certified Level 1 PCI DSS compliant."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.shopify.com/legal/dpa",
     "q": "supplements and is incorporated by reference into the Shopify Terms of Service."
    },
    "sso_saml": {
     "v": true,
     "plan": "Shopify Plus",
     "src": "https://help.shopify.com/en/manual/your-account/users/security/advanced-security-features",
     "q": "Set up Security Assertion Markup Language (SAML) authentication for your users."
    },
    "scim": {
     "v": true,
     "plan": "Shopify Plus",
     "src": "https://help.shopify.com/en/manual/your-account/users/security/advanced-security-features",
     "q": "Generate an API token to add or remove users through your identity provider with System for Cross-domain Identity Management (SCIM)."
    },
    "mfa": {
     "v": true,
     "enforce": "Shopify Plus",
     "src": "https://help.shopify.com/en/manual/your-account/users/security/advanced-security-features",
     "q": "Require all users to log in using two-step authentication."
    },
    "audit_log": {
     "v": true,
     "plan": "Shopify Plus",
     "src": "https://help.shopify.com/en/manual/your-account/users/security/advanced-security-features",
     "q": "Review your user activity log for the organization."
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "The Shopify POS app can take cash and custom payments offline and, once activated, card payments on supported Shopify readers within merchant-set limits; orders and inventory sync with the Shopify admin after reconnecting.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/selling-offline/offline-payments",
     "q": "To reduce the risk of declined payments, reconnect to the internet as soon as possible, ideally within 24 hours."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/pos-app-requirements",
     "q": "is a point of sale system available on iOS or Android that you can use to sell your products in person."
    },
    "limits": {
     "v": "Offline card payments need POS app 9.14.0+, a compatible Shopify reader, and are capped by a device daily limit and a per-transaction limit that apply to all locations; POS Terminal needs the local Wi-Fi network working.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/selling-offline/offline-payments",
     "q": "Your POS app is updated to version 9.14.0 or later."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "Shopify POS runs on your iOS/Android phone or tablet with Shopify card readers (Tap & Chip Card Reader $49, POS Terminal $349, Verifone Victa Mobile $399) plus retail hardware such as barcode scanners, receipt printers and cash drawers.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/pos-app-requirements",
     "q": "Connect Shopify POS to additional retail hardware, such as a barcode scanner or a cash drawer, to create a full retail store experience."
    }
   },
   "facts": [
    {
     "topic": "office",
     "text": "With the POS Terminal reader, offline payments still require the store's local Wi-Fi network to be working.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/selling-offline/offline-payments",
     "q": "Your local Wi-Fi network must still be working."
    },
    {
     "topic": "offline",
     "text": "Offline payment limits (device daily and per-transaction) are set once and apply to every store location.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/shopify-pos/selling-offline/offline-payments",
     "q": "If you have multiple store locations, then offline payment settings and transaction limits apply to all locations."
    },
    {
     "topic": "office",
     "text": "Third-party card terminals can be used alongside Shopify POS only as a custom payment method for tracking; Shopify does not process those funds.",
     "src": "https://help.shopify.com/en/manual/sell-in-person/getting-started/setup-payment-method/enable-payments",
     "q": "When a customer uses a custom payment method, the funds aren't processed by Shopify."
    },
    {
     "topic": "security",
     "text": "SAML SSO, SCIM provisioning, mandatory two-step authentication and the organization user activity log are Shopify Plus-only.",
     "src": "https://help.shopify.com/en/manual/your-account/users/security/advanced-security-features",
     "q": "Advanced security features are available only for organizations on the Shopify Plus plan."
    }
   ]
  },
  {
   "slug": "slack",
   "name": "Slack",
   "category": "Team Communication",
   "checked": "2026-09-19",
   "scope": "Commercial Slack plans (Free, Pro, Business+, Enterprise). GovSlack is a separate FedRAMP High offering.",
   "profile_url": "https://helpcompare.com/tools/slack/#security-offline-remote",
   "trust_center": "https://slack.com/trust/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://slack.com/trust/compliance",
     "q": "SOC 2 (Type Ⅱ) Trust Services Principles"
    },
    "iso27001": {
     "v": true,
     "src": "https://slack.com/trust/compliance",
     "q": "ISO/IEC 27001 Information Security Management System (ISMS) Download certificate"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "ISO/IEC 42001",
      "SOC 3",
      "CSA STAR (registry listing)",
      "FedRAMP Moderate",
      "TISAX",
      "IRAP",
      "ISMAP",
      "C5",
      "ENS High",
      "Korea CSP Safety Assessment",
      "FINRA 17a-4 configurable"
     ],
     "src": "https://slack.com/trust/compliance",
     "q": "Slack is FedRAMP Moderate authorized to meet the compliance needs of organizations in the public sector with an Enterprise or Enterprise+ Slack plan"
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Enterprise",
     "src": "https://slack.com/help/articles/360020685594-Slack-and-HIPAA",
     "q": "You must be using a Slack Enterprise plan. You must execute a Business Associate Agreement."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://slack.com/trust/compliance",
     "q": "Slack offers Data Processing Addenda that supplement the Customer Terms of Service or any MSA."
    },
    "sso_saml": {
     "v": true,
     "plan": "Business+",
     "src": "https://slack.com/help/articles/203772216-Set-up-SAML-single-sign-on-for-Slack",
     "q": "Available on the Business+ and Enterprise plans"
    },
    "scim": {
     "v": true,
     "plan": "Business+",
     "src": "https://slack.com/help/articles/212572638-Manage-members-with-SCIM-provisioning",
     "q": "Slack supports member provisioning with the System for Cross-domain Identity Management (SCIM) standard."
    },
    "mfa": {
     "v": true,
     "enforce": "Free (available on all plans)",
     "src": "https://slack.com/help/articles/212221668-Mandatory-workspace-two-factor-authentication-",
     "q": "For an added layer of security, you can require your members and guests to use two-factor authentication (2FA) when they sign in to Slack."
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://slack.com/help/articles/360000394286-Audit-logs-in-Slack",
     "q": "Available on Enterprise plans"
    },
    "data_residency": {
     "v": [
      "US",
      "DE",
      "FR",
      "SE",
      "CH",
      "JP",
      "IN",
      "SG",
      "KR",
      "AU",
      "UK",
      "CA",
      "BR"
     ],
     "plan": "Business+",
     "src": "https://slack.com/help/articles/360035633934-Data-residency-for-Slack",
     "q": "Data residency for Slack allows global teams to choose the region where certain types of data at rest are stored."
    },
    "encryption": {
     "v": "Encrypted at rest and in transit by default; optional customer-managed keys via Slack EKM",
     "src": "https://slack.com/trust/security",
     "q": "We protect your data with tools like Slack Enterprise Key Management (Slack EKM), audit logs and native data loss prevention (DLP)"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://slack.com/downloads/mac",
     "q": "Slack works for Windows and Linux, too."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://slack.com/downloads/mac",
     "q": "Take teamwork to go with the Slack apps for Android and iOS"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "plan": "Free",
     "summary": "Block desktop/mobile file downloads (desktop downloads can be limited to allowed IP ranges) and mobile message copying on all plans; session duration controls; EMM-managed mobile device requirement on Enterprise Grid/Enterprise+.",
     "src": "https://slack.com/help/articles/360016181794-Block-file-downloads-and-message-copying-in-Slack",
     "q": "can choose to block file downloads on desktop and mobile devices and block message copying on mobile devices only."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "office",
     "text": "Slack huddles need UDP/3478 (or legacy UDP/22466) and TCP/443 open on office networks.",
     "src": "https://slack.com/help/articles/36284146785427-Guide-to-network-and-system-configuration-for-Slack-huddles",
     "q": "Allow traffic to and from UDP/3478 or UDP/22466, and TCP/443"
    },
    {
     "topic": "security",
     "text": "Admins can block desktop file downloads except from specified IP ranges, e.g. office or VPN addresses.",
     "src": "https://slack.com/help/articles/360016181794-Block-file-downloads-and-message-copying-in-Slack",
     "q": "You can block file downloads and previews from unauthorized locations by only allowing downloads from specific IP address ranges."
    },
    {
     "topic": "remote",
     "text": "Guest accounts for contractors or clients require a paid plan; Single-Channel Guests are free, up to 5 per paid member.",
     "src": "https://slack.com/help/articles/202518103-Understand-guest-roles-in-Slack",
     "q": "For every paid active member in your workspace, you can add up to 5 guests."
    },
    {
     "topic": "office",
     "text": "Slack needs a persistent WebSocket connection over port 443; proxies and firewalls must allow it.",
     "src": "https://slack.com/help/articles/360001603387-Manage-Slack-connection-issues",
     "q": "Slack must have a persistent connection between our messaging server and members’ apps or browsers. To do so, Slack uses WebSockets over port 443."
    }
   ]
  },
  {
   "slug": "smartlead",
   "name": "Smartlead",
   "category": "Cold Email & Sales Engagement",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/smartlead/#security-offline-remote",
   "trust_center": null,
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.smartlead.ai/dpa",
     "q": "This Data Processing Addendum (“DPA”) reflects the requirements of the European Union and United Kingdom General Data Protection Regulations (‘GDPR’)."
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "AU"
     ],
     "src": "https://www.smartlead.ai/dpa",
     "q": "securely storing data in a certified data repository, specifically one located in the Sydney Region of Amazon Web Services;"
    },
    "encryption": {
     "v": "AES-256 at rest",
     "src": "https://www.smartlead.ai/dpa",
     "q": "safeguarding data while not in operation by using the Advanced Encryption Standard (AES) along with a 256-bit encryption key;"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://helpcenter.smartlead.ai/en/articles/198-smartlead-mobile-app-how-to-manage-leads-effectively",
     "q": "Download the app today: Google Play Store: Link iOS App Store: Link"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Smartlead's DPA says data is stored in the AWS Sydney region, though other user data may be processed in several other countries.",
     "src": "https://www.smartlead.ai/dpa",
     "q": "All other User Data may be transferred and processed in Australia; Singapore; India; Japan; United States; Canada; Germany; Ireland; and Sweden"
    },
    {
     "topic": "remote",
     "text": "Once a campaign exists, it can be fully managed (inbox, leads, analytics) from the mobile app; campaigns are created in the web app.",
     "src": "https://helpcenter.smartlead.ai/en/articles/198-smartlead-mobile-app-how-to-manage-leads-effectively",
     "q": "Once a campaign exists, you can fully manage it (inbox, leads, analytics) from your phone."
    }
   ]
  },
  {
   "slug": "sortly",
   "name": "Sortly",
   "category": "Inventory Management",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/sortly/#security-offline-remote",
   "trust_center": "https://trust.sortly.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://help.sortly.com/hc/en-us/articles/40924079209371-Backing-Up-Your-Data",
     "q": "Sortly is SOC 2 Type II Compliant"
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://trust.sortly.com/",
     "q": "We offer optional SSO with our Enterprise Plan which allows the client to configure an identity provider using OAuth2 or SAML v2 authentication standards."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "src": "https://trust.sortly.com/",
     "q": "Our internal authentication method does not, though we do optionally offer SSO for customers on our Enterprise Plan, and external identity providers can be set up to use two-factor authentication."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://trust.sortly.com/",
     "q": "We host in the us-west-2 (Oregon) region"
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "In the iOS and Android apps you disable sync to work offline and can update inventory levels on the device; changes push to the server when you reconnect, while the web app has no offline mode.",
     "src": "https://help.sortly.com/hc/en-us/articles/360060638832-Can-I-use-Sortly-in-offline-mode",
     "q": "Offline mode only updates inventory levels on your device. Once you reconnect to WiFi, LTE, or 5G, your changes push to the server and reflect on every other device on your account."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://help.sortly.com/hc/en-us/articles/360060638832-Can-I-use-Sortly-in-offline-mode",
     "q": "Offline mode is available on our mobile apps only, for both Android and iOS."
    },
    "limits": {
     "v": "Mobile apps only (not web); listed on all plans including Free.",
     "plan": "Free",
     "src": "https://www.sortly.com/pricing/",
     "q": "Offline Mobile Access lets you track and update inventory even when you’re offline or out of range."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "Phones scan barcodes/QR codes in the app on all plans; third-party barcode scanner support and barcode label creation start on Ultra.",
     "src": "https://www.sortly.com/pricing/",
     "q": "3rd-party Scanner Support"
    }
   },
   "facts": [
    {
     "topic": "offline",
     "text": "Before going offline, run a full sync: with sync disabled the app shows inventory only as it was at that moment.",
     "src": "https://help.sortly.com/hc/en-us/articles/360060638832-Can-I-use-Sortly-in-offline-mode",
     "q": "When you disable sync, the app only shows the inventory as it was at that moment. Force a full sync first so you are working from the most current data."
    },
    {
     "topic": "security",
     "text": "Sortly's own login has no two-factor authentication; 2FA is only possible through an external identity provider via SSO on the Enterprise plan.",
     "src": "https://trust.sortly.com/",
     "q": "Our internal authentication method does not, though we do optionally offer SSO for customers on our Enterprise Plan"
    },
    {
     "topic": "remote",
     "text": "Sortly data and backups are hosted on AWS in the us-west-2 (Oregon) region.",
     "src": "https://trust.sortly.com/",
     "q": "We host in the us-west-2 (Oregon) region"
    },
    {
     "topic": "security",
     "text": "Activity history (who changed what, and when) is kept for 1 month on Free, 1 year on Advanced, 3 years on Ultra and unlimited on Premium/Enterprise.",
     "src": "https://www.sortly.com/pricing/",
     "q": "Activity History lets you monitor who from your team did what, and when in Sortly."
    }
   ]
  },
  {
   "slug": "sprout-social",
   "name": "Sprout Social",
   "category": "Social Media Management",
   "checked": "2026-09-19",
   "scope": "Sprout Social application (core platform). Employee Advocacy and Influencer Marketing have separate security pages.",
   "profile_url": "https://helpcompare.com/tools/sprout-social/#security-offline-remote",
   "trust_center": "https://sproutsocial.com/trust-center/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://sproutsocial.com/trust-center/",
     "q": "Sprout Social regularly completes a SOC 2 Type 2 audit by a qualified, third-party auditor"
    },
    "iso27001": {
     "v": true,
     "src": "https://sproutsocial.com/trust-center/",
     "q": "Sprout Social maintains an Information Security Management System (ISMS) that is independently audited and certified to the ISO/IEC 27001:2013 standard."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27701",
      "CSA STAR Level 1",
      "PCI DSS"
     ],
     "src": "https://sproutsocial.com/trust-center/",
     "q": "Sprout Social has completed a Level 1 assessment through the CSA’s Security Trust Assurance and Risk (STAR) registry."
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Guardian (add-on) for PHI collection via Secure Forms",
     "src": "https://sproutsocial.com/legal/baa-healthcare-customers/",
     "q": "we began offering a tailored BAA scoped to inadvertent uploading of PHI by a social media user."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://sproutsocial.com/trust-center/",
     "q": "Terms of Service Privacy Policy Data Processing Addendum"
    },
    "sso_saml": {
     "v": true,
     "src": "https://support.sproutsocial.com/hc/en-us/articles/360025655491-Single-Sign-on-SSO",
     "q": "Sprout Social offers SAML 2.0 Single Sign-on (SSO) support to our customers across web and mobile."
    },
    "scim": {
     "v": true,
     "src": "https://support.sproutsocial.com/hc/en-us/articles/48587986567565-September-2026",
     "q": "System for Cross-domain Identity Management (SCIM) for Okta and Microsoft Entra ID (formerly Azure AD) is now Generally Available!"
    },
    "mfa": {
     "v": true,
     "enforce": "All plans (email two-step verification is enforced by default)",
     "src": "https://sproutsocial.com/security/sprout-social-application/",
     "q": "By default, users log in to the Sprout application using a designated username and password, with two-step verification via email enforced."
    },
    "audit_log": {
     "v": true,
     "src": "https://sproutsocial.com/security/sprout-social-application/",
     "q": "The Sprout application includes customer-facing audit trail logs that provide information on user activity within an account."
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://sproutsocial.com/security/sprout-social-application/",
     "q": "all components of the Sprout Social application - including the infrastructure, application software, and customer data - are hosted across multiple Availability Zones within the United States."
    },
    "encryption": {
     "v": "AES-256 or greater at rest (including backups); TLS 1.2+ in transit",
     "src": "https://sproutsocial.com/security/sprout-social-application/",
     "q": "All data, including backups, is stored encrypted at rest with AES-256 or greater."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://sproutsocial.com/pricing/",
     "q": "Mobile app for iOS and Android Included Included Included Included"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Advanced",
     "src": "https://sproutsocial.com/pricing/",
     "q": "IP whitelisting Not included Not included Not included Included"
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Live phone and live chat support run 24/5 on every plan, which covers teams working across time zones on weekdays.",
     "src": "https://sproutsocial.com/pricing/",
     "q": "Support hours 24/5 24/5 24/5 24/5 Live phone support 24/5"
    },
    {
     "topic": "security",
     "text": "Admins can restrict app and API access to specific IP ranges, such as an office or VPN.",
     "src": "https://sproutsocial.com/security/sprout-social-application/",
     "q": "Sprout Social may be configured to restrict application and API access from specific IP ranges."
    },
    {
     "topic": "remote",
     "text": "In a crisis, one button pauses all scheduled and queued messages, and it works from both the web and mobile apps.",
     "src": "https://sproutsocial.com/security/sprout-social-application/",
     "q": "This is accessible from our web and mobile applications."
    },
    {
     "topic": "security",
     "text": "All data is hosted in the US (AWS us-east-1 primary, us-west-2 secondary, GCP us-central1 for disaster recovery); no other region is offered.",
     "src": "https://sproutsocial.com/security/sprout-social-application/",
     "q": "Primary - AWS us-east-1 (N. Virginia) Secondary - AWS us-west-2 (Oregon) Disaster Recovery/Backup - GCP us-central1 (Iowa)"
    }
   ]
  },
  {
   "slug": "square-pos",
   "name": "Square",
   "category": "POS Systems",
   "checked": "2026-09-19",
   "scope": "Square Point of Sale (US) and Square hardware.",
   "profile_url": "https://helpcompare.com/tools/square-pos/#security-offline-remote",
   "trust_center": "https://squareup.com/us/en/payments/secure",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": true,
     "src": "https://squareup.com/us/en/payments/secure",
     "q": "We’ve achieved the renowned ISO 27001 certification."
    },
    "other_certs": {
     "v": [
      "PCI DSS Level 1"
     ],
     "src": "https://squareup.com/us/en/payments/secure",
     "q": "ISO 27001 certified PCI Data Security Standard, Level 1"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://squareup.com/us/en/payments/secure",
     "q": "Set up 2-Step Verification to add a layer of security to your account."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "Card-present payments encrypted end to end; no unencrypted payment data touches the device",
     "src": "https://squareup.com/us/en/payments/secure",
     "q": "All card-present payments are encrypted from end to end."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "Square POS apps on supported Square hardware can take cash and card payments offline; payments are stored in the app and process automatically on reconnection (ideally within 24 hours, expiring after 72 hours), while online orders, gift cards, Tap to Pay and manual card entry are unavailable offline.",
     "src": "https://squareup.com/help/us/en/article/7777-process-card-payments-with-offline-mode",
     "q": "If your device goes offline, you can allow offline payments to accept cash and card payments from most major card brands."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://play.google.com/store/apps/details?id=com.squareup&hl=en_US",
     "q": "Square Point of Sale: Payment - Apps on Google Play"
    },
    "limits": {
     "v": "Upload within 24 hours, no later than 72 hours; not supported on Square Reader 1st gen v1/v2, Kiosk, Tap to Pay, manually entered cards, gift cards, Afterpay, Cash App Pay, Invoices app or services mode.",
     "src": "https://squareup.com/help/us/en/article/7777-process-card-payments-with-offline-mode",
     "q": "Offline payments will process automatically when you reconnect your device to the internet within 24 hours (no later than 72 hours)."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "summary": "Remote device management: device profiles and codes, printer profiles, monitoring from off-site.",
     "src": "https://squareup.com/us/en/pricing",
     "q": "Set up, monitor, and manage devices, even when you’re off-site. View device details, set device profiles or codes, and create printer profiles."
    },
    "office_hardware": {
     "v": "Square sells its own POS hardware: Reader for contactless and chip ($59), Terminal ($299), Handheld ($399), Stand ($149), Kiosk ($149) and Register ($899).",
     "src": "https://squareup.com/us/en/hardware",
     "q": "Square Terminal The all-in-one POS with a receipt printer $299 or $27/mo over 12 months"
    }
   },
   "facts": [
    {
     "topic": "offline",
     "text": "Offline payments not uploaded within 72 hours expire; Square recommends reconnecting within 24 hours.",
     "src": "https://squareup.com/help/us/en/article/7777-process-card-payments-with-offline-mode",
     "q": "Offline payments will process automatically when you reconnect your device to the internet within 24 hours (no later than 72 hours)."
    },
    {
     "topic": "office",
     "text": "Offline payments will be enabled on all devices automatically unless the seller opts out (change rolled out March–April 2026).",
     "src": "https://squareup.com/help/us/en/article/7777-process-card-payments-with-offline-mode",
     "q": "Offline payments will be automatically allowed on all your devices unless you opt out."
    },
    {
     "topic": "remote",
     "text": "Phone support is 6am–6pm PT on weekdays for Square Plus (first 90 days only on Square Free); only Square Premium includes 24/7 phone support.",
     "src": "https://squareup.com/us/en/pricing",
     "q": "6am–6pm PT M–F for the first 90 days 6am–6pm PT M–F 24/7"
    },
    {
     "topic": "security",
     "text": "Square is the merchant of record and maintains PCI certification, so sellers do not validate PCI compliance individually.",
     "src": "https://squareup.com/us/en/payments/secure",
     "q": "As the merchant of record, we maintain PCI certification so you don’t have to individually validate your compliance."
    }
   ]
  },
  {
   "slug": "squarespace",
   "name": "Squarespace",
   "category": "Website Builders",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/squarespace/#security-offline-remote",
   "trust_center": "https://www.squarespace.com/security",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.squarespace.com/dpa",
     "q": "This Squarespace Data Processing Addendum (this \"DPA\") forms part of, and is subject to the provisions of, the Squarespace Terms of Service."
    },
    "sso_saml": {
     "v": true,
     "plan": "Premium",
     "src": "https://support.squarespace.com/hc/en-us/articles/17752064216589-Logging-in-with-single-sign-on-through-Google-Premium-Enterprise",
     "q": "First, you'll need to set up a custom SAML app for your Google organization."
    },
    "scim": {
     "v": true,
     "plan": "Premium",
     "src": "https://support.squarespace.com/hc/en-us/articles/360048211611-Logging-in-with-single-sign-on-through-Okta-Premium-Enterprise",
     "q": "With SCIM user provisioning, user accounts in Okta sync with accounts in Squarespace."
    },
    "mfa": {
     "v": true,
     "src": "https://www.squarespace.com/security",
     "q": "Add an extra layer of security and prevent unauthorized access to your account by enabling two-factor authentication (2FA)."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "TLS in transit",
     "src": "https://www.squarespace.com/measures",
     "q": "Squarespace leverages transport layer security (TLS) to encrypt data in-transit between website end users and customer domains."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "none",
     "summary": "Squarespace point of sale in the Squarespace app requires an internet connection; there is no offline checkout.",
     "src": "https://support.squarespace.com/hc/en-us/articles/41203307826445-Accepting-payments-with-a-Square-Reader",
     "q": "You need to be connected to the internet to use point of sale"
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.squarespace.com/hc/en-us/articles/360002093708-Edit-your-site-with-the-Squarespace-app",
     "q": "Download the app for Android or iOS."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "In-person sales run in the Squarespace app with Tap to Pay (iPhone/Android) or a Square Reader (US only); Square Register, Stand and Terminal are not supported.",
     "src": "https://support.squarespace.com/hc/en-us/articles/360035711431-Selling-in-person-with-Squarespace",
     "q": "Use the Squarespace app on your device to take orders and collect payments."
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "SSO for team logins (Okta, Microsoft Entra ID, Google SAML) is limited to Squarespace's Premium and Enterprise plans.",
     "src": "https://support.squarespace.com/hc/en-us/articles/360048211611-Logging-in-with-single-sign-on-through-Okta-Premium-Enterprise",
     "q": "If you're on our Premium or Enterprise plan, you can set up single sign-on (SSO) with Okta."
    },
    {
     "topic": "security",
     "text": "Squarespace says its built-in payment processor integrations are PCI-DSS compliant; it publishes no SOC 2 or ISO 27001 claim on its security page.",
     "src": "https://www.squarespace.com/security",
     "q": "All of Squarespace's built-in payment processor integrations are compliant with PCI-DSS."
    },
    {
     "topic": "office",
     "text": "Squarespace point of sale stops working without internet, so a store needs Wi-Fi or cellular data at the counter.",
     "src": "https://support.squarespace.com/hc/en-us/articles/41203307826445-Accepting-payments-with-a-Square-Reader",
     "q": "You need to be connected to the internet to use point of sale"
    }
   ]
  },
  {
   "slug": "stripe",
   "name": "Stripe",
   "category": "Payment Processing",
   "checked": "2026-09-19",
   "scope": "Stripe payments platform and Dashboard (usage-based pricing, no tiered plans); Stripe Terminal covered for in-person payments.",
   "profile_url": "https://helpcompare.com/tools/stripe/#security-offline-remote",
   "trust_center": "https://docs.stripe.com/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://docs.stripe.com/security",
     "q": "SOC 1 and SOC 2 Type II reports are produced annually and can be provided upon request."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "PCI DSS Level 1 (Service Provider)",
      "SOC 1 Type II",
      "SOC 3",
      "EMVCo Level 1 and 2 (Terminal)"
     ],
     "src": "https://docs.stripe.com/security",
     "q": "Stripe Terminal is certified to the EMVCo Level 1 and 2 standards of EMV® Specifications for card and terminal security and interoperability."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://stripe.com/legal/dpa",
     "q": "If User's Stripe Account is located in North America or South America, User enters this DPA with Stripe, LLC."
    },
    "sso_saml": {
     "v": true,
     "src": "https://docs.stripe.com/get-started/account/sso",
     "q": "Stripe supports Security Assertion Markup Language (SAML) 2.0, so your IdP can manage the creation of user accounts (team members)"
    },
    "scim": {
     "v": true,
     "src": "https://docs.stripe.com/get-started/account/sso/scim",
     "q": "With SCIM, you can automatically provision team members in Stripe even before they sign in, and deprovision them on demand"
    },
    "mfa": {
     "v": true,
     "enforce": "Any account (Administrator or Super Administrator setting)",
     "src": "https://docs.stripe.com/get-started/account/orgs/team",
     "q": "Only an organization Administrator or Super Administrator can require 2FA for all team members."
    },
    "audit_log": {
     "v": true,
     "src": "https://docs.stripe.com/get-started/account/orgs/team",
     "q": "To view your organization’s security history, go to the Security history tab. Here, you can filter your security history by date or action."
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "Card numbers AES-256 at rest; TLS 1.2+ required in transit",
     "src": "https://docs.stripe.com/security",
     "q": "All card numbers are encrypted at rest with AES-256."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "Stripe Terminal can store in-person card payments locally on the POS device or smart reader during an outage and forwards them to Stripe automatically when the connection comes back.",
     "src": "https://docs.stripe.com/terminal/features/operate-offline/overview",
     "q": "If you have internet connectivity issues, Stripe Terminal allows you to store payments locally on your POS device or smart reader."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://docs.stripe.com/dashboard/mobile",
     "q": "Stripe offers a mobile application to access the Dashboard for both iOS and Android devices."
    },
    "limits": {
     "v": "Offline mode works only with supported Terminal readers; Tap to Pay on Android doesn't support it",
     "src": "https://docs.stripe.com/terminal/features/operate-offline/overview",
     "q": "Tap to Pay on Android doesn’t support offline mode."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "Stripe Terminal supports pre-certified card readers (Stripe Reader S700/S710, BBPOS WisePOS E, Stripe Reader M2, BBPOS WisePad 3, Verifone) and Tap to Pay.",
     "src": "https://docs.stripe.com/terminal/payments/setup-reader",
     "q": "Stripe Terminal readers offer end-to-end encryption and remote management tools."
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "API access can be restricted by access policies to specific IPv4 addresses or CIDR ranges (this applies to API keys, not Dashboard sign-in).",
     "src": "https://docs.stripe.com/keys",
     "q": "IP addresses : Restrict access to one or more specific IPv4 addresses or CIDR ranges. Use this approach if your servers have fixed IP addresses."
    },
    {
     "topic": "office",
     "text": "Stored offline payments survive a POS reboot and are forwarded once the SDK reconnects.",
     "src": "https://docs.stripe.com/terminal/features/operate-offline/overview",
     "q": "You can safely reboot the POS device even if it has stored offline payments."
    },
    {
     "topic": "security",
     "text": "The Dashboard security history can be filtered by action across hundreds of event types and exported as CSV.",
     "src": "https://docs.stripe.com/get-started/account/orgs/team",
     "q": "You can also export your entire security history as a CSV file."
    }
   ]
  },
  {
   "slug": "toggl-track",
   "name": "Toggl Track",
   "category": "Time Tracking",
   "checked": "2026-09-19",
   "scope": "Toggl Track (legacy standalone time tracker, still supported for existing users); the new unified Toggl 2.0 product not researched.",
   "profile_url": "https://helpcompare.com/tools/toggl-track/#security-offline-remote",
   "trust_center": "https://toggl.com/track/security-and-reliability/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://toggl.com/track/soc-compliance/",
     "q": "Toggl has successfully completed its SOC 2 Type II audit — the highest bar in the SOC 2 framework, and the standard most security teams look for."
    },
    "iso27001": {
     "v": true,
     "src": "https://support.toggl.com/en-us/article/what-is-toggl-track-129hmik",
     "q": "Toggl is ISO/IEC 27001 certified, demonstrating our commitment to the highest standards of information security management."
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://toggl.com/legal/data-processing-agreement",
     "q": "The purpose of this DPA is to supplement the Terms in respect to the processing of Relevant Data and the standard contractual clauses"
    },
    "sso_saml": {
     "v": true,
     "plan": "Premium",
     "src": "https://support.toggl.com/en-us/article/how-to-set-up-single-sign-on-1o5890d",
     "q": "Toggl Track - Premium and Enterprise subscriptions"
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://support.toggl.com/en-us/article/how-to-set-up-2fa-two-factor-authentication-16vsejg",
     "q": "Two-factor authentication adds a second verification step each time you sign in with your password."
    },
    "audit_log": {
     "v": true,
     "plan": "Premium",
     "src": "https://support.toggl.com/en-us/article/audit-log-1k6yeiw",
     "q": "Audit Log is available exclusively on Premium and Enterprise plans."
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "Encryption in transit and at rest; TLS; hosted on Google Cloud Platform",
     "src": "https://toggl.com/legal/track/privacy/",
     "q": "including encryption in transit and at rest, access controls, monitoring, and resilience measures."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "full",
     "summary": "The Windows and macOS desktop apps track and edit time offline and sync when reconnected; the web app works offline only on the Timer page, with reports and settings unavailable.",
     "src": "https://support.toggl.com/en-us/article/toggl-track-desktop-app-for-macos-1669b8x",
     "q": "The desktop app also works offline; it stores data locally and sends it to the Toggl Track server once you’re back online."
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://support.toggl.com/en-us/article/what-is-toggl-track-129hmik",
     "q": "it's available on the web, as desktop apps for both Windows and Mac, as browser extensions for Chrome and Firefox, and as mobile apps for iOS and Android."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.toggl.com/en-us/article/what-is-toggl-track-129hmik",
     "q": "it's available on the web, as desktop apps for both Windows and Mac, as browser extensions for Chrome and Firefox, and as mobile apps for iOS and Android."
    },
    "limits": {
     "v": "Web app offline mode covers time tracking on the Timer page only, for a limited time; logging out of a desktop app deletes unsynced entries.",
     "src": "https://support.toggl.com/en-us/article/can-toggl-track-work-offline-4r4tcw",
     "q": "Offline mode is only available for time tracking. In other words, it only works on the Timer page."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Toggl Track does not take screenshots or monitor app usage in any of its apps, so remote staff are not surveilled.",
     "src": "https://support.toggl.com/en-us/article/can-toggl-track-take-screenshots-of-my-employees-screen-while-they-work-1x52xg5",
     "q": "Toggl Track does not support screenshot functionality or app usage monitoring in any of our apps."
    },
    {
     "topic": "office",
     "text": "Desktop apps in offices with restricted internet (firewall/proxy) most commonly hit sync problems; the Windows app has proxy settings.",
     "src": "https://support.toggl.com/en-us/article/how-does-toggl-track-sync-data-12n5i7e",
     "q": "most commonly has sync issues when used in an office environment with a restricted internet"
    },
    {
     "topic": "security",
     "text": "Organizations can enforce SSO-only login for their domain once an SSO profile (Premium or Enterprise) is approved.",
     "src": "https://support.toggl.com/en-us/article/how-to-set-up-single-sign-on-1o5890d",
     "q": "Enforcing SSO-only login ensures that access to Toggl is controlled solely by single sign-on via your identity provider."
    }
   ]
  },
  {
   "slug": "trello",
   "name": "Trello",
   "category": "Project Management",
   "checked": "2026-09-19",
   "scope": "Trello cloud (Atlassian); SSO, SCIM and org audit log come from Atlassian Guard, administered in Atlassian Administration",
   "profile_url": "https://helpcompare.com/tools/trello/#security-offline-remote",
   "trust_center": "https://www.atlassian.com/trust/compliance/resources",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://wac-cdn.atlassian.com/misc-assets/pdfs/FY25_Mega_Audit_Atlassian_SOC_2_Bridge_Letter.pdf",
     "q": "Coalfire Controls, LLC prepared the latest SOC 2 Type II report relevant to the following Atlassian Cloud products"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.atlassian.com/trust/compliance/resources/iso27001",
     "q": "ISO/IEC 27001:2022 is a security management standard that specifies security management best practices and comprehensive security controls following the ISO/IEC 27002 best practice guidance."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27018",
      "CSA STAR",
      "TISAX"
     ],
     "src": "https://www.atlassian.com/trust/compliance/resources/iso27001",
     "q": "which further extends to the additional controls defined within ISO/IEC 27018:2019."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.atlassian.com/legal/data-processing-addendum",
     "q": "Atlassian Data Processing Addendum"
    },
    "sso_saml": {
     "v": true,
     "plan": "Any plan with Atlassian Guard Standard (add-on); included in Enterprise",
     "src": "https://trello.com/pricing",
     "q": "Add enterprise-grade security and controls. This plan includes Atlassian Guard Standard and 24/7 Enterprise Admin support."
    },
    "scim": {
     "v": true,
     "plan": "Any plan with Atlassian Guard Standard (add-on); included in Enterprise",
     "src": "https://trello.com/pricing",
     "q": "Free SSO and user provisioning with Atlassian Guard"
    },
    "mfa": {
     "v": true,
     "enforce": "All plans (managed accounts)",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/enforce-two-step-verification/",
     "q": "Atlassian Cloud: All plans Atlassian Government Cloud: Not available Enforce two-step verification for managed accounts"
    },
    "audit_log": {
     "v": true,
     "plan": "Any plan with Atlassian Guard Standard (add-on); included in Enterprise",
     "src": "https://support.atlassian.com/security-and-access-policies/docs/atlassian-guard-product-and-plan-availability/",
     "q": "Audit logs for organization administration activities Atlassian Cloud: Atlassian Guard Standard"
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "AES-256 full-disk encryption at rest; TLS 1.2+ in transit",
     "src": "https://www.atlassian.com/trust/security/security-practices",
     "q": "Trello, Loom, Compass and Rovo use full disk, industry-standard AES-256 encryption at rest."
    },
    "self_host": {
     "v": false,
     "src": "https://trello.com/pricing",
     "q": "Trello is proudly a cloud-only product. We offer access via the web, desktop, and our awesome mobile apps."
    },
    "mode": {
     "v": "full",
     "summary": "The iOS and Android apps let you create and edit boards, lists and cards offline and sync automatically on reconnect; the web and desktop apps need an internet connection.",
     "src": "https://blog.trello.com/trello-mobile-offline",
     "q": "you can create new boards, lists, cards, and more from your Android and iOS devices."
    },
    "desktop": {
     "v": [
      "macOS",
      "Windows"
     ],
     "src": "https://support.atlassian.com/trello/docs/what-browsers-and-mobile-platforms-does-trello-support/",
     "q": "The Trello desktop app is available for: macOS - 12 or higher (64-bit Only) Windows 10 or 11 - (64-bit)"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.atlassian.com/trello/docs/what-browsers-and-mobile-platforms-does-trello-support/",
     "q": "iOS - Version 18.6 or higher Android - Version 10 or higher with Google Play"
    },
    "limits": {
     "v": "Mobile apps only; the desktop apps and web need an active connection",
     "src": "https://support.atlassian.com/trello/docs/trello-desktop-apps/",
     "q": "Just like Trello on the web, the Trello desktop apps require an active internet connection and do not support offline syncing."
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "plan": "Free",
     "summary": "Built-in mobile device management (MDM) support for the iOS and Android apps, listed on every plan.",
     "src": "https://trello.com/pricing",
     "q": "Enforce security controls on mobile app usage through built-in mobile device management (MDM) support for iOS and Android."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "SAML SSO and enforced 2FA for Trello come through Atlassian Guard, a separate subscription (from $4/user/month) unless you are on Trello Enterprise, which includes Guard Standard.",
     "src": "https://trello.com/pricing",
     "q": "Atlassian Guard is a separate subscription that your company can enable across all your Atlassian products and starts at $4/month/user."
    },
    {
     "topic": "offline",
     "text": "Trello's desktop apps behave like the web app and do not work offline; only the mobile apps sync offline changes.",
     "src": "https://support.atlassian.com/trello/docs/trello-desktop-apps/",
     "q": "Just like Trello on the web, the Trello desktop apps require an active internet connection and do not support offline syncing."
    }
   ]
  },
  {
   "slug": "vendasta",
   "name": "Vendasta",
   "category": "Agency & White-Label Software Platforms",
   "checked": "2026-09-19",
   "scope": "Vendasta platform (Partner Center + client-facing Business App)",
   "profile_url": "https://helpcompare.com/tools/vendasta/#security-offline-remote",
   "trust_center": "https://trust.vendasta.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://support.vendasta.com/getting-started/security-and-privacy/",
     "q": "Vendasta and Yesware maintain a current System and Organization Controls (SOC 2®) Type 2 report, issued by an independent auditor."
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "PCI DSS (self-assessment questionnaire)"
     ],
     "src": "https://trust.vendasta.com/faq",
     "q": "We’ve completed our Self-Assessment Questionnaire (SAQ) for PCI-DSS, aligning how we handle payment card data with Payment Card Industry standards."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "TLS in transit; at-rest encryption provided by Google Cloud",
     "src": "https://trust.vendasta.com/faq",
     "q": "Data is encrypted in transit using industry-standard TLS and at rest using strong encryption provided by our cloud infrastructure."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://docs.vendasta.com/business-app/",
     "q": "Install the unbranded app on mobile devices (iOS and Android) or white-labeled Progressive Web App (PWA)"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Vendasta publishes a SOC 3 report on its Trust Center with no NDA required; the full SOC 2 report is gated.",
     "src": "https://support.vendasta.com/getting-started/security-and-privacy/",
     "q": "Vendasta also publishes a SOC 3® report on the Trust Center , publicly and with no NDA required."
    },
    {
     "topic": "security",
     "text": "Partners can connect their own identity provider for SSO via OpenID Connect (not SAML) in Partner Center.",
     "src": "https://developers.vendasta.com/getting-started/single-sign-on/identity-provider-sso/",
     "q": "Vendasta currently supports OpenIDConnect, an industry standard protocol built to extend OAuth2.0 with a user identification layer"
    },
    {
     "topic": "security",
     "text": "Vendasta is hosted on Google Cloud infrastructure.",
     "src": "https://trust.vendasta.com/faq",
     "q": "Vendasta is hosted on Google Cloud infrastructure."
    }
   ]
  },
  {
   "slug": "webex",
   "name": "Webex",
   "category": "Video Conferencing",
   "checked": "2026-09-19",
   "scope": "Webex Suite (Meetings, Messaging, Calling) managed in Control Hub. FedRAMP and DISA IL5 apply to Webex for Government.",
   "profile_url": "https://helpcompare.com/tools/webex/#security-offline-remote",
   "trust_center": "https://www.webex.com/us/en/solutions/cross-platform/security.html",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.webex.com/us/en/solutions/cross-platform/security.html",
     "q": "ISO/IEC 27701:2019 ISO/IEC 9001:2015 SOC 2 Type II SOC 3"
    },
    "iso27001": {
     "v": true,
     "src": "https://help.webex.com/en-us/article/pdz31w/Webex-Compliance-and-Certifications",
     "q": "Webex is ISO/IEC 27001:2013 certified."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "ISO 9001",
      "SOC 3",
      "C5",
      "CSA STAR Level 2",
      "Cyber Essentials (UK)",
      "ENS (Spain)",
      "EU Cloud CoC",
      "IRAP",
      "ISMAP",
      "FedRAMP (Webex for Government)",
      "DISA IL5 (Webex for Government)"
     ],
     "src": "https://www.webex.com/us/en/solutions/cross-platform/security.html",
     "q": "C5 (Germany) CSA STAR - Level 1 CSA STAR - Level 2 Cyber Essentials (UK) ENS (Spain) EU Cloud CoC IRAP (Australia) ISMAP (Japan)"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": true,
     "src": "https://help.webex.com/en-us/article/lfu88u/Single-Sign-On-Integration-in-Cisco-Webex-Control-Hub",
     "q": "If you have your own identity provider (IdP) in your organization, you can integrate the SAML IdP with your organization in Control Hub for single sign-on (SSO)."
    },
    "scim": {
     "v": true,
     "src": "https://help.webex.com/en-us/article/6ta3gz/Synchronize-Azure-Active-Directory-users-into-Control-Hub",
     "q": "Use the prebuilt Cisco Webex enterprise application in Microsoft Entra ID to synchronize assigned users to Control Hub with the legacy SCIM provisioning integration."
    },
    "mfa": {
     "v": true,
     "src": "https://help.webex.com/en-us/article/52szeq/Enable-multi-factor-authentication-integration-in-Control-Hub",
     "q": "If you want to add an extra layer of security for users in your organization, you can enable multi-factor authentication (MFA) in Control Hub."
    },
    "audit_log": {
     "v": true,
     "src": "https://help.webex.com/en-us/article/2tc9yx/Review-Your-Administrator-Activity-Logs-in-Cisco-Webex-Control-Hub",
     "q": "Organization full and read-only administrators can audit activities in the activity log, which tracks site configuration changes and recording management."
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "CA",
      "UK",
      "JP",
      "AU",
      "SG",
      "SA",
      "AE",
      "IN"
     ],
     "src": "https://help.webex.com/en-US/article/oybc4fb/Data-Residency-in-Webex",
     "q": "Webex services and user-generated content US EU Canada UK Japan Australia Singapore Saudi Arabia UAE India"
    },
    "encryption": {
     "v": "AES-256-GCM for meeting media and stored content; TLS 1.2+ in transit; optional end-to-end encryption",
     "src": "https://help.webex.com/en-us/article/nhxkyce/Webex-Suite-Meetings-Security-technical-paper",
     "q": "Media streams—including audio, video, screen sharing, and document sharing—are encrypted using the AES-256-GCM as the preferred cipher."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://help.webex.com/en-us/article/nhxkyce/Webex-Suite-Meetings-Security-technical-paper",
     "q": "Webex desktop application on Windows, Mac and Linux."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://help.webex.com/en-us/article/nhxkyce/Webex-Suite-Meetings-Security-technical-paper",
     "q": "Webex mobile application on Android and iOS."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "Cisco Board, Desk and Room Series devices are Webex's own meeting-room and desk hardware; meetings also accept third-party SIP endpoints and PSTN phones.",
     "src": "https://help.webex.com/en-us/article/nhxkyce/Webex-Suite-Meetings-Security-technical-paper",
     "q": "Cisco Room Devices and Desk Devices. Third-party SIP standards-based audio and video endpoints. PSTN devices."
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Webex HD video uses up to 3.0 Mbps sending and 2.5 Mbps receiving per participant.",
     "src": "https://help.webex.com/en-us/article/WBX22158/What-are-the-Minimum-Bandwidth-Requirements-for-Sending-and-Receiving-Video-in-Cisco-Webex-Meetings",
     "q": "High Definition Video: 2.5 Mbps (Receive) and 3.0 Mbps (Send)"
    },
    {
     "topic": "remote",
     "text": "Webex Messaging data region follows the organization's country: EMEA orgs go to EU data centers, the Americas and APAC to US data centers.",
     "src": "https://help.webex.com/en-US/article/oybc4fb/Data-Residency-in-Webex",
     "q": "EU, Middle East, and Africa customers will be provisioned to EU data centers; US, Canada, APAC, and South America customers will be provisioned to US data centers."
    },
    {
     "topic": "security",
     "text": "Webex says it can be used in healthcare settings consistent with HIPAA needs; its help page does not state a standard customer BAA.",
     "src": "https://help.webex.com/en-us/article/pdz31w/Webex-Compliance-and-Certifications",
     "q": "Webex can be used in a healthcare environment consistent with customer needs for HIPAA compliance."
    },
    {
     "topic": "security",
     "text": "Admin audit logs are kept one year in most regions and three years in India.",
     "src": "https://help.webex.com/en-US/article/oybc4fb/Data-Residency-in-Webex",
     "q": "Audit log retention is one year (12 months) in most regions and three years in India."
    }
   ]
  },
  {
   "slug": "wix",
   "name": "Wix",
   "category": "Website Builders",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/wix/#security-offline-remote",
   "trust_center": "https://www.wix.com/trust-center/security",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.wix.com/trust-center/security",
     "q": "Wix is compliant and certified with the highest international privacy and security regulations, including Soc 2 Type 2"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.wix.com/trust-center/security",
     "q": "ISO 27001, 27017, 27018, and 27701"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "PCI DSS Level 1"
     ],
     "src": "https://www.wix.com/trust-center/security",
     "q": "ISO 27001, 27017, 27018, and 27701"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://support.wix.com/en/article/wixs-data-processing-agreement-for-wix-users",
     "q": "The DPA (Data Processing Agreement) is a public and binding document between Wix and its users"
    },
    "sso_saml": {
     "v": true,
     "plan": "Enterprise (OpenID Connect only, not SAML)",
     "src": "https://support.wix.com/en/article/sso-setting-up-single-sign-on-sso-login-for-your-organization",
     "q": "Wix currently supports only the Open ID Connect protocol"
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.wix.com/en/article/wix-studio-faqs-enterprise-users",
     "q": "additional security features like SSO, audit logs, IP allowlisting, SCIM, and a custom SSL certificate are included with the enterprise solution"
    },
    "mfa": {
     "v": true,
     "src": "https://www.wix.com/trust-center/security",
     "q": "We offer two-factor authentication via email, SMS or authenticator app"
    },
    "audit_log": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.wix.com/en/article/wix-studio-faqs-enterprise-users",
     "q": "additional security features like SSO, audit logs, IP allowlisting, SCIM, and a custom SSL certificate are included with the enterprise solution"
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "AES-256 at rest; HTTPS/TLS 1.2+ in transit",
     "src": "https://www.wix.com/trust-center/security",
     "q": "Our data in transit encryption uses HTTPS, TLS 1.2+ and automatic SSL [...] data at rest uses AES-256"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "none",
     "summary": "Wix POS Register cannot take credit card sales offline for later sync; Wix lists it as a feature request.",
     "src": "https://support.wix.com/en/article/wix-retail-pos-request-ability-to-make-offline-credit-card-sales",
     "q": "Currently, if you do not have a WiFi connection, you cannot make credit card sales offline that sync when you get back online."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.wix.com/en/article/wix-app-downloading-the-app",
     "q": "Go to the Apple App Store (on iPhone) or Google Play (on Android)."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://support.wix.com/en/article/wix-studio-faqs-enterprise-users",
     "q": "additional security features like SSO, audit logs, IP allowlisting, SCIM, and a custom SSL certificate are included with the enterprise solution"
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "Wix POS Register runs on a POS tablet with card readers (Stripe Reader M2 in the US, WisePad 3 in Canada/UK, Wix POS Go in all three) and Epson receipt printers.",
     "src": "https://support.wix.com/en/article/wix-pos-register-selecting-a-card-reader",
     "q": "Stripe Reader M2 (Available in the US)"
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Organization SSO on Wix is OpenID Connect only (not SAML) and requires the Wix Studio enterprise solution or Wix Channels.",
     "src": "https://support.wix.com/en/article/sso-setting-up-single-sign-on-sso-login-for-your-organization",
     "q": "SSO login is only available with Wix Studio enterprise solution and Wix Channels"
    },
    {
     "topic": "security",
     "text": "Audit logs, IP allowlisting, SCIM and SSO are enterprise-solution features, not part of standard Wix plans.",
     "src": "https://support.wix.com/en/article/wix-studio-faqs-enterprise-users",
     "q": "additional security features like SSO, audit logs, IP allowlisting, SCIM, and a custom SSL certificate are included with the enterprise solution"
    },
    {
     "topic": "offline",
     "text": "Wix POS cannot queue card payments while the Wi-Fi is down, so stores need a fallback payment method during outages.",
     "src": "https://support.wix.com/en/article/wix-retail-pos-request-ability-to-make-offline-credit-card-sales",
     "q": "Currently, if you do not have a WiFi connection, you cannot make credit card sales offline that sync when you get back online."
    }
   ]
  },
  {
   "slug": "woocommerce",
   "name": "WooCommerce",
   "category": "E-commerce Platforms",
   "checked": "2026-09-19",
   "scope": "Self-hosted WordPress plugin; store data lives on your web host, so certifications, encryption, SSO, residency and access controls depend on your host and add-ons. Only WooCommerce's own statements recorded.",
   "profile_url": "https://helpcompare.com/tools/woocommerce/#security-offline-remote",
   "trust_center": "https://woocommerce.com/document/woocommerce-security-faq/",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": null
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": null
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": null
    },
    "self_host": {
     "v": true,
     "src": "https://woocommerce.com/document/woocommerce-security-faq/",
     "q": "This information, like the rest of your WordPress installation's data, is stored in your website host's database."
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://woocommerce.com/document/woo-mobile-app-point-of-sale-mode/",
     "q": "Tablet device running iOS 18 or later, or Android 9 or later"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "POS mode in the Woo mobile app accepts card payments via an M2 reader (US) or WisePad 3 reader (UK and other supported countries), Tap to Pay, or an Android phone as a remote reader.",
     "src": "https://woocommerce.com/document/woo-mobile-app-point-of-sale-mode/",
     "q": "M2 card reader (US) or WisePad 3 reader (UK and other supported countries)"
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "The core WooCommerce plugin is not PCI certified; PCI DSS compliance is the store owner's responsibility.",
     "src": "https://woocommerce.com/document/pci-dss-compliance-and-woocommerce/",
     "q": "PCI DSS compliance is ultimately the responsibility of the store owner."
    },
    {
     "topic": "security",
     "text": "A WooCommerce store's security is tied to its WordPress install and host, so the hosting choice decides most security controls.",
     "src": "https://woocommerce.com/document/woocommerce-security-faq/",
     "q": "Because WooCommerce is built on WordPress, a given WooCommerce site is overall exactly as secure as the WordPress installation itself."
    },
    {
     "topic": "offline",
     "text": "POS mode downloads the store's product catalog to the device for browsing, search and barcode scanning; WooCommerce does not document offline checkout.",
     "src": "https://woocommerce.com/document/woo-mobile-app-point-of-sale-mode/",
     "q": "To support fast product browsing, search, and barcode scanning in POS mode, the Woo Mobile app downloads your store's product catalog to the device."
    }
   ]
  },
  {
   "slug": "woodpecker",
   "name": "Woodpecker",
   "category": "Cold Email & Sales Engagement",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/woodpecker/#security-offline-remote",
   "trust_center": "https://woodpecker.co/safety-security/",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://woodpecker.co/safety-security/",
     "q": "if you, as a Customer, wish to sign a Data Processing Agreement please contact our support team."
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://woodpecker.co/help-center/en/articles/10586933-enabling-two-step-authentification-in-woodpecker",
     "q": "If you're an account admin, you can enable it in Woodpecker."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "Partial: AES-256-GCM at rest and TLS 1.3 in transit, per vendor 'partially encrypt' wording",
     "src": "https://woodpecker.co/safety-security/",
     "q": "We partially encrypt our data is encrypted at rest with 256-bit AES with GCM to ensure safety. Furthermore, we partially encrypt data in transit – the environment utilizes TLS 1.3"
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": null
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Woodpecker stores data on OVH-hosted servers; the ISO 27001 certification cited belongs to the hosting provider, not Woodpecker itself.",
     "src": "https://woodpecker.co/safety-security/",
     "q": "Woodpecker stores its data on OVH hosted servers – ISO certified (ISO 27001)."
    },
    {
     "topic": "security",
     "text": "Woodpecker's two-step login sends a verification code to the account email address.",
     "src": "https://woodpecker.co/help-center/en/articles/10586933-enabling-two-step-authentification-in-woodpecker",
     "q": "Next time you log in, you’ll be asked to enter the verification code sent to your email address."
    },
    {
     "topic": "security",
     "text": "Woodpecker states full recovery after a complete database breakdown should not exceed 6 hours, with backups every 6 hours.",
     "src": "https://woodpecker.co/safety-security/",
     "q": "Full recovery time shall not exceed 6 hours in case of full database breakdown."
    }
   ]
  },
  {
   "slug": "wordpress",
   "name": "WordPress",
   "category": "Website Builders",
   "checked": "2026-09-19",
   "scope": "WordPress.com hosted plans (Automattic) for security and plan fields; self-hosted WordPress.org software depends on your host. Enterprise WordPress VIP not covered.",
   "profile_url": "https://helpcompare.com/tools/wordpress/#security-offline-remote",
   "trust_center": "https://wordpress.com/support/security/",
   "fields": {
    "soc2": {
     "v": null
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": null
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://wordpress.com/support/data-processing-agreements/",
     "q": "The Data Processing Agreement is an amendment to our Terms of Service and is available to all WordPress.com site owners."
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://wordpress.com/support/security/",
     "q": "Two-step authentication adds an extra step to your login process: after you enter your password, you must provide a code from your phone or a physical key."
    },
    "audit_log": {
     "v": true,
     "plan": "Free (last 20 events; full history on paid plans)",
     "src": "https://wordpress.com/support/activity/",
     "q": "Free plans are limited to viewing only the past 20 events, whereas WordPress.com paid plans have access to their complete site activity"
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "SSL/HTTPS on all sites, including custom domains",
     "src": "https://wordpress.com/support/security/",
     "q": "We encrypt (serve over SSL) all WordPress.com sites, including custom domains."
    },
    "self_host": {
     "v": true,
     "src": "https://wordpress.org/download/",
     "q": "Recommend PHP 8.3 or greater and MySQL version 8.0 or MariaDB version 10.11 or greater."
    },
    "mode": {
     "v": "full",
     "summary": "The Jetpack mobile apps (iOS and Android) let you write and edit posts and pages while offline for your WordPress.com site.",
     "src": "https://wordpress.com/support/offline-editing/",
     "q": "write posts while offline and are available for both iOS and Android"
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://wordpress.com/support/apps/",
     "q": "The full WordPress.com experience is also available as an app for your laptop or desktop on Windows, Mac, and Linux."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://wordpress.com/support/apps/",
     "q": "Our Jetpack app is intuitive, free-to-use, and puts the full WordPress experience in your pocket."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "A WordPress.com staff member stated in the support forums (Sep 2023) that WordPress.com does not have SOC 2 reports.",
     "src": "https://wordpress.com/forums/topic/requesting-for-a-copy-of-wordpress-soc-2-report/",
     "q": "while we do take security very seriously here, we do not have SOC 2 reports."
    },
    {
     "topic": "security",
     "text": "Activity log retention depends on plan: Free shows only the last 20 events, paid plans show full activity for their retention period.",
     "src": "https://wordpress.com/support/activity/",
     "q": "Free plans are limited to viewing only the past 20 events, whereas WordPress.com paid plans have access to their complete site activity"
    },
    {
     "topic": "offline",
     "text": "Offline writing is supported via the Jetpack apps and third-party editors such as MarsEdit and Microsoft Word that publish to WordPress.com.",
     "src": "https://wordpress.com/support/offline-editing/",
     "q": "create and edit posts and pages for your WordPress.com site at any time from the apps"
    }
   ]
  },
  {
   "slug": "xero",
   "name": "Xero",
   "category": "Accounting Software",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/xero/#security-offline-remote",
   "trust_center": "https://www.xero.com/us/security/",
   "fields": {
    "soc2": {
     "v": "Report (type not stated)",
     "src": "https://www.xero.com/us/security/",
     "q": "Xero produces Service Organization Control (SOC) 2 reports based on independent audits of Xero’s cloud-based"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.xero.com/us/security/",
     "q": "Xero is certified as compliant with ISO/IEC ISO27001:2022, the premier global information security management system (ISMS) standard."
    },
    "other_certs": {
     "v": [
      "PCI DSS v4.0 (SAQ A; Level 2 merchant)"
     ],
     "src": "https://www.xero.com/us/security/",
     "q": "We comply with the Payment Card Industry Data Security Standard. We're a level 2 merchant & outsource card processing to level 1 providers."
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.xero.com/us/legal/terms/data-processing/",
     "q": "This Data Processing Addendum (the Addendum ) forms part of the Xero terms of use (and any related documentation), as amended from time to time"
    },
    "sso_saml": {
     "v": null
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "All plans (MFA is mandatory for all users)",
     "src": "https://www.xero.com/us/security/multi-factor-authentication/faq/",
     "q": "You’ll need to set up and use MFA. It’s a mandatory requirement if you want to continue to use Xero."
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": null
    },
    "encryption": {
     "v": "Encryption in transit and at rest (algorithms not stated)",
     "src": "https://www.xero.com/us/security/",
     "q": "We provide multiple layers of protection for the information you trust to Xero, including encryption when it’s transferred and stored."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "partial",
     "summary": "In the Xero mobile app you can draft invoices and capture receipts offline and they sync when you reconnect; everything else, including the web app, needs an internet connection.",
     "src": "https://www.xero.com/uk/guides/mobile-accounting-app/",
     "q": "You need an internet connection to sync data and access your accounts. You can draft invoices and capture receipts offline, and they will sync automatically when you are back online."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://www.xero.com/us/accounting-software/xero-accounting-mobile-app/",
     "q": "The Xero Accounting app is available on iOS and Android devices, including iPads and tablets."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "Tap to Pay in the Xero Accounting app (powered by Stripe) takes contactless in-person payments for invoices with no extra hardware or terminal.",
     "src": "https://www.xero.com/us/accounting-software/xero-accounting-mobile-app/",
     "q": "accept in-person contactless payments for invoices, straight from the Xero Accounting app, powered by Stripe. Included No additional hardware or physical terminals needed"
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Xero runs in the browser and mobile apps with multiple users working at the same time, but it needs an internet connection.",
     "src": "https://www.xero.com/us/about/common-questions/",
     "q": "You’ll need an internet connection to access Xero."
    },
    {
     "topic": "security",
     "text": "Xero's SOC 2 reports and ISO 27001 certificate are available to logged-in customers on request; the SOC 2 report type is not stated publicly.",
     "src": "https://www.xero.com/us/security/",
     "q": "Xero produces Service Organization Control (SOC 2) reports based on independent audits of Xero’s cloud-based accounting system."
    },
    {
     "topic": "security",
     "text": "Payroll employees and Xero portal/Ask portal users don't have to set up MFA; everyone else with access to a paid subscription does.",
     "src": "https://www.xero.com/us/security/multi-factor-authentication/faq/",
     "q": "like payroll employees and those who use the Xero portal and Ask portal, won’t need to set up MFA."
    }
   ]
  },
  {
   "slug": "zapier",
   "name": "Zapier",
   "category": "Workflow Automation",
   "checked": "2026-09-19",
   "scope": null,
   "profile_url": "https://helpcompare.com/tools/zapier/#security-offline-remote",
   "trust_center": "https://trust.zapier.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://zapier.com/security-compliance",
     "q": "Yes, Zapier has obtained SOC 2 Type II and SOC 3 certifications"
    },
    "iso27001": {
     "v": null
    },
    "other_certs": {
     "v": [
      "SOC 3"
     ],
     "src": "https://zapier.com/security-compliance",
     "q": "Maintain SOC 2 Type II, SOC 3, GDPR, and CCPA compliance"
    },
    "hipaa": {
     "v": "Not supported",
     "src": "https://zapier.com/legal/data-privacy",
     "q": "Zapier also can’t sign business associate agreements (BAAs) or equivalent agreements for handling PHI or other similar information."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://zapier.com/legal/data-privacy",
     "q": "Zapier regularly reviews and periodically updates its Privacy Policy, Data Processing Addendum, and Terms of Service"
    },
    "sso_saml": {
     "v": true,
     "plan": "Team",
     "src": "https://help.zapier.com/hc/en-us/articles/33678718215309-Team-plan-updates-SSO-is-now-included-and-new-user-limits",
     "q": "You can now use SAML single sign-on (SSO) with your Team plan at no extra cost"
    },
    "scim": {
     "v": true,
     "plan": "Enterprise",
     "src": "https://help.zapier.com/hc/en-us/articles/8496291497741-Provision-user-accounts-with-SCIM",
     "q": "SCIM user provisioning is available only to Enterprise accounts with Workspaces."
    },
    "mfa": {
     "v": true,
     "src": "https://help.zapier.com/hc/en-us/articles/8496305453069-Set-up-two-factor-authentication-for-your-Zapier-account",
     "q": "2FA is managed at the individual account member level. It is not managed by admins or owners of your account if you are on a Team or Enterprise plan."
    },
    "audit_log": {
     "v": true,
     "plan": "Team",
     "src": "https://help.zapier.com/hc/en-us/articles/13295074298125-Use-the-audit-log-to-review-your-account-activity",
     "q": "The Audit log is only available to users on Team and Enterprise plans."
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://zapier.com/legal/data-privacy",
     "q": "Zapier hosts data in AWS servers located in the United States, including customers’ personal data and the data that is processed on behalf of customers."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2+ in transit",
     "src": "https://zapier.com/security-compliance",
     "q": "Zapier web application communications are secured using TLS 1.2 and above, and data is encrypted at rest using AES-256."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": null
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "src": "https://zapier.com/security-compliance",
     "q": "IP allowlist | Restrict access to trusted networks only"
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Zapier does not offer EU-only data storage.",
     "src": "https://zapier.com/legal/data-privacy",
     "q": "Is there an option to have my data stored only within the EU? Zapier does not support this option."
    },
    {
     "topic": "security",
     "text": "Admins cannot force 2FA in Zapier; with SAML enabled, 2FA must be enforced in your identity provider instead.",
     "src": "https://help.zapier.com/hc/en-us/articles/8496305453069-Set-up-two-factor-authentication-for-your-Zapier-account",
     "q": "2FA is managed at the individual account member level."
    },
    {
     "topic": "security",
     "text": "Company and Enterprise customers can shorten Zap data retention to between 7 and 30 days.",
     "src": "https://zapier.com/legal/data-privacy",
     "q": "Customers on Company or Enterprise plans can set a custom data retention period of between 7 to 30 days for data held in their Zapier account."
    },
    {
     "topic": "office",
     "text": "Enterprise customers can connect Zapier to internal data sources over VPC peering.",
     "src": "https://zapier.com/security-compliance",
     "q": "Connect securely to internal data sources with VPC Peering"
    }
   ]
  },
  {
   "slug": "zendesk",
   "name": "Zendesk",
   "category": "Customer Support",
   "checked": "2026-09-19",
   "scope": "Zendesk Suite (Team, Growth, Professional, Enterprise, Enterprise Plus); legacy Support-only plans differ",
   "profile_url": "https://helpcompare.com/tools/zendesk/#security-offline-remote",
   "trust_center": "https://www.zendesk.com/trust-center/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.zendesk.com/trust-center/",
     "q": "We undergo routine audits to receive updated SOC 2 Type II reports, available upon request and under NDA."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.zendesk.com/trust-center/",
     "q": "Zendesk is ISO 27001:2022 certified."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "ISO/IEC 42001",
      "FedRAMP LI-SaaS",
      "CSA STAR Level 2",
      "Cyber Essentials Plus",
      "HDS (France)"
     ],
     "src": "https://www.zendesk.com/trust-center/",
     "q": "Zendesk is FedRAMP authorized with Low Impact Software-as-a-Service (LI-SaaS) and is listed in the FedRAMP Marketplace."
    },
    "hipaa": {
     "v": "BAA available",
     "plan": "Advanced Security or Advanced Compliance add-on",
     "src": "https://www.zendesk.com/trust-center/",
     "q": "purchase the Advanced Security Deployed Associated Service or Advanced Compliance Deployed Associated Service Add-On;"
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.zendesk.com/trust-center/",
     "q": "You can review and/or execute Zendesk’s DPA here."
    },
    "sso_saml": {
     "v": true,
     "plan": "Suite Team",
     "src": "https://support.zendesk.com/hc/en-us/articles/4408887505690-Enabling-SAML-single-sign-on",
     "q": "Zendesk supports enterprise single sign-on access to Zendesk accounts via Secure Assertion Markup Language (SAML),"
    },
    "scim": {
     "v": false,
     "src": "https://support.zendesk.com/hc/en-us/articles/8966513066138-Does-Zendesk-support-SCIM",
     "q": "No, Zendesk does not currently support any official SCIM connections."
    },
    "mfa": {
     "v": true,
     "enforce": "Suite Team",
     "src": "https://support.zendesk.com/hc/en-us/articles/4408826974874-Managing-two-factor-authentication",
     "q": "You can require two-factor authentication for all team members, all end users, or both user types."
    },
    "audit_log": {
     "v": true,
     "plan": "Suite Enterprise",
     "src": "https://support.zendesk.com/hc/en-us/articles/4408828001434-Viewing-the-audit-log-for-changes-to-your-account",
     "q": "The audit log allows customers on Enterprise plans and above to view various changes in their Zendesk account since the account was created."
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "UK",
      "JP",
      "AU"
     ],
     "plan": "Suite Professional (Data Center Location add-on, free)",
     "src": "https://support.zendesk.com/hc/en-us/articles/4408838409754-About-the-Data-Center-Location-add-on",
     "q": "a Subscriber can choose to host their data within the following regions: United States European Economic Area (EEA) United Kingdom (UK) Japan (JP) Australia (AU)"
    },
    "encryption": {
     "v": "AES-256 at rest (AWS); TLS 1.2 or higher in transit",
     "src": "https://www.zendesk.com/trust-center/",
     "q": "Service Data is encrypted at rest in AWS using AES-256 key encryption."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.zendesk.com/hc/en-us/articles/7301111970842-Installing-and-configuring-the-Zendesk-Support-mobile-app",
     "q": "The Zendesk Support mobile app is available for download from both the App Store and Google Play Store for iOS and Android devices."
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "plan": "Suite Team",
     "src": "https://support.zendesk.com/hc/en-us/articles/4408894156186-Restricting-access-to-Zendesk-Support-and-your-help-center-using-IP-restrictions",
     "q": "You can restrict access to Zendesk to users within a specified IP address range."
    },
    "device_controls": {
     "v": true,
     "plan": "Suite Team",
     "summary": "Admin-set inactivity session timeout and maximum session duration, separately for team members and end users.",
     "src": "https://support.zendesk.com/hc/en-us/articles/4408832533274-Setting-session-timeout-for-users",
     "q": "You can set inactivity session time-out and maximum session duration to protect accounts by signing users out after inactivity."
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "With IP restrictions on, sign-ins, API calls and page access from outside the allowed IP ranges fail; admins can let customers bypass the restriction, but not agents or admins.",
     "src": "https://support.zendesk.com/hc/en-us/articles/4408894156186-Restricting-access-to-Zendesk-Support-and-your-help-center-using-IP-restrictions",
     "q": "Customers can be allowed to bypass restrictions while agents and admins cannot."
    },
    {
     "topic": "remote",
     "text": "Zendesk hosts Service Data in the US, EEA and Asia Pacific, and Suite Professional and above can pin data to the US, EEA, UK, Japan or Australia at no extra cost.",
     "src": "https://support.zendesk.com/hc/en-us/articles/4408838409754-About-the-Data-Center-Location-add-on",
     "q": "The Data Center Location add-on is available and free of charge for Zendesk Suite Professional or higher plans, but it is not automatically activated."
    },
    {
     "topic": "security",
     "text": "Default session timeouts are 60 minutes for agents and eight hours for end users, and admins can shorten them.",
     "src": "https://support.zendesk.com/hc/en-us/articles/4408832533274-Setting-session-timeout-for-users",
     "q": "Admins can choose separate session settings for team members and end users, with defaults of 60 minutes for agents and eight hours for end users."
    },
    {
     "topic": "remote",
     "text": "Agents can create and update tickets and get ticket notifications from the iOS and Android Support mobile app.",
     "src": "https://support.zendesk.com/hc/en-us/articles/4408846407066-About-the-Zendesk-Support-mobile-app",
     "q": "The Zendesk Support mobile app is an app for agents and team leads to view and respond to Zendesk tickets from your mobile device or tablet."
    }
   ]
  },
  {
   "slug": "zoho-crm",
   "name": "Zoho CRM",
   "category": "CRM Platforms",
   "checked": "2026-09-19",
   "scope": "Zoho CRM (cloud). Certifications, SSO and MFA are handled at Zoho-wide level (Zoho Accounts / Zoho Directory), not CRM-specific.",
   "profile_url": "https://helpcompare.com/tools/zoho-crm/#security-offline-remote",
   "trust_center": "https://www.zoho.com/security.html",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.zoho.com/compliance.html",
     "q": "Zoho is SOC 2 Type 2 compliant."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.zoho.com/compliance.html",
     "q": "Zoho has earned ISO/IEC 27001 certification for Applications, Systems, People, Technology, and Processes"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "SOC 1 Type II",
      "SOC 2 + HIPAA Type 2",
      "PCI DSS (self-assessment SAQ-D)",
      "CSA STAR Self-Assessment"
     ],
     "src": "https://www.zoho.com/compliance.html",
     "q": "Zoho is certified with ISO/IEC 27017 - Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud services."
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://help.zoho.com/portal/en/kb/crm/faqs/hipaa/articles/faq-on-hipaa",
     "q": "HIPAA requires Covered Entities to sign a Business Associate Agreement (BAA) with its Business Associates. You can request our BAA template by sending an email to legal@zohocorp.com."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.zoho.com/gdpr.html",
     "q": "If you are the organization administrator and would like to sign a DPA with us, please drop an email to legal@zohocorp.com"
    },
    "sso_saml": {
     "v": true,
     "src": "https://help.zoho.com/portal/en/kb/accounts/manage-your-organization/saml/articles/overview-saml",
     "q": "IdP will create a signed SAML assertion response, which is sent to the ACS (Assertion Consumer Service) URL endpoint at Zoho."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://help.zoho.com/portal/en/kb/accounts/multi-factor-authentication/articles/mfa-introduction",
     "q": "If you are an organization admin, you can enforce MFA for all the users in your organization."
    },
    "audit_log": {
     "v": true,
     "src": "https://www.zoho.com/crm/comparison.html",
     "q": "Audit Logs - Yes Yes Yes Yes Yes"
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "IN",
      "AU",
      "JP",
      "CA",
      "SA",
      "AE",
      "SG",
      "CN"
     ],
     "src": "https://www.zoho.com/know-your-datacenter.html",
     "q": "When you sign up for Zoho, you are given the option to choose the country from which you're signing up from."
    },
    "encryption": {
     "v": "AES-256 at rest for sensitive data; TLS 1.2/1.3 in transit; optional field-level encryption (Enterprise and up)",
     "src": "https://www.zoho.com/security.html",
     "q": "Sensitive customer data at rest is encrypted using 256-bit Advanced Encryption Standard (AES)."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": "full",
     "summary": "The Zoho CRM iPhone app keeps working on data stored on the device when connectivity drops, and changes sync to the online account automatically on reconnect.",
     "src": "https://help.zoho.com/portal/en/kb/crm/faqs/crm-for-mobile/iphone/articles/faqs-crm-for-iphone",
     "q": "You can continue to work on the local data stored in the device even when you lose connectivity to the internet."
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://play.google.com/store/apps/details?id=com.zoho.crm&hl=en_US",
     "q": "Zoho CRM - Sales & Marketing - Apps on Google Play"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": true,
     "src": "https://www.zoho.com/crm/comparison.html",
     "q": "Allowed IPs - Yes Yes Yes Yes Yes"
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "office",
     "text": "Zoho CRM admins can limit logins to office IPs per user, role or group, and the restriction then also applies to every other Zoho app those users sign in to.",
     "src": "https://help.zoho.com/portal/en/kb/crm/security-control/configure-allowed-ips/articles/configure-allowed-ips",
     "q": "Users can log in to Zoho CRM only from these allowed IPs added by the CRM administrator. This also applies to all the other Zoho products."
    },
    {
     "topic": "security",
     "text": "The Zoho datacenter (US, EU, India, Australia, Japan, Canada, Saudi Arabia, UAE, Singapore or China) is assigned from the country chosen at sign-up.",
     "src": "https://www.zoho.com/know-your-datacenter.html",
     "q": "Based on the country chosen there, the corresponding datacenter is chosen for your account."
    },
    {
     "topic": "security",
     "text": "Zoho CRM's HIPAA settings let admins mark health-data fields and block that data from exports and API access.",
     "src": "https://help.zoho.com/portal/en/kb/crm/faqs/hipaa/articles/faq-on-hipaa",
     "q": "In Personal Health Data Handling, toggle Restrict Data access through API, Restrict Data in Export, or both, as required."
    }
   ]
  },
  {
   "slug": "zoho-inventory",
   "name": "Zoho Inventory",
   "category": "Inventory Management",
   "checked": "2026-09-19",
   "scope": "Zoho Inventory (US edition). Certifications, SSO, encryption and data centers are stated Zoho-wide on zoho.com security/compliance pages.",
   "profile_url": "https://helpcompare.com/tools/zoho-inventory/#security-offline-remote",
   "trust_center": "https://www.zoho.com/security.html",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.zoho.com/compliance.html",
     "q": "Zoho is SOC 2 Type 2 compliant."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.zoho.com/compliance.html",
     "q": "Zoho has earned ISO/IEC 27001 certification for Applications, Systems, People, Technology, and Processes"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27701",
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO 9001",
      "ISO/IEC 20000-1",
      "ISO 22301",
      "SOC 1 Type 2",
      "SOC 2 + HIPAA Type 2",
      "Cyber Essentials Plus",
      "TX-RAMP",
      "ENS (Spain)"
     ],
     "src": "https://www.zoho.com/compliance.html",
     "q": "Zoho is certified with ISO/IEC 27017 - Information technology - Security techniques - Code of practice for information security controls"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.zoho.com/gdpr.html",
     "q": "If you are the organization administrator and would like to sign a DPA with us, please drop an email to legal@zohocorp.com"
    },
    "sso_saml": {
     "v": true,
     "src": "https://www.zoho.com/security.html",
     "q": "We also support SAML for single sign-on that makes it possible for customers to integrate their company's identity provider like LDAP,ADFS when they login to Zoho services"
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "src": "https://www.zoho.com/security.html",
     "q": "You can configure multi-factor authentication using Zoho One-Auth"
    },
    "audit_log": {
     "v": true,
     "src": "https://www.zoho.com/security.html",
     "q": "Detailed audit logging covering all update and delete operations performed by the user are available to the customers in every Zoho service."
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "IN",
      "AU",
      "JP",
      "CA",
      "SA",
      "AE",
      "SG",
      "CN"
     ],
     "src": "https://www.zoho.com/know-your-datacenter.html",
     "q": "When you sign up for Zoho, you are given the option to choose the country from which you're signing up from."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2/1.3 in transit",
     "src": "https://www.zoho.com/security.html",
     "q": "Sensitive customer data at rest is encrypted using 256-bit Advanced Encryption Standard (AES)."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS"
     ],
     "src": "https://apps.apple.com/us/app/zoho-inventory-inventory-app/id1477506694?mt=12",
     "q": "Zoho Inventory — Inventory App App - App Store"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://play.google.com/store/apps/details?id=com.zoho.inventory&hl=en_US",
     "q": "Inventory Management App -Zoho - Apps on Google Play"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": "The Windows app supports barcode scanners and RFID, weighing-scale integration and terminal payments; mobile apps scan barcodes with the phone.",
     "src": "https://www.zoho.com/us/inventory/windows-app/",
     "q": "Weighing Scale Integration Autofill items directly from your weighing scale."
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "Zoho Inventory users can be restricted by location or reporting tag, so staff at one warehouse only see that warehouse's data.",
     "src": "https://www.zoho.com/us/inventory/help/settings/users.html",
     "q": "You can invite team members, assign roles, and restrict access by location or reporting tag to keep information organised and secure."
    },
    {
     "topic": "office",
     "text": "The Windows app lets warehouse staff scan items into transactions with barcode scanners or RFID and sign in with Windows Hello.",
     "src": "https://www.zoho.com/us/inventory/windows-app/",
     "q": "Barcode Scanner and RFID Support Scan items into transactions."
    },
    {
     "topic": "remote",
     "text": "Free support is available 24 hours a day, 5 days a week; US phone line runs Monday–Friday 9 AM–9 PM ET.",
     "src": "https://www.zoho.com/us/inventory/pricing/",
     "q": "Monday - Friday (9:00 AM - 9:00 PM ET) Toll-free - 8443165544"
    },
    {
     "topic": "security",
     "text": "Only Admin-role users can start a full data backup, and a new backup can only be started every 15 days.",
     "src": "https://www.zoho.com/us/inventory/help/import-export/data-backup.html",
     "q": "Once you have initiated a backup, you can’t initiate another backup within the next 15 days."
    }
   ]
  },
  {
   "slug": "zoho-workplace",
   "name": "Zoho Workplace",
   "category": "Business Email & Office Suites",
   "checked": "2026-09-19",
   "scope": "Zoho Workplace and Zoho Mail plans (Free, Mail Lite, Mail Premium, Workplace Standard/Professional/Enterprise).",
   "profile_url": "https://helpcompare.com/tools/zoho-workplace/#security-offline-remote",
   "trust_center": "https://www.zoho.com/workplace/security.html",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.zoho.com/compliance.html",
     "q": "Zoho is SOC 2 Type 2 compliant. SOC 2 is an evaluation of the design and operating effectiveness of controls"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.zoho.com/compliance.html",
     "q": "ISO/IEC 27001 Steps to download Valid Upto : 21-Aug-2028"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "SOC 1 Type II",
      "ISO 9001",
      "ISO/IEC 20000-1",
      "ISO 22301",
      "PCI DSS (SAQ-D)",
      "CSA STAR Self-Assessment",
      "Cyber Essentials Plus",
      "TX-RAMP",
      "HDS",
      "ENS"
     ],
     "src": "https://www.zoho.com/compliance.html",
     "q": "ISO/IEC 27017 Steps to download Valid Upto : 21-Aug-2028 ... ISO/IEC 27701 Steps to download Valid Upto : 21-Aug-2028"
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://www.zoho.com/mail/hipaa.html",
     "q": "You can request our BAA template by sending an email to legal@zohocorp.com ."
    },
    "gdpr_dpa": {
     "src": "https://www.zoho.com/workplace/security.html",
     "q": "we’re compliant with GDPR"
    },
    "sso_saml": {
     "v": true,
     "plan": "Mail Lite",
     "src": "https://www.zoho.com/workplace/pricing.html",
     "q": "SAML based SSO integration Enable Single Sign-On for the Zoho Mail web application across various domains."
    },
    "scim": {
     "v": null
    },
    "mfa": {
     "v": true,
     "enforce": "Not plan-gated on the pages read (policy enforcement described generally)",
     "src": "https://www.zoho.com/mail/hipaa.html",
     "q": "The administrator can enforce and customize the following policies to suit their organization's compliance requirements: TFA/MFA Password policy Access control IP based restrictions"
    },
    "audit_log": {
     "v": true,
     "src": "https://www.zoho.com/mail/hipaa.html",
     "q": "Zoho Mail provides extensive audit logs to record the activities from the Admin Panel. The admin audit logs are available for a period of 1 year."
    },
    "data_residency": {
     "v": [
      "US",
      "EU",
      "IN",
      "AU",
      "JP",
      "CA",
      "SA",
      "AE",
      "SG",
      "CN"
     ],
     "src": "https://www.zoho.com/know-your-datacenter.html",
     "q": "When you sign up for Zoho, you are given the option to choose the country from which you're signing up from. ... Based on the country chosen there, the corresponding datacenter is chosen for your account."
    },
    "encryption": {
     "v": "Encrypted at rest and in transit (TLS; S/MIME and OpenPGP options); WorkDrive AES-256 at rest",
     "src": "https://www.zoho.com/mail/secure-email.html",
     "q": "Data is encrypted both at rest and in transit, leaving nothing to chance."
    },
    "self_host": {
     "src": "https://www.zoho.com/workplace/pricing.html",
     "q": "Virtual Private Cloud for isolated hosting"
    },
    "mode": {
     "v": "full",
     "summary": "The Trident desktop app lets users read, search, draft and organise email and edit tasks, notes and contacts offline, syncing when reconnected; the Writer desktop app edits cloud documents offline and syncs later.",
     "src": "https://help.zoho.com/portal/en/kb/trident/windows/faq-trident-windows/general-trident-windows/articles/can-i-work-offline-in-trident-windows",
     "q": "Draft new emails and replies and queue in Outbox (will be sent automatically when online)"
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://www.zoho.com/writer/desktop-app.html",
     "q": "feature-rich and secure desktop writing app optimized for Windows, Mac, and Linux devices."
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://apps.apple.com/us/app/zoho-mail-email-and-calendar/id909262651",
     "q": "Zoho Mail - Email and Calendar App - App Store"
    },
    "limits": {
     "v": "Trident offline data excludes email attachments not previously viewed; Trident is for paid and trial Zoho Mail/Workplace users.",
     "src": "https://help.zoho.com/portal/en/kb/trident/windows/faq-trident-windows/general-trident-windows/articles/can-i-work-offline-in-trident-windows",
     "q": "Email attachments are not downloaded and stored locally as part of Trident's offline data"
    },
    "ip_allowlist": {
     "v": true,
     "src": "https://www.zoho.com/mail/hipaa.html",
     "q": "The administrator can enforce and customize the following policies ... TFA/MFA Password policy Access control IP based restrictions"
    },
    "device_controls": {
     "v": true,
     "plan": "Mail Premium",
     "summary": "Mobile Access Management on Mail Premium and Workplace Professional; Workplace Enterprise adds endpoint control features; Zoho Directory device authentication (10 devices) on all paid plans.",
     "src": "https://www.zoho.com/workplace/pricing.html",
     "q": "Mobile Access Management"
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Zoho Meeting video conferencing allows up to 100 participants on Workplace Standard and 250 on Workplace Professional.",
     "src": "https://www.zoho.com/workplace/pricing.html",
     "q": "Video Conferencing Collaborate with your team in real-time using video, audio, and screen sharing Up to 100 participants Up to 250 participants"
    },
    {
     "topic": "security",
     "text": "Email retention and eDiscovery are only on Mail Premium and Workplace Professional, not on Mail Lite or Workplace Standard.",
     "src": "https://www.zoho.com/mail/hipaa.html",
     "q": "eDiscovery is available only in the premium plans of Zoho Mail."
    },
    {
     "topic": "offline",
     "text": "The Forever Free plan has no IMAP, POP or ActiveSync, so desktop mail clients and IMAP-based migrations out are not available on it.",
     "src": "https://www.zoho.com/workplace/pricing.html",
     "q": "IMAP/ POP/ Active Sync not included."
    },
    {
     "topic": "remote",
     "text": "Zoho's Microsoft 365 importer relies on Exchange Web Services; Zoho recommends finishing in-place archive migrations before October 1, 2026.",
     "src": "https://www.zoho.com/mail/help/adminconsole/o365-migration.html",
     "q": "If you plan to migrate in-place archive mailboxes from Microsoft 365 to Zoho Mail, we recommend completing the migration before October 1, 2026"
    }
   ]
  },
  {
   "slug": "zoom",
   "name": "Zoom",
   "category": "Video Conferencing",
   "checked": "2026-09-19",
   "scope": "Zoom Workplace commercial plans (Pro, Business, Business Plus, Enterprise). FedRAMP Moderate, GovRAMP and DoD IL4 apply to Zoom for Government, not commercial Zoom.",
   "profile_url": "https://helpcompare.com/tools/zoom/#security-offline-remote",
   "trust_center": "https://www.zoom.com/en/trust/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.zoom.com/en/trust/legal-compliance/",
     "q": "SOC 2 Type 2 report covering Security, Availability, Confidentiality, and Privacy"
    },
    "iso27001": {
     "v": true,
     "src": "https://www.zoom.com/en/trust/legal-compliance/",
     "q": "ISO 27001 Globally recognized security standard for implementing an ISMS"
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27017",
      "ISO/IEC 27018",
      "ISO/IEC 27701",
      "SOC 2 + HITRUST",
      "CSA STAR Level 2",
      "UK Cyber Essentials Plus",
      "IRAP",
      "ENS",
      "BSI C5",
      "ISMAP",
      "TX-RAMP",
      "HDS",
      "PCI DSS (Zoom Phone and Contact Center via PCIpal)",
      "FedRAMP Moderate (Zoom for Government)"
     ],
     "src": "https://www.zoom.com/en/trust/legal-compliance/",
     "q": "CSA STAR Level 2 Registry of security and compliance controls for cloud service offerings"
    },
    "hipaa": {
     "v": "BAA available",
     "src": "https://www.zoom.com/en/trust/legal-compliance/faq/",
     "q": "Yes, Zoom has a standard BAA that can be entered into when required by our customers."
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://www.zoom.com/en/trust/legal-compliance/faq/",
     "q": "Zoom’s Global Data Processing Addendum (DPA) can be accessed here"
    },
    "sso_saml": {
     "v": true,
     "plan": "Business",
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0065487",
     "q": "Business or Education account"
    },
    "scim": {
     "v": true,
     "plan": "Business",
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0058988",
     "q": "Business, Education, or Enterprise account with an approved Vanity URL"
    },
    "mfa": {
     "v": true,
     "enforce": "Pro",
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0064901",
     "q": "Sign in with two-factor authentication: Enable two-factor authentication for users."
    },
    "audit_log": {
     "v": true,
     "plan": "Pro",
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0067251",
     "q": "Admin activity logs allow account owners and other users with a customized role the ability to view changes made by admins on the account"
    },
    "data_residency": {
     "v": [
      "US",
      "AU",
      "BR",
      "CA",
      "DE",
      "JP",
      "SG",
      "MX",
      "CH"
     ],
     "plan": "Pro",
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0066473",
     "q": "All paid customers (including Pro) will be able to choose the storage location for some of their data for their account."
    },
    "encryption": {
     "v": "256-bit AES-GCM for meeting audio, video and shared content in transit by default; optional end-to-end encryption",
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0065408",
     "q": "By default, Zoom meetings and webinars use 256-bit AES GCM encryption for real-time audio, video, and shared content in transit between participants using the Zoom client."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": [
      "Windows",
      "macOS",
      "Linux"
     ],
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0060748",
     "q": "Zoom system requirements: Windows, macOS, Linux"
    },
    "mobile": {
     "v": [
      "iOS",
      "Android"
     ],
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0061734",
     "q": "Zoom system requirements: iOS, iPadOS, and Android"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": true,
     "plan": "Pro",
     "summary": "Account security settings include automatic sign-out after a set time and re-authentication after inactivity.",
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0064901",
     "q": "Automatically sign users out after a specified time"
    },
    "office_hardware": {
     "v": "Zoom Rooms runs conference rooms and shared desks on Zoom Certified Hardware from major vendors, and Direct Guest Join lets rooms join other platforms' meetings.",
     "src": "https://www.zoom.com/en/products/meeting-rooms/",
     "q": "Deliver seamless, high-quality video collaboration experiences with Zoom Certified Hardware tested for compatibility and connectivity with major hardware vendors."
    }
   },
   "facts": [
    {
     "topic": "remote",
     "text": "Zoom recommends 3.8 Mbps up / 3.0 Mbps down per user for 1080p group video.",
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0060748",
     "q": "For 1080p HD video: 3.8Mbps/3.0Mbps (up/down)"
    },
    {
     "topic": "office",
     "text": "Zoom Rooms can join meetings on other major video platforms via Direct Guest Join and Conference Room Connector.",
     "src": "https://www.zoom.com/en/products/meeting-rooms/",
     "q": "Use Direct Guest Join and Conference Room Connector to instantly jump into meetings on any major video platform."
    },
    {
     "topic": "security",
     "text": "Turning on end-to-end encryption disables cloud recording, AI features and live transcription for that meeting.",
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0065408",
     "q": "Enabling E2EE will disable the following in-meeting features: Zoom AI features, Cloud recording, Meeting chat before and after the meeting, Live streaming, Live transcription"
    },
    {
     "topic": "security",
     "text": "Admins on Pro and higher can restrict meeting-summary access to specific IP ranges (a feature-level control, not a sign-in allowlist).",
     "src": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0078420",
     "q": "When enabled, it allows meeting summary access only from specific IP address ranges."
    }
   ]
  },
  {
   "slug": "zoominfo",
   "name": "ZoomInfo",
   "category": "Sales Intelligence & B2B Data",
   "checked": "2026-09-19",
   "scope": "ZoomInfo SalesOS / GTM platform. ZoomInfo's help center requires a customer login, so plan-level availability of admin controls could not be verified.",
   "profile_url": "https://helpcompare.com/tools/zoominfo/#security-offline-remote",
   "trust_center": "https://trust.zoominfo.com/",
   "fields": {
    "soc2": {
     "v": "Type II",
     "src": "https://www.zoominfo.com/legal/security-overview",
     "q": "ZoomInfo is ISO 27001, ISO 27701, TRUSTe, and SOC 2 Type II certified."
    },
    "iso27001": {
     "v": true,
     "src": "https://www.zoominfo.com/legal/security-overview",
     "q": "ZoomInfo is ISO 27001, ISO 27701, TRUSTe, and SOC 2 Type II certified."
    },
    "other_certs": {
     "v": [
      "ISO/IEC 27701",
      "ISO/IEC 27017",
      "CSA STAR Level 1",
      "TRUSTe Enterprise Privacy Certification"
     ],
     "src": "https://trust.zoominfo.com/",
     "q": "TRUSTe Enterprise Privacy Certification EU-US Data Privacy Framework Swiss-US Privacy Shield CSA star level 1 ISO 27017 ISO 27001:2013 ISO 27701"
    },
    "hipaa": {
     "v": null
    },
    "gdpr_dpa": {
     "v": true,
     "src": "https://trust.zoominfo.com/controls",
     "q": "ZoomInfo has a data processing addendum outlining its terms for the processing of personal data."
    },
    "sso_saml": {
     "v": true,
     "src": "https://trust.zoominfo.com/controls",
     "q": "Users can sign into the product using security assertion markup language (SAML) single sign-on (SSO)."
    },
    "scim": {
     "v": true,
     "src": "https://trust.zoominfo.com/controls",
     "q": "The product uses the system for cross-domain identity management (SCIM) for user management."
    },
    "mfa": {
     "v": true,
     "src": "https://trust.zoominfo.com/controls",
     "q": "Multi-Factor Authentication Currently supports: SMS Text and smartphone app (Android and IOS)"
    },
    "audit_log": {
     "v": null
    },
    "data_residency": {
     "v": [
      "US"
     ],
     "src": "https://www.zoominfo.com/legal/security-overview",
     "q": "Our services are hosted on the three major cloud providers with hosting data centers in the U.S."
    },
    "encryption": {
     "v": "AES-256 at rest; TLS 1.2 minimum in transit",
     "src": "https://www.zoominfo.com/legal/security-overview",
     "q": "Customer data is encrypted at rest using AES256 and browser client communication is encrypted with a minimum of Transport Layer Security (TLS 1.2)."
    },
    "self_host": {
     "v": null
    },
    "mode": {
     "v": null
    },
    "desktop": {
     "v": null
    },
    "mobile": {
     "v": [
      "iOS"
     ],
     "src": "https://apps.apple.com/us/app/zoominfo/id1493170277",
     "q": "Zoominfo customers, download the ZoomInfo Mobile App and make it your trusty sales travel companion!"
    },
    "limits": {
     "v": null
    },
    "ip_allowlist": {
     "v": null
    },
    "device_controls": {
     "v": null
    },
    "office_hardware": {
     "v": null
    }
   },
   "facts": [
    {
     "topic": "security",
     "text": "ZoomInfo customer data is hosted only in U.S. data centers; no EU or other regional hosting option is published.",
     "src": "https://www.zoominfo.com/legal/security-overview",
     "q": "Our services are hosted on the three major cloud providers with hosting data centers in the U.S."
    },
    {
     "topic": "security",
     "text": "Customer roles are limited to two built-in types, administrator and user.",
     "src": "https://trust.zoominfo.com/controls",
     "q": "For ZoomInfo customers, there are two roles with distinct permissions and access rights: administrator and user."
    },
    {
     "topic": "remote",
     "text": "The iOS app is included for all ZoomInfo customers for looking up company data and prepping meetings on the road.",
     "src": "https://apps.apple.com/us/app/zoominfo/id1493170277",
     "q": "Available for all Zoominfo customers."
    }
   ]
  }
 ]
}