Gong
Security and trust center evidence
Gong Revenue AI OS helps your entire GTM organization
Summary
Gong has 10 vendor-stated rows in the CertReports index, last verified 19 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
Gong states it holds that it will sign a business associate agreement. Gong states it holds a SOC 2 Type II report. Gong states it holds a data processing agreement. Gong states it holds a PCI DSS attestation of compliance.
- HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured) (as of 19 Sep 2026)
- SOC 2: Vendor states SOC 2 on its trust centre (as of 19 Sep 2026)
- GDPR: Vendor states GDPR on its trust centre (as of 19 Sep 2026)
Facts only, each dated; nothing here is inferred, scored or advised.
Evidence count
0verified rows
Compliance grid
- HIPAAVendor-stated
Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)
as of 19 Sep 20261 source
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 19 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 19 Sep 20261 source
PCI DSSVendor-statedVendor states PCI DSS on its trust centre
as of 19 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001 on its trust centre
as of 19 Sep 20261 source- CSA STARVendor-stated
Vendor states CSA STAR on its trust centre
as of 19 Sep 20261 source
ISO/IEC 27701Vendor-statedVendor states ISO/IEC 27701 on its trust centre
as of 19 Sep 20261 source
ISO/IEC 42001Vendor-statedVendor states ISO/IEC 42001:2023 on its trust centre
as of 19 Sep 20261 source
ISO/IEC 27017Vendor-statedVendor states ISO/IEC 27017:2015 on its trust centre
as of 19 Sep 20261 source
ISO/IEC 27018Vendor-statedVendor states ISO/IEC 27018:2019 on its trust centre
as of 19 Sep 20261 source
No public evidence yet for FedRAMP, Cyber Essentials. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this. Check the vendor trust centre.
Subprocessors
No subprocessor list captured yet.