GTMGTM

Security & compliance

Compliance is architecture here, not a policy document

Sourcing leads ourselves makes us a controller in our own right rather than merely your processor. That is a deliberate choice with a real cost, and it drives six things that cannot be retrofitted onto a tool that started life as a sequencer.

100%
Of sends carry a gate verdict
us-east-2
Where the data lives
Scoped
Model inputs and operational reporting
Daily
Retention purge

Where the certifications actually stand

SOC 2 Type IIIn progress

Programme underway. We are not certified yet.

ISO 27001In progress

Working toward it. Not certified yet.

GDPRIn progress

Data model built to it. We serve the US today.

CCPAIn progress

Controls being verified against it.

We hold none of these yet. Three are programmes we are working toward and one is a regulation whose data model we built to before we had a customer in it. Nothing on this page carries a certifying body’s seal, because putting one there before the audit would be the first thing this site ever got wrong. When each lands, this block changes and the changelog says so.

The gate is a database constraint

An outbound row cannot reach sent without a compliance verdict and an unsubscribe URL. That is a constraint on the table rather than a branch in the code, so a bug in the sending path fails loudly as a violation instead of quietly as a delivered email. It is the single most load-bearing decision in the product.

Provenance on every field

Source system, collection method and collection date, written at the moment a record is created rather than reconstructed later. It is what makes a deletion request answerable and a retention rule computable, and it cannot be added retroactively to records that never stored it.

Retention anchored to collection

Never to last-updated. Anchoring to last-updated means an actively used record never expires, which is the exact finding that produced a €240,000 fine for one lead-generation company. The purge runs daily and batched.

Suppression survives every purge

At workspace scope for people who told you specifically, and at platform scope for anyone who should never hear from the system again. Both are exempt from retention deletion, because a suppression list a purge can empty is a list that eventually mails somebody who asked you not to.

The footer is injected by the transport

Unsubscribe link and postal address are added where the send happens, not by the caller, because a caller able to omit them eventually will. Both email transports refuse a send without them.

Relevant data for model tasks

Qualification, writing and reply review may send contact details and conversation content to model providers. See the subprocessor page for the data flow. Operational alerts and CSP reports exclude message bodies, credentials and full request URLs.

The gate

Checks apply in every sending mode

Autopilot sends eligible messages automatically. Supervised campaigns hold steps for review. Both paths use the same sender, allowance, suppression and compliance checks; approving a draft does not bypass them.

JurisdictionEntity typeLawful basis
How the gate works
Outbound14,208

Outbound row · pre-send evaluation

JurisdictionUS · CAN-SPAM
Entity typeBusiness contact
Lawful basisLegitimate interest, documented
SuppressionNo match at workspace or platform scope
Unsubscribe URLInjected by the transport
Postal addressInjected by the transport
Verdict: allow. Written to the row before the send.

messages_outbound_sent_was_gated. A row cannot reach sent without a verdict and an unsubscribe URL.

Posture

What we claim, and what we do not

A security page that only lists strengths is a security page you have to read twice. This is the whole posture, including the parts a procurement team will dislike.

Data residency
United States, us-east-2
SOC 2 Type II
Programme underway, not certified
ISO 27001
Not held
HIPAA
Not in scope
GDPR
Data model built to it; US-only today
CAN-SPAM
Enforced, not configurable
Tenancy
Row-level security from the first migration
Model processing
Provider and account controls
Bug bounty
Not yet. Disclosure by email

Tenant isolation

A client workspace is a container

Not a filter on a shared list. The sender picker only ever sees the queue row’s own workspace plus the org-level pool you explicitly shared, and the same rule decides which account a search runs from. There is no code path from one client’s queue to another’s sender.

  • Row-level security on every table, from its first migration
  • Connections assigned per workspace, never inherited by accident
  • Sourcing searches from that client's own connected account
  • Audit log across membership, connector and agent changes

Security questions, answered without hedging

Are you SOC 2 or ISO 27001 certified?

No. Both are programmes we are working toward and neither is finished. If your procurement needs a signed report today we are the wrong choice this quarter, and we would rather say that now than during the review.

Where is customer data stored?

The United States, in us-east-2, chosen explicitly rather than defaulted into. We claim no EU residency and no adequacy decision.

How is access to my workspace controlled?

Row-level security on every table from its first migration, and every scoped token carries the authorising person's own permissions rather than the workspace's. Re-read from your membership on each call, so revoking access takes effect immediately rather than when a token expires.

What happens to a LinkedIn password?

It is read from the request, forwarded to the connection vendor within that same request, and goes out of scope. Never persisted, never logged, never returned. LinkedIn offers no OAuth, which is why a credential form exists at all.

Can an agent be talked into doing something it should not?

Prompt injection arriving through a contact record, an agent prompt or an inbound reply can at worst name a tool that does not exist. The belt is an allowlist built from your own membership, checked when the tool list is assembled and again at execution, and nothing in any belt can send a message to a prospect.

Do you train models on my data?

TryGTM requests inference routing that excludes provider data collection. Model inputs can include contact details and conversation content. Retention depends on the selected provider and account configuration; contact us to confirm the terms required for your workspace.

How do I report a vulnerability?

Email support@trygtm.com with the affected feature and reproduction steps, without credentials or customer content. We do not currently run a bug bounty.

Bring your security review. We would rather have it early.

Send the questionnaire to support and a person who wrote the code answers it, rather than a template that answers around it.

SOC 2 programme underway. We say where it stands rather than implying a badge.