Security & compliance
Compliance is architecture here, not a policy document
Sourcing leads ourselves makes us a controller in our own right rather than merely your processor. That is a deliberate choice with a real cost, and it drives six things that cannot be retrofitted onto a tool that started life as a sequencer.
- 100%
- Of sends carry a gate verdict
- us-east-2
- Where the data lives
- Scoped
- Model inputs and operational reporting
- Daily
- Retention purge
Where the certifications actually stand
Programme underway. We are not certified yet.
Working toward it. Not certified yet.
Data model built to it. We serve the US today.
Controls being verified against it.
We hold none of these yet. Three are programmes we are working toward and one is a regulation whose data model we built to before we had a customer in it. Nothing on this page carries a certifying body’s seal, because putting one there before the audit would be the first thing this site ever got wrong. When each lands, this block changes and the changelog says so.
The gate is a database constraint
An outbound row cannot reach sent without a compliance verdict and an unsubscribe URL. That is a constraint on the table rather than a branch in the code, so a bug in the sending path fails loudly as a violation instead of quietly as a delivered email. It is the single most load-bearing decision in the product.
Provenance on every field
Source system, collection method and collection date, written at the moment a record is created rather than reconstructed later. It is what makes a deletion request answerable and a retention rule computable, and it cannot be added retroactively to records that never stored it.
Retention anchored to collection
Never to last-updated. Anchoring to last-updated means an actively used record never expires, which is the exact finding that produced a €240,000 fine for one lead-generation company. The purge runs daily and batched.
Suppression survives every purge
At workspace scope for people who told you specifically, and at platform scope for anyone who should never hear from the system again. Both are exempt from retention deletion, because a suppression list a purge can empty is a list that eventually mails somebody who asked you not to.
The footer is injected by the transport
Unsubscribe link and postal address are added where the send happens, not by the caller, because a caller able to omit them eventually will. Both email transports refuse a send without them.
Relevant data for model tasks
Qualification, writing and reply review may send contact details and conversation content to model providers. See the subprocessor page for the data flow. Operational alerts and CSP reports exclude message bodies, credentials and full request URLs.
The gate
Checks apply in every sending mode
Autopilot sends eligible messages automatically. Supervised campaigns hold steps for review. Both paths use the same sender, allowance, suppression and compliance checks; approving a draft does not bypass them.
Outbound row · pre-send evaluation
messages_outbound_sent_was_gated. A row cannot reach sent without a verdict and an unsubscribe URL.
Posture
What we claim, and what we do not
A security page that only lists strengths is a security page you have to read twice. This is the whole posture, including the parts a procurement team will dislike.
- Data residency
- United States, us-east-2
- SOC 2 Type II
- Programme underway, not certified
- ISO 27001
- Not held
- HIPAA
- Not in scope
- GDPR
- Data model built to it; US-only today
- CAN-SPAM
- Enforced, not configurable
- Tenancy
- Row-level security from the first migration
- Model processing
- Provider and account controls
- Bug bounty
- Not yet. Disclosure by email
Tenant isolation
A client workspace is a container
Not a filter on a shared list. The sender picker only ever sees the queue row’s own workspace plus the org-level pool you explicitly shared, and the same rule decides which account a search runs from. There is no code path from one client’s queue to another’s sender.
- Row-level security on every table, from its first migration
- Connections assigned per workspace, never inherited by accident
- Sourcing searches from that client's own connected account
- Audit log across membership, connector and agent changes

Security questions, answered without hedging
Are you SOC 2 or ISO 27001 certified?
No. Both are programmes we are working toward and neither is finished. If your procurement needs a signed report today we are the wrong choice this quarter, and we would rather say that now than during the review.
Where is customer data stored?
The United States, in us-east-2, chosen explicitly rather than defaulted into. We claim no EU residency and no adequacy decision.
How is access to my workspace controlled?
Row-level security on every table from its first migration, and every scoped token carries the authorising person's own permissions rather than the workspace's. Re-read from your membership on each call, so revoking access takes effect immediately rather than when a token expires.
What happens to a LinkedIn password?
It is read from the request, forwarded to the connection vendor within that same request, and goes out of scope. Never persisted, never logged, never returned. LinkedIn offers no OAuth, which is why a credential form exists at all.
Can an agent be talked into doing something it should not?
Prompt injection arriving through a contact record, an agent prompt or an inbound reply can at worst name a tool that does not exist. The belt is an allowlist built from your own membership, checked when the tool list is assembled and again at execution, and nothing in any belt can send a message to a prospect.
Do you train models on my data?
TryGTM requests inference routing that excludes provider data collection. Model inputs can include contact details and conversation content. Retention depends on the selected provider and account configuration; contact us to confirm the terms required for your workspace.
How do I report a vulnerability?
Email support@trygtm.com with the affected feature and reproduction steps, without credentials or customer content. We do not currently run a bug bounty.
Bring your security review. We would rather have it early.
Send the questionnaire to support and a person who wrote the code answers it, rather than a template that answers around it.
SOC 2 programme underway. We say where it stands rather than implying a badge.