Policies

    Security

    Last updated: May 14, 2026

    Security is foundational to Databook. Our platform is built and operated to meet the expectations of the world’s largest enterprise revenue teams, with controls designed for confidentiality, integrity, and availability.

    Compliance and certifications

    Databook maintains SOC 2 Type II attestation, supports GDPR and CCPA obligations, and aligns to NIST CSF and ISO 27001 control families. Customer-specific audit support is available under NDA.

    Infrastructure

    The Databook platform runs on hardened cloud infrastructure with isolated environments, network segmentation, and encrypted storage. Production access is limited to authorized personnel and protected by SSO, MFA, and least-privilege role-based access controls.

    Data protection

    Customer data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Customer-managed encryption keys are available for qualifying enterprise plans. Data is logically separated by customer tenant.

    Identity and access

    Databook supports SAML SSO, SCIM provisioning, MFA enforcement, and granular role-based access controls inside the product, plus a full administrative audit log.

    Monitoring and incident response

    We operate 24/7 monitoring, vulnerability management, and an incident response program with defined severity tiers, notification commitments, and post-incident review.

    Responsible disclosure

    Researchers who identify potential vulnerabilities can disclose them confidentially to security@databook.com. We commit to acknowledging reports promptly and working in good faith to remediate validated issues.

    Content for this policy is a working draft and will be replaced with finalized legal language. For questions, please contact legal@databook.com.