Skip to main content

Security

You're about to connect us to your live CRM. Here's what that means.

Closin reads the system your revenue runs on, which makes this a fair question to ask early and in detail. Everything below is what we can state plainly today — not a roadmap.

The short version

Four things a reviewer usually asks first.

  • Dedicated infrastructure per customer — no cross-tenant co-mingling.
  • Zero-retention terms with our LLM providers; your data never trains a shared model.
  • SOC 2 Type 2, audited by an independent third party.
  • Scoped OAuth into Salesforce or HubSpot, revocable by you at any time.

Tenancy and data residency

Your data stays in your own tenant.

Most platforms in this category are multi-tenant by default: your records and every other customer's share a database, separated by a column and the correctness of every query written against it. Closin runs dedicated infrastructure per customer instead, so the isolation is structural rather than conditional on application logic.

What we state

In your own tenant. Closin runs on dedicated infrastructure per customer, with no co-mingling across tenants. We read your CRM through a scoped OAuth integration; we never screenshot, scrape, or store credentials outside your CRM's own grant.

AI and model training

Your records answer your questions. Nothing else.

Coffee reads your live CRM to answer questions, and every answer cites the record it came from. The question a security reviewer actually cares about is what happens to that data after the answer is returned.

What we state

No. Your records answer your team's questions; they never train any shared model. Our LLM providers operate under zero-retention terms, confirmable in your contract.

Certification and testing

SOC 2 Type 2, audited independently.

Type 2 means the controls were observed operating over a period, not attested at a single point in time. We share the report and our completed security questionnaire under NDA, before a technical evaluation rather than after it.

What we state

Closin is SOC 2 Type 2 certified, audited by an independent third party. Annual pen testing is scheduled. We share the report and our security questionnaire response under NDA before any technical evaluation.

CRM access

Scoped OAuth. No credentials, no scraping.

Closin connects through your CRM's own OAuth grant, which means access is scoped, visible in your CRM's admin console, and revocable by you at any time without involving us. We never screenshot, scrape, or store credentials outside that grant.

What we state

Salesforce and HubSpot today, with more added every quarter. Our data model is CRM-agnostic; only the OAuth scope and field mapping change per CRM. If your stack isn't supported yet, tell us. The roadmap is buyer-led.

Anything not covered here

Ask a person.

If your review needs something this page doesn't cover, the answer comes from the founding team rather than from a document that overstates. We share the SOC 2 report and our security questionnaire response under NDA before any technical evaluation begins. founders@closin.ai

Less firefighting. More building.

Start with a read-only diagnosis.

The assessment connects through a scoped grant and produces a written read on where your revenue system leaks. Your security team can review the connection before anything is built.