Apollo.io security review: SOC 2, AI training & subprocessors

What Apollo.io publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.

Transparency score
70/100
SOC 2
SOC 2 Type II
ISO 27001
Claimed
Trains AI on your data?
See quotes
Subprocessors
Not found

"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.

Does Apollo.io train AI on your data?

Statements differ between pages

Apollo.io's own words (apollo.io/ai-policy):

Apollo will never share Customer Data with third-party providers for the purposes of algorithm training or model enhancement without first disclosing it to customers and obtaining customer consent.

Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.

Other statements we found
Apollo may use Customer Data (as defined in Apollo’s Terms of Service) and its proprietary data as inputs to train these internal models to provide more accurate and relevant recommendations.
apollo.io/ai-policy
For clarity, Apollo will not share Customer Data with any third party for the purpose of training such third party's artificial intelligence or machine learning models.
apollo.io/terms

Different pages say different things. This is often a split between business plans and free or consumer plans. Read each quote for the plan you would use.

Certifications Apollo.io claims

Certification or reportMentioned on
SOC 2 Type IIapollo.io
ISO/IEC 27001apollo.io
PCI DSSapollo.io

Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA, EU-U.S. Data Privacy Framework. These are laws the vendor says it follows, not certifications.

A certification on a website is a claim. For anything sensitive, ask Apollo.io for the SOC 2 report or ISO certificate.

Apollo.io subprocessors

Our reader didn't find a subprocessor list on Apollo.io's public pages. It may be published somewhere we couldn't reach, such as a trust portal that needs JavaScript or a login. Ask Apollo.io for it if you need it.

Security features mentioned

SSO / SAMLNot found
SCIM provisioningNot found
Multi-factor authenticationNot found
Encryption at restNot found
Encryption in transitNot found
Penetration testingNot found
Bug bounty / disclosure programNot found
Audit logsNot found
Data residencyNot found
security.txt contactNot found

Key documents

Trust / security centertrust.apollo.io
Privacy policyapollo.io/privacy-policy
Subprocessor listNot found
Data processing agreement (DPA)apollo.io/dpa
AI policyapollo.io/ai-policy
Termsapollo.io/terms
Status pageNot found

How this score is worked out

CheckPointsResult
Security or trust page15Yes
Certifications listed20Yes
Privacy policy10Yes
Subprocessor list15No
DPA available10Yes
AI training policy stated15Yes
security.txt contact5No
Status page10No

The score measures how much of a standard security review our reader could answer from Apollo.io's public pages. It is not a rating of how secure Apollo.io is, and a "No" can mean the document exists where our reader couldn't see it.

Check another vendor

Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.

Other CRM & support vendors

Attio · Chili Piper · Clay · Close · Drift · Gorgias · Help Scout · HubSpot · Intercom · Kustomer · Outreach · Pipedrive

Source: Apollo.io's own public website (6 pages read on October 10, 2026). Stormap is not affiliated with Apollo.io. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.