Gong security review: SOC 2, AI training & subprocessors

What Gong publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.

Transparency score
95/100
SOC 2
SOC 2 Type II
ISO 27001
Claimed
Trains AI on your data?
See quotes
Subprocessors
9 listed

"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.

Does Gong train AI on your data?

Statements differ between pages

Gong's own words (gong.io/platform/trust):

Understand how insights are generated — and trust that your data is never used to train generative models.

Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.

Other statements we found
Is customer data used to train generative AI?
gong.io/platform/trust
Your data is never used to train generative AI models, and it’s never shared with or exposed to the public domain.
gong.io/platform/trust

Different pages say different things. This is often a split between business plans and free or consumer plans. Read each quote for the plan you would use.

Certifications Gong claims

Certification or reportMentioned on
SOC 2 Type IIgong.io/platform/trust
ISO/IEC 27001gong.io/platform/trust
ISO/IEC 27017gong.io/platform/trust
ISO/IEC 27018gong.io/platform/trust
ISO/IEC 27701gong.io/platform/trust
ISO/IEC 42001gong.io/platform/trust
HIPAAgong.io/platform/trust
PCI DSSgong.io/platform/trust

Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA, EU-U.S. Data Privacy Framework. These are laws the vendor says it follows, not certifications.

A certification on a website is a claim. For anything sensitive, ask Gong for the SOC 2 report or ISO certificate.

Gong subprocessors

Gong lists 9 subprocessors on gong.io/legal/sub-processors:

Security features mentioned

SSO / SAMLNot found
SCIM provisioningNot found
Multi-factor authenticationMentioned
Encryption at restNot found
Encryption in transitMentioned
Penetration testingNot found
Bug bounty / disclosure programNot found
Audit logsMentioned
Data residencyNot found
security.txt contactNot found

Key documents

Trust / security centergong.io/platform/trust
Privacy policygong.io/legal/privacy-policy
Subprocessor listgong.io/legal/sub-processors
Data processing agreement (DPA)gong.io/legal/data-processing-addendum
AI policygong.io/blog/ai-governance-operating-discipline
TermsNot found
Status pagestatus.gong.io

How this score is worked out

CheckPointsResult
Security or trust page15Yes
Certifications listed20Yes
Privacy policy10Yes
Subprocessor list15Yes
DPA available10Yes
AI training policy stated15Yes
security.txt contact5No
Status page10Yes

The score measures how much of a standard security review our reader could answer from Gong's public pages. It is not a rating of how secure Gong is, and a "No" can mean the document exists where our reader couldn't see it.

Check another vendor

Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.

Other Communication vendors

Aircall · Braze · Customer.io · Dialpad · Discord · Front · Klaviyo · Mailchimp · Postmark · RingCentral · SendGrid · Slack

Source: Gong's own public website (6 pages read on October 10, 2026). Stormap is not affiliated with Gong. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.