Gong logo

Gong

Revenue intelligence platform that captures and analyzes customer interactions across calls, email, and messaging.

✓ 14 of 32 frameworks
Security & General Standards
SOC 2 Type II

SOC 3
?

Not publicly documented

SOC 1 Type II

ISO 27001 (Information Security Management)

ISO/IEC 27001:2022

ISO 27017 (Cloud Security)

ISO 27018 (Cloud Privacy)

ISO 27701 (Privacy Information Management)

ISO 42001 (AI Management Systems)

ISO/IEC 42001:2023

ISO 9001 (Quality Management)

CSA STAR (Cloud Security Alliance)

HITRUST CSF

BSI C5 (German Cloud Security)

Privacy & Data Transfer
GDPR (EU)

CCPA / CPRA (California)

UK GDPR

LGPD (Brazil)
?

Not publicly documented

PIPEDA (Canada)
?

Not publicly documented

DPDP Act (India)
?

Not publicly documented

PIPL (China)
?

Not publicly documented

EU-US Data Privacy Framework

Swiss-US Data Privacy Framework

Not publicly documented

Global CBPR (APEC)

Global PRP (APEC)

Industry & Government
HIPAA (US Healthcare)

Health information privacy program; BAA available

PCI DSS (Payment Card Industry)

PCI DSS SAQ D

FedRAMP (US Federal)

StateRAMP / TX-RAMP (US State)

DORA (EU Finance)
?

Not publicly documented

CJIS (US Law Enforcement)

FINRA (US Broker-Dealers)

IRAP (Australian Government)

Emerging & Strategic
NIST CSF (Cybersecurity Framework)
?

Not publicly documented

Data last verified: September 2026

Is this data outdated?

Spotted an error or a recent change in Gong's posture? Submit a correction.

Submit a correction →

Work at Gong?

Claim this profile to verify and enrich your compliance data.

Claim this profile →
← All Sales & CRM tools

Data sourced from public trust centers. Not legal or compliance advice.

Logos and trademarks are property of their respective owners. Use does not imply endorsement, affiliation, or sponsorship.

© Compliance Posture 2026