Security

Built for the rep, hardened for the VP doing diligence.

A privacy-conscious VP doing diligence on a vendor that reads their team's data should walk away comfortable. Here's how we earn that.

Encrypted in transit and at rest

TLS 1.3 in transit. AES-256 at rest. Every connection between Bonggy and your CRM, sequencer, email, and the other tools it reads is encrypted end to end.

Scoped, read-only permissions

We request only the permissions needed to read the effort your team already logs. Bonggy doesn't write back, send, or act on your reps' behalf.

No training on your data

Your account context, contact lists, and notes do not train any foundation model or get pooled across customers. Anything we tune runs on your tenant.

Read-only by design

Bonggy reads and aligns effort — it never sends, sequences, or acts. Nothing leaves your domain, because Bonggy isn't the one doing the sending.

Data residency and retention

Data lives in your chosen region. You can export everything at any time. If you cancel, we offer a 30-day grace period before deletion. You own your data.

Compliance roadmap

SOC 2 Type II is on the path for our first enterprise cohort. If your procurement requires it ahead of pilot, email founders@bonggy.com and we'll share the current trust documentation and our attestation timeline.