Procurement

Procurement & security questionnaire

A concise, honest summary designed for procurement reviewers. Where a control is in development or not applicable, that status is stated explicitly rather than obscured.

In Development

Summary

  • Product. SalesOps is a B2B CRM and outside-sales productivity platform.
  • Deployment model. Multi-tenant SaaS on managed cloud infrastructure.
  • Primary data region. Germany (EU).
  • Certifications. No independent third-party certifications held by SalesOps at this time.
  • Sensitive data. SalesOps is not designed for health, biometric, financial-account, or government-ID information.
  • AI features. Draft and recommendation tools with human review. Never send email or place calls autonomously.
Enterprise customers requiring a countersigned DPA, defined uptime SLA, or completed vendor questionnaire in your preferred format can request them from info@salesops.ca.

How to use this page

Each response below is scoped to what SalesOps can substantiate today. Status badges distinguish current controls from items that are in development, planned, or available by agreement. Nothing on this page constitutes a warranty or replaces the contractual terms of a signed agreement.

Questionnaire responses

Company & governance

  • Legal entity and jurisdiction?

    Yes

    SalesOps is a sole proprietorship based in Sudbury, Ontario, Canada. Governing jurisdiction is Ontario, Canada.

  • Do you have an executed written information-security policy?

    In Development

    Foundational internal policies exist; a formal, versioned policy set is in development and will be shared with enterprise customers under NDA once finalized.

  • Do you hold SOC 2, ISO 27001, or PCI DSS certifications?

    No

    No third-party certification is held at this time. We describe underlying controls factually and reference the certifications of our platform providers.

Data handling

  • Where is customer data stored?

    Current Control

    Primary database region: Germany (EU). Additional subprocessors may process data in other regions as disclosed at /legal/subprocessors.

  • Is data encrypted in transit and at rest?

    Current Control

    TLS in transit for all application and API traffic. At-rest encryption provided by the managed database and storage provider using provider-managed keys.

  • Do you offer customer-managed encryption keys (BYOK / HYOK)?

    No

    Not offered.

  • Do you sell customer data or use it to train shared models?

    No

    No. See /trust/responsible-ai and /legal/ai-usage.

  • Do you support customer-initiated data export and deletion?

    Current Control

    Yes. Workspace administrators can export data and request permanent deletion.

Access & authentication

  • Password and SSO options?

    Current Control

    Email/password and Google SSO are supported today. Enterprise SSO (SAML) is planned.

  • Multi-factor authentication?

    Planned

    User-configurable MFA is planned.

  • Role-based access inside a workspace?

    Current Control

    Admin, Manager, and Rep roles with workspace-scoped authorization on every read and write.

Operations

  • Backup frequency and retention?

    Current Control

    Managed provider point-in-time recovery, retained for approximately one month.

  • Documented disaster-recovery runbook?

    In Development

    In development; runs on managed cloud services that provide default resilience.

  • Contractual uptime SLA?

    Available by Agreement

    Not published for self-serve plans. Enterprise agreements may set a defined uptime commitment and service credits.

  • Incident notification?

    Policy Commitment

    SalesOps commits to notify affected customers of confirmed security incidents without unreasonable delay.

Software development

  • Change management?

    Current Control

    Continuous integration, code review, and staged deploys.

  • Static application security testing (SAST)?

    In Development

    Being integrated into CI.

  • Third-party penetration testing?

    Planned

    On the roadmap. Not conducted at this time.

  • Dependency management?

    Current Control

    Automated dependency updates with review before merge.

Vendor management

  • Subprocessor transparency?

    Current Control

    Public list at /legal/subprocessors, updated when new providers are engaged.

  • Data Processing Addendum?

    Available by Agreement

    Template published at /legal/dpa; countersignable copy available on request from enterprise customers.

  • Standard Contractual Clauses for international transfers?

    Policy Commitment

    Relied on where applicable, including the EU 2021 SCCs and the UK IDTA.

Documents available on request

  • SalesOps Trust Brief (PDF) — a one-page procurement summary generated from this Trust Center. Download without contacting sales.
  • Countersigned Data Processing Addendum (see /legal/dpa).
  • SalesOps completed CAIQ-Lite or customer-specific vendor questionnaire.
  • Subprocessor list with data categories and regions (public copy at /legal/subprocessors).
  • Insurance summary and business-continuity notes (enterprise, under NDA).

Procurement contact

Every procurement inquiry routes through info@salesops.ca. Please include your legal entity, target workspace size, and any timing constraints.

Information provided in the SalesOps Trust Center is for general informational purposes and does not constitute legal advice. Contractual commitments applicable to a particular customer are governed by that customer's executed agreement with SalesOps. SalesOps is a sole proprietorship based in Sudbury, Ontario, Canada.