Skip to main content

Security and privacy FAQs

Answers to the most common questions about how Databook protects your data, backed by independent audits and enterprise-grade controls

Written by Alex

Databook is built to enterprise security, privacy, and compliance standards. It's independently audited, and its controls are continuously monitored. This article answers the questions we hear most often. For the most current control detail, visit the Databook Trust Center.

About Databook and its AI

What is Databook?

Databook is the decision system for enterprise sales. It gives your sales team verified buyer intelligence, structured reasoning, and step-by-step guidance, delivered through a conversational interface and inside the tools you already use. It's built to help you identify the best accounts and buyers, prepare for meetings, generate pipeline, and increase conversion and deal size.

How does Databook keep AI responses accurate?

Databook uses Retrieval-Augmented Generation (RAG) rather than relying on general model knowledge or open web search. Before generating a response, Databook grounds it in high-quality, sourced data, including financial, firmographic, and proprietary datasets such as strategic priorities and management intent. Key datasets are refreshed daily and traced back to sources like investor documents, earnings transcripts, and company filings. Databook also runs automated accuracy checks and maintains a human review step, where analysts approve or reject AI-generated insights before they're published. You can see data sources and freshness (when something was last checked and last updated) directly within key insights.

Can I customize how Databook's AI behaves for my team?

Yes. Coaches (Databook's guided, step-by-step workflows for specific sales motions) can be customized: you can adjust the name, description, tasks, and output tone, format, and examples to fit your team. The core building blocks that make a coach reliable, like its trigger and workflow type, stay fixed, so customization doesn't break the underlying verified logic. You can preview and test any change before it goes live, and version history lets an administrator roll back a change if needed. Find out more in our help articles about the GTM Control Center Admin Console and help articles about the AI Studio.

How is Databook different from ChatGPT or other general-purpose AI tools?

  • Grounded in verified data: Databook uses RAG to anchor responses in verified financial, firmographic, and proprietary buyer data, rather than a model's general training data or open web search.

  • Proactive guidance: Databook suggests relevant questions and next steps, and walks you through structured workflows rather than waiting for the right prompt.

  • Built into your workflow: Databook is available as a web app and inside the collaboration and CRM tools your team already works in.


Certifications and compliance

What security certifications does Databook maintain?

Databook completes an annual, independent SOC 2 Type II examination covering the Security and Availability Trust Services Criteria, with continuous monitoring and auditing of its controls in between. Databook also aligns with:

Standard

SOC 2 Type II

GDPR

CCPA

Microsoft Supplier Security & Privacy Assurance (SSPA) Program

NIST Cybersecurity Framework

A copy of the SOC 2 Type II report is available under NDA on request. Current control detail is published on the Databook Trust Center.

What privacy regulations does Databook comply with?

Databook complies with data privacy laws including GDPR and CCPA, and maintains a documented privacy policy and formal process for handling data subject requests (access, correction, and deletion), including identity verification. We carry out Data Protection Impact Assessments (DPIAs) for new or higher-risk processing to identify and minimize privacy risk.


How your data is protected

What measures protect my data?

Databook’s controls to protect your data include:

  • Encryption: data in transit is encrypted with TLS 1.3 and AES-256; data at rest is encrypted with AES-256. Access to encryption keys is limited to authorized personnel with a business need.

  • Tenant isolation: your data, including your queries, is logically separated by workspace and organization and is only accessible to authorized users within your own tenant.

  • Network security: segmented networks, firewalls with regularly reviewed rules, encrypted transmission over public networks, and intrusion detection.

  • Audit logging: operations are monitored and recorded to support investigations and compliance.

  • Endpoint controls: anti-malware protection and centrally managed device management on company devices.

Is my data kept separate from other customers' data?

Yes. Your data is stored in a logically separated tenant with strong data isolation, including row-level security. It's only accessible to users within your own tenant and is never combined or exposed across customers.

Where is my data hosted?

Databook is hosted on Amazon Web Services (AWS) in the US. AWS provides the underlying physical and environmental security for that data center as a subprocessor, and this is reflected in Databook's SOC 2 report.

How long is my data kept, and how is it deleted?

Databook follows formal data retention and disposal procedures as set out in your customer agreement or data processing addendum. Your transaction data is retained for the life of your account. Deletion requests are handled in line with applicable law.


AI and your data

What data does Databook's AI use to generate responses?

Databook may use the solutions, use cases, case studies, and other content your organization has configured on the platform to personalize responses, coaches, and generated assets. That configured content is only used to inform responses for users in your organization. If you include information in your own query, such as an account name, that input is only used to inform responses to your queries.

Is my data used to train AI models?

Data shared with third-party AI providers is not used to train their models, is not shared with their other customers, and isn't made available to them for their own use. By default, Databook does not use your data to train models that are shared with other customers, and any use of your data is governed by your customer agreement.

What third-party AI providers does Databook use?

Depending on the use case, Databook uses enterprise AI services such as OpenAI or Anthropic, accessed through their business or enterprise APIs. A current list of the third-party AI services we use can be found in our subprocessors list. Data shared with these providers is not used to train their models.

What guardrails are in place against misuse?

Databook is built for a specific set of enterprise sales use cases, which narrows the ways it can be misused. Databook has guardrails against misuse and is tested against prompt-injection attacks. External penetration testing covers the OWASP Top 10 for large language models in addition to traditional web application threats.


Access controls and administration

Who can access my data?

Databook enforces role-based access tied to job function, with a documented request and approval process. Remote access to production systems requires multi-factor authentication (MFA) over an approved, encrypted connection. Access is reviewed at least quarterly and revoked promptly when an employee leaves. Privileged access to databases, systems, networks, and firewalls is limited to people with a business need.

What administrative controls do I have?

Your administrators manage your environment through your Databook admin console. From there, they can manage team membership and invitations, configure and publish prompts and coaches with preview and version control, apply your organization's branding, and view analytics such as conversations, high-priority accounts, coverage gaps, and usage of assets and coaches. Databook supports single sign-on (SSO) for authentication.

Does Databook support single sign-on (SSO)?

Yes. Databook supports SAML 2.0, with both identity-provider-initiated and service-provider-initiated login. It's been configured for identity providers including Okta, Salesforce, and AWS Federated, though that's not an exhaustive list, so check with your account team if yours isn't listed. Setup isn't self-serve: contact your Databook account team to get started, and have your ACS URL, Entity ID, and a signing certificate ready. See How to configure Single Sign On (SSO) for the full walkthrough.


Integrations and API security

How secure is the Salesforce integration?

The Salesforce integration lets your CRM power automated workflows, account coverage, and deal-specific AI in Databook. Opportunities, personas, stages, and company details can flow into Databook to pre-fill briefs, presentations, and business cases. Your Salesforce data lands in a data store dedicated to your organization and is never combined with another customer's data. Find out more in our help articles about the Salesforce integration.

How does the Slack integration protect my data?

The Slack integration is one-way and read-only: Databook reads relevant conversations so they can be attached to the right account, and never posts, edits, or deletes anything in your Slack workspace. A few things worth knowing:

  • Public channels only. Databook reads public channels only. It doesn't request, and can't use, the permissions that would let it read private channels, direct messages, or group DMs.

  • Kept separate from other customers. Your Slack data lands in a data store dedicated to your organization and is never combined with another customer's data.

  • Only what maps to an account. A channel has to be matched to an account in your CRM before anything from it is processed. Content that can't be matched never surfaces anywhere in Databook.

Installing the integration is optional and is done by your own Slack workspace administrator, who has to approve the app before it can be added, particularly in workspaces that restrict app installs. Find out more in our help articles about our Slack integration.

What about the Gong integration?

Gong records and transcribes your customer calls, and the integration brings that conversation record into Databook so account intelligence reflects what was actually discussed. It's read-only and follows the same per-customer data isolation as the Salesforce and Slack integrations. Databook excludes any call marked private in Gong, any call with only internal participants, and any call that isn't linked to a Salesforce record, so only externally facing, CRM-linked calls reach an account timeline. Find out more in our help articles about our Gong integration.

How is the Databook API secured?

The Databook REST API (Chat and Batch) uses OAuth 2.0 for authorization, and every request must present a valid access token. The API enforces rate limiting and throttling, and includes monitoring and logging. Data in transit is encrypted with TLS 1.3/AES-256, and data at rest with AES-256. Databook runs annual third-party penetration testing and internal vulnerability assessments against the API, referencing the OWASP Top 10. Find out more in our help articles about our APIs and MCP.

Can I chat with Databook or generate assets in Slack and Microsoft Teams?

Yes. Separately from the Slack data integration above, Databook has conversational apps for both Slack and Microsoft Teams that let you ask questions and generate assets, like a PowerPoint deck for an account, without leaving the app you're working in. Both apps are published in their platform's official marketplace, so you can review them yourself before installing:

Both require a paid Databook account (the app itself is free to add) and are set up by your own IT administrator. For setup steps, see these help articles.


Security operations and resilience

How does Databook manage vulnerabilities?

Databook runs annual third-party external penetration testing, with any findings tracked to remediation SLAs, plus regular vulnerability assessments. Testing covers the OWASP Top 10 for both traditional web applications and large language models, with OWASP API Top 10 coverage for the API. Databook also has a process to triage and remediate vulnerabilities in a timely manner.

How are changes to the platform controlled?

Databook follows a formal software development lifecycle. Changes are authorized, documented, tested, reviewed, and approved before they reach production, and only authorized personnel can deploy to production.

What happens if there's a security incident?

Databook maintains documented security and privacy incident response policies. Incidents are logged, tracked, resolved, and communicated to affected parties in line with those policies. The incident response plan itself is tested at least annually.

How does Databook stay available and recover from disruptions?

Databook maintains Business Continuity and Disaster Recovery plans, tested at least annually. Production runs across multiple availability zones, data is replicated to a secondary location in real time with alerting on any replication failure, and backups are stored separately from the production system. Databook also carries cybersecurity insurance.

What personnel and governance controls are in place?

Databook runs background checks on new employees, requires confidentiality agreements from employees and contractors, and requires acknowledgment of a code of conduct. Information security policies are reviewed at least annually, and Databook's board of directors is briefed on cybersecurity and privacy risk at least annually. Databook also maintains a whistleblower policy with an anonymous reporting channel.

Who are Databook's subprocessors, and can I get a copy of the DPA?

A current list of subprocessors is published here. Databook's Data Processing Addendum (DPA) is available here.


Contact us

Have a question this article didn't answer? Reach the Databook Privacy & Security team at [email protected].

Did this answer your question?