// Guides · Security
What does a CRM security review ask for, and how do you get through it in a week?
A CRM security review asks for eight things: a SOC 2 report under NDA, the OAuth scopes the email and calendar connection requests, a subprocessor list, where data is stored, retention and deletion terms, SSO and SAML support, the permissions model, and what the AI does with customer data. You get through it in a week by collecting all eight before the questionnaire arrives and answering from that pack.
What does a CRM security review ask for?
In our sales calls the review arrives as a questionnaire. Sometimes it is forty rows, sometimes three hundred, and the length hides how repetitive the substance is. I have read enough of them this year to say that eight questions carry nearly all of the weight. The rest are the same eight asked in the vocabulary of whichever framework the reviewer applies to every vendor, or rows about physical office security that a cloud product answers with one sentence.
What makes the review slow is that the eight questions are owned by different people on the buyer's side, and each of those people has a different idea of what a satisfactory answer looks like. The table maps each section to the evidence that closes it and to the person who usually has to say yes.
| Questionnaire section | What satisfies it | Who owns it on the buyer side |
|---|---|---|
| Third-party assurance | SOC 2 Type II report shared under NDA (Type I if that is what exists), plus a bridge letter if the observation period has ended | Security or IT |
| Integration scopes | The exact OAuth scopes the Google Workspace or Microsoft 365 connection requests, with one line per scope on why it is needed and what stops working without it | Whoever administers the Workspace or 365 tenant |
| Subprocessors | A current list with purpose and region for each: hosting, the model provider, email delivery, support tooling | Legal or privacy |
| Data location | Region of storage and of processing, stated plainly, and whether either is configurable | Security; sometimes a parent company's IT team |
| Retention and deletion | Retention period by data type, deletion on request, deletion at termination, and how excluded addresses and domains are kept out of sync | Legal or privacy |
| Identity and access | SAML SSO, enforced MFA, and an offboarding path that follows the identity provider | IT admin |
| Permissions inside the product | Roles, field-level visibility, workspace isolation between business units, and who can export | CRM admin or sales ops, with security signing off |
| AI use of customer data | Whether customer data trains any model, which provider sees what, and what the AI can do without a person approving it | Security and your champion, together |
The third column is the one I would read twice. A manufacturing prospect we worked with this year ran the review through a five-person committee, and the champion, who had been ready to sign for a month, ended up escalating to his own executives to get a decision out of it. Another deal was gated entirely on the parent company's IT team, who had never spoken to the sales leader who wanted the tool and had no reason to hurry. In both cases the questionnaire was the easy part. The buyer's org chart set the clock.
Why does it take six weeks by hand?
Six weeks is roughly what we see when a review is run by email, one question at a time. My view, having sat through a fair number of them now, is that most of those six weeks are spent waiting for documents that could have been ready on day one. The NDA for the SOC 2 report is its own round trip. The subprocessor list goes from the reviewer to the vendor's sales rep, from the rep to legal, from legal to engineering for the current version, and back. Each hop is a business day or two, and there are eight sections.
The decade I spent at HubSpot was on the CRM engineering side, where the answers to these questions belonged to a compliance team down the hall and I rarely saw the questionnaire. At a smaller company they land on the founders, which is how I came to have opinions about them. The reviews that finish fast are the ones where the vendor had the pack assembled before anyone asked, and the buyer had already worked out which of their own people needed to say yes to which row.
Healthcare buyers change the order of the questions rather than the list. Every one we have spoken to says the same thing up front: if there is PHI in the CRM, no LLM tool gets connected without a BAA, a SOC 2 report, and explicit consent flows for the people whose data is in the record. That is the right order, and it means the AI section moves from the last page of the questionnaire to the first call.
Those six weeks come out of the deal. A champion who was excited in week one is defending the purchase against a budget review by week five, and the drift is measurable in the same way any quiet deal is: replies slow, the meeting that was going to be a kickoff becomes a check-in. Compressing the review is a sales problem as much as a security one.
How do you get through it in a week?
The plan below is written from the buyer's side, since that is where the calendar lives, but every step has a vendor half. The days are illustrative; a review with a parent company in the loop will run longer, and your own numbers will differ.
- Day 1: get the pack before the questionnaire. Ask the vendor for their standing security pack: the SOC 2 report, the scope list, the subprocessor list, the retention terms, and a completed questionnaire from a previous review. Sign the NDA for the SOC 2 report the same day. If a vendor cannot produce this within a day, that is a finding in itself.
- Day 2: put a name on every row. Take the eight sections in the table and write down who at your company has to approve each one. If a row has no owner, or the owner is at a parent company, book twenty minutes with them now rather than discovering it in week four.
- Day 3: pre-fill from the pack. Answer every questionnaire row you can from the vendor's documents before sending anything to the vendor. Mark the rows that are not applicable to a cloud product and say why. What remains is the real question list, and it is usually a tenth of the original.
- Day 4: run the scope review with your tenant admin. Put the OAuth scopes in front of the person who administers Google Workspace or Microsoft 365 and go through them one at a time. The question for each is what the product does with it and what breaks without it. Ask for the do-not-sync controls at the same time, since those are the answer to "what about the CEO's inbox."
- Day 5: get the AI answers in writing. Three written answers, covered in the next section: whether your data trains anything, what permissions the AI inherits, and what it can do without a person approving. Attach them to the questionnaire so the committee reads the same words.
- Days 6 and 7: one session, all owners, exceptions only. Get every row owner into one meeting with the vendor and go through only the open rows. Anything that cannot be resolved in that hour gets an owner and a date, and the champion escalates it the same afternoon rather than letting it sit in a thread.
Take an illustrative case. A company with thirty sellers, an IT team of four, and a general counsel who covers privacy receives a 120-row questionnaire from its own security function. On day three the buyer pre-fills ninety rows from the vendor's pack and marks twelve as not applicable. Day four's scope review closes another ten, because the tenant admin's real question was whether the connection could read mail it had not been told to read, and the exclusion list answers it. That leaves eight open rows for the committee session: two about data region, three about the AI, and three about export rights and offboarding. The session runs an hour, six rows close in it, and the remaining two go to the general counsel with a date. The review finishes in seven business days. Run by email one row at a time, the same 120 rows are the six-week version.
What AI-specific questions do buyers add now?
Two years ago the AI section did not exist. Now it is the section a security reviewer reads first, and the one that a champion is least able to answer alone. The questions we hear come in a predictable shape.
Does our data train your models? The reviewer wants a plain no, with the model provider named and the contractual basis for the no. "We use a leading provider" does not satisfy anyone. The answer has to say which provider, under what terms, and whether prompts or outputs are retained on the provider's side.
What can the AI see? This is a permissions question in a new costume. If the product has roles and field-level visibility for people, the reviewer wants to know whether the AI inherits the permissions of the user it is acting for, or has a service-level view of everything. This row catches vendors off guard more than any other, because the product team never thought of the AI as a user that needs a role.
What can the AI do without a person? Specifically, can it send an email to a customer, change a deal stage, or delete a record on its own. If a vendor's answer here is vague, keep asking until it is not. An AI that prepares the work and waits for one-tap approval is a control the reviewer can reason about. An AI that acts on customer data without that tap is another category of product, and it deserves its own review rather than a row in this one.
Healthcare buyers add a fourth, about consent: whether the people whose data is in the CRM have agreed to it being processed by an LLM at all. That one has no product answer, only a policy the buyer has to have already, and a good vendor will say so rather than pretend a feature covers it.
What to look for in a tool
For this problem the tool question is narrower than usual, because the tool's job is to make the review short. The thing to ask for is a standing security pack, and the things to check are these:
- Can the vendor produce the SOC 2 report, the OAuth scope list with reasons, the subprocessor list, and a completed questionnaire within a day of being asked, under an NDA they already have drafted?
- Does the product have the controls the review will ask about, rather than a roadmap for them: SAML SSO, roles with field-level visibility, workspace isolation, a deletion path you can invoke yourself?
- Is there a written answer to the three AI questions, and does the product keep a person between the AI and any outbound action?
- Are the sync exclusions real? A do-not-track list that keeps chosen addresses and domains out of the email sync, and can remove what was already synced, is the answer to half the questions a tenant admin will ask.
That is the reason our answers live on a page instead of in an inbox. Our security page lists what is available for a review, SOC 2 Type I and Type II reports, completed questionnaires, and BAAs for teams handling protected health information, along with the controls in the product: encryption in transit and at rest, roles and field-level visibility, workspace isolation, SAML SSO, and a do-not-track list for the email sync. Ahoy's AI prepares follow-ups, tasks, and record updates from captured email, calendar, and meetings, and every outbound action waits for one-tap approval, which is the sentence that closes the third AI row. If you are earlier than the security review and want to know what your current CRM actually holds before anyone asks about it, the free CRM audit spends 45 minutes on your pipeline and your data with us, before anything is connected or installed.
Frequently asked questions
What does a CRM security review require?
Nearly every review comes down to eight items: a SOC 2 report shared under NDA, the OAuth scopes requested by the email and calendar connection, a subprocessor list, the storage and processing region, retention and deletion terms, SSO and SAML support, the permissions model inside the product, and a written account of what the AI does with customer data. Longer questionnaires are those eight items asked in more rows.
Does a CRM vendor need SOC 2 to pass a security review?
For most companies with a security function, yes in practice. A SOC 2 Type II report is the evidence reviewers accept in place of auditing the vendor themselves, and its absence turns every other row into a longer conversation. A Type I report shows the controls are designed; a Type II report shows they operated over an observation period, and it is the one buyers usually mean.
What OAuth scopes should a CRM ask for on Google Workspace?
Only the scopes the product needs to capture email and calendar activity, each with a one-line reason and a description of what stops working without it. A tenant admin will also ask how mail is excluded from the sync, so a do-not-track list for chosen addresses and domains, with the ability to remove what was already synced, belongs in the same answer.
Can a CRM with AI features be used with PHI?
Healthcare buyers set three conditions before any LLM tool touches a CRM holding protected health information: a signed BAA, a SOC 2 report, and explicit consent flows for the people whose data is in the record. The vendor can supply the first two. The consent policy belongs to the buyer, and a reviewer will expect it to exist before the integration is approved.
How long should a CRM security review take?
About a week when the vendor's security pack exists before the questionnaire arrives and the buyer has assigned an owner to each section. Run by email one row at a time it stretches to roughly six weeks, most of which is waiting for documents that were available on day one. A parent company or a multi-person committee adds time regardless of how prepared either side is.
Related guides: What transfers when you leave HubSpot? · When should a startup get a CRM? · Why don't sales reps update the CRM? · Security and compliance · All guides