Ahoy

// Security & Compliance

Security to sell on

Ahoy handles your email, your calendar, and your customer conversations. Here is exactly what we do with that data, who can see it, and what we will send your security team.

Certifications

SOC 2 Type I & II

Independently audited against the AICPA Trust Services Criteria for security, availability, and confidentiality.

Reports on request

HIPAA

Ahoy is HIPAA compliant and we will sign a BAA.

BAA available

GDPR & Compliance

Ahoy is in full compliance with the General Data Protection Regulation (GDPR).

Learn more

Ahoy never trains on your data

Your conversations, emails, and records are used to run Ahoy for you, nothing else. We don't use your data to train or fine-tune any model, ours or anyone else's, and the model providers we work with are contractually barred from training on it either.

Encryption and infrastructure

Your data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Ahoy runs on Amazon Web Services in the United States (us-east-1).

Subprocessors

Every subprocessor that touches customer data, what it does, and where it runs, is listed on our Trust Center, alongside the policies and controls behind the audits.

Where your data lives

The United States. We sign a Data Processing Agreement, and our privacy policy sets out the transfer safeguards for EU and UK customers.

Uptime and incidents

If an incident affects your data, we tell you as soon as we have confirmed it, with what happened, what was affected, and what we did about it.

Access controls in your workspace

Roles and permissions on every plan, granular permissions on Pro, SAML SSO and SCIM provisioning on Growth. Field-level visibility keeps sensitive properties with the people who should have them, and each workspace is fully isolated from the others in your organization.

Access controls at Ahoy

Nobody at Ahoy has standing access to customer data. An engineer who needs it has to request it for a specific job, gets the least access that job needs, for a limited time, and every request and every action is logged. Support sees your workspace only when you ask for help.

// Data privacy / our promise

Your data stays yours

Export everything, any time, including custom objects and fields. If you cancel, we delete your data from active systems within 30 days and from backups within 90, and confirm when it is done.

For your security review

Tell us what you need and we will send it: SOC 2 Type I & II reports (under NDA), a completed security questionnaire (SIG Lite or CAIQ), DPA, BAA, and the subprocessor list. Policies, controls, and report requests also live on the Trust Center.

Email hello@ahoy.ai

We respond within two business days.

Frequently asked questions

01 /Do you use our data to train AI models?

No. Your conversations, emails, and records are used to run Ahoy for you and nothing else. We do not use your data to train or fine-tune any model, ours or anyone else's, and the model providers we work with are contractually barred from training on it.

02 /Which AI providers do you use, and do they train on our data?

Ahoy runs on a small number of third-party model providers, listed with every other subprocessor on our Trust Center at trust.ahoy.ai. Each one is under a contract that prohibits training on customer data, and requests to them are not retained beyond what is needed to return a response.

03 /Where is our data stored?

In the United States, on Amazon Web Services in the us-east-1 region, encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. We sign a Data Processing Agreement for customers in the EU and UK.

04 /Can we see your SOC 2 report?

Yes. Ahoy has completed SOC 2 Type I and Type II audits against the AICPA Trust Services Criteria for security, availability, and confidentiality. Request the reports on our Trust Center at trust.ahoy.ai; they are shared under NDA.

05 /Will you sign a BAA and a DPA?

Yes to both. A Business Associate Agreement is available for teams that handle protected health information, and a Data Processing Agreement for teams that need one under GDPR or UK GDPR.

06 /Who at Ahoy can see our data?

By default, nobody. There is no standing access to customer data at Ahoy. An engineer who needs it requests it for a specific job, gets the least access that job needs for a limited time, and every request and action is logged. Support looks at your workspace only when you ask for help.

07 /Can we keep certain emails out of Ahoy?

Yes. A do-not-track list keeps the addresses and domains you choose out of your email sync, and it can retroactively remove what was already synced. Investors, lawyers, HR, and personal contacts stay out of the CRM.

08 /Are our workspaces isolated from each other?

Yes. An organization running multiple workspaces gets full isolation between them. Each workspace has its own pipelines, data model, roles, and permissions, and nobody sees across workspaces unless you grant it.

09 /What happens to our data if we cancel?

You can export everything first, including custom objects and fields. After cancellation we delete your data from active systems within 30 days and from backups within 90, and we confirm when it is done. You can also request deletion at any time. Data deletion request.

Ready to Navigate Smarter?

Ahoy is built for teams who'd rather close deals than manage a CRM. Find out what your pipeline looks like when it runs itself.