PromptLab security: SOC 2, GDPR, and CASA compliance
Learn how PromptLab protects your sales data with SOC 2, GDPR, and CASA certifications, plus enterprise-grade SSO and advanced security controls.
PromptLab is built to meet the security and compliance requirements of manufacturing organizations. Your customer conversations, deal data, and contact information are handled with strict controls at every layer — from the infrastructure that stores your data to the certifications that verify those controls are in place.
Certifications
SOC 2
PromptLab is SOC 2 certified under the AICPA Service Organization Control Reports framework. SOC 2 is an independent audit that verifies an organization has the controls in place to protect the security, availability, and confidentiality of customer data.
For your team, this means:
- Security — controls are in place to prevent unauthorized access to your data
- Availability — the platform is built and monitored to meet uptime commitments
- Confidentiality — your deal data, call recordings, and contact information are protected from unauthorized disclosure
GDPR
PromptLab is compliant with the General Data Protection Regulation (GDPR), the EU data protection law that governs how personal data is collected, stored, and processed.
If your team operates in Europe or works with EU-based customers, GDPR compliance means:
- Your data is processed only for the purposes you've consented to
- You retain rights over your personal data, including the right to access and delete it
- PromptLab applies appropriate safeguards when transferring data across borders
CASA
PromptLab holds a CASA (Cloud Application Security Assessment) certification. CASA is a cloud application security framework that assesses whether a cloud service meets a defined set of security controls for protecting user data.
CASA certification confirms that PromptLab's cloud infrastructure and application-level controls have been independently reviewed and meet the required security standards.
Enterprise security features
Enterprise plan customers get additional security controls designed for organizations with stricter access and compliance requirements.
Single sign-on (SSO)
SSO lets your team sign in to PromptLab using your existing identity provider — such as Okta, Azure AD, or Google Workspace. This means your team uses the same credentials they use for everything else, and your IT team retains full control over access provisioning and deprovisioning.
When a team member leaves your organization, revoking their access in your identity provider immediately removes their PromptLab access — no manual cleanup required.
Advanced security controls
Enterprise accounts include additional controls for managing how your team accesses and uses PromptLab, including granular permission settings and audit capabilities that go beyond the admin controls available on the Business plan.
SLA and priority support
Enterprise customers receive a service-level agreement with defined uptime and response time commitments. Priority support means your tickets are escalated ahead of the standard queue, and you have a direct path to resolution for business-critical issues.
Dedicated account manager
Your dedicated account manager is the primary point of contact for onboarding, ongoing configuration questions, and escalations. They work with your team to make sure PromptLab is set up to match your sales workflow and can coordinate with the PromptLab engineering team on custom requirements.
SSO and advanced security controls require the Enterprise plan. If you're on Pro or Business and need these features, view the plans page to compare options or contact the team to discuss upgrading.
Data handling
PromptLab processes and stores the activity data your team generates — including call recordings and transcripts, emails, meeting summaries, and CRM records. Here is how that data is managed:
- Unlimited storage on all plans — there is no cap on how much call, email, or deal data you can store in PromptLab
- Data is used only to power your workflows — your conversations and deal data are used to generate summaries, drafts, and CRM updates for your team; they are not used to train shared models or shared with other organizations
- Secure processing — email, call, and meeting data is transmitted and stored using encryption in transit and at rest
If your organization has specific data residency requirements or needs a data processing agreement (DPA), contact the PromptLab team to discuss Enterprise options.