Trying to get some answers re. Clay compliance when using the Salesfoce & Hubspot integration namely 1) confirming SOC2 or ISO 27001, reviewing what data you access.
2.
If that's fine, determine if you use a single integration user, or if it connects as each named SFDC user
a.
If single integration, do you have static ips, I can put into the integration user profile to lock it down.
Compliance: We have SOC 2 Type II and ISO 27001 certifications. [1]
Data Access: For Salesforce, we access data scoped to the OAuth user who sets up the connection - limited to objects and fields that user can access. You can create permission sets to restrict access to sensitive fields. [2]
Integration Method: We use a single OAuth user connection, not individual named users. Once set up by one OAuth user, any workspace member can use the integration.
Static IPs: No - our integration calls originate from cloud IPs that may change. We recommend setting IP Relaxation to "Relax IP Restrictions" in your Connected Apps settings rather than using static IP restrictions. [3]
If you need any further clarification or assistance regarding Clay's compliance and integration details, I'm here to help. Would you like to provide more specifics about what you're trying to resolve or understand?