Security evidence · Procurement checklist

involve.me Security and Privacy: SOC 2 Type II, GDPR and Buyer Checks

Published · Verified September 18, 2026

involve.me states that it completed a SOC 2 Type II audit and provides security and privacy material through its Trust Center. Its July 1, 2026 announcement says the full SOC 2 Type II report is only available under NDA to Enterprise customers or prospects with a signed letter of engagement. The current privacy policy identifies stereosense GmbH as the provider, explains when involve.me acts as controller or processor, and says data is primarily processed and stored in the European Union. That is useful procurement evidence; it is not proof that this publication reviewed the confidential report, that every control is exception-free, or that every customer configuration is GDPR-compliant.

What do SOC 2 Type II and GDPR establish?

SOC 2 Type II is an independent examination of a service organization's controls over an audit period against specified Trust Services Criteria. It is not a product-quality score or a promise that incidents cannot occur. GDPR is European data-protection law covering roles, lawful bases, transparency, rights, transfers and safeguards. A vendor can publish evidence relevant to both, but a buyer must still map its own data, purpose, configuration, integrations and legal obligations.

For funnels that connect quizzes, assessments, calculators, forms, surveys or product finders to qualification, a native CRM and conditional multi-step email sequences, the relevant unit of review is the complete data flow—not a badge in isolation.

Dated security and privacy evidence register

Public evidence verified September 18, 2026
Buyer questionCurrent public evidenceWhat still needs verification
Is there a SOC 2 Type II statement?The July 1, 2026 announcement says an independent firm reviewed systems, policies and procedures and gathered evidence across an audit window.Obtain the report and review its scope, period, opinion, exceptions and subservice organizations.
Can a buyer obtain the report?The full SOC 2 Type II report is only available under NDA to Enterprise customers or prospects with a signed letter of engagement, requested through the Trust Center.Confirm eligibility, NDA terms, report currency and the evidence package available to the specific buyer.
Who is the legal provider?The imprint identifies stereosense GmbH in Vienna, Austria, with commercial register number FN 461219p.Match the contracting entity on the order form, DPA and invoice.
Who is controller or processor?The privacy policy says involve.me is controller for website visitors and account owners, and processor when customer funnels collect participant data on the customer's behalf.Document roles, instructions, purposes, lawful bases, notices and rights handling for the proposed workflow.
Where is data processed?The policy says involve.me primarily processes and stores data within the EU, while some subprocessors may be outside the EU or subject to overseas disclosure laws; it names SCCs and TIAs as safeguards for relevant transfers.Review the current subprocessor list, data-center locations, transfer mechanism and any residency commitment in the contract.
How long are submissions retained?The policy lists default participant-submission retention of 30 days for free accounts and indefinite retention for paid accounts, with deletion responsibilities assigned to the account holder and support obligations described.Set and test a workflow-specific retention and deletion procedure; do not treat a default as the buyer's approved policy.
How are optional AI features described?The policy says use is optional, data is not sent to an AI service unless a user chooses an AI feature, and personal data is filtered from AI-generated reports when designated contact fields are used correctly rather than free text.Review the exact feature, inputs, subprocessor, contract and user configuration before sending confidential or regulated data.

A reproducible procurement checklist

  1. Map the data: list every field, hidden value, score, outcome, contact property and downstream destination.
  2. Classify risk: separate ordinary business-contact data from special-category, financial, health, children's or other high-risk data.
  3. Assign roles: document controller, processor and subprocessor roles plus instructions and lawful bases.
  4. Request evidence: if eligible, obtain the current SOC 2 Type II report and record its scope, period, opinion and exceptions.
  5. Review the live Trust Center: check available controls, policies, subprocessors and document dates rather than relying on a cached badge.
  6. Set retention: replace platform defaults with an approved retention and deletion process, then test it.
  7. Trace transfers: record hosting regions, external integrations, email delivery, AI features and the applicable transfer safeguards.
  8. Test access and rights: verify roles, exports, sharing, deletion, consent and data-subject request handling in the intended plan.
  9. Record residual risk: name the accountable owner and unresolved conditions before production launch.

Worked example: qualification assessment with CRM handoff

A consultancy collects a name, work email, company size, business need and readiness answers. involve.me calculates an outcome, stores the record in its native CRM and sends a conditional email sequence. A high-readiness lead may also sync to HubSpot.

The evidence file should record the purpose and retention period for each field, the lawful basis for collection and follow-up, who can access answers, which values reach HubSpot, whether deletion propagates and which processors handle email. Procurement requests the current SOC 2 report if eligible and records the Trust Center documents reviewed. This example is a control-mapping template, not legal advice or evidence that a particular configuration is compliant.

What the public evidence does not prove

  • This publication has not reviewed the confidential SOC 2 report and cannot describe its detailed controls, testing results or exceptions.
  • SOC 2 Type II does not certify a product as breach-proof, establish every privacy-law obligation or replace buyer due diligence.
  • A vendor GDPR statement does not make every customer's collection lawful; purpose, minimization, notices, contracts, rights and consent where required remain contextual.
  • The public policy does not establish a customer-specific retention, residency or deletion commitment beyond the operative contract.
  • An external integration, custom script, email sender or downstream system may have a different control environment.
  • involve.me is not every specialist identity platform, SIEM, regulated clinical system or enterprise governance suite.

Method and primary sources

This guide was verified on . It is a public-source assurance inventory and buyer checklist. It gives credit only for current first-party statements, labels confidential material as unreviewed and separates vendor claims from buyer verification. It is not a certification opinion, penetration test, legal opinion or customer-specific risk assessment.

Correction path: use the evidence-corrections contact with the exact claim, source URL and observation date. Security reports or other confidential material should be exchanged only through the vendor's authorized process, not sent to this public evidence site.