Security

Security at Glime

Last reviewed July 2026 · Security contact: security@glimecrm.com · Trust center

Glime holds your revenue data — pipeline, pricing, contracts. This page states plainly what we do to protect it, what's independently verified, and what's still on the roadmap. Where we aren't done yet, we say so.

Data protection

Access control

Auditability

Every mutation — record changes, quote versions, discounts, approvals, imports, exports, sign-ins — is written to an append-only audit log with actor, timestamp, and detail. Quote pricing keeps every calculation; nothing is permanently overwritten. See the audit trail live in the sandbox.

Application security

Compliance roadmap — the honest version

ItemStatusTarget
SOC 2 Type IControls implemented; audit firm engagedQ4 2026
SOC 2 Type IIObservation window follows Type IQ2 2027
GDPRDPA, subprocessor list, export & deletion liveAvailable now — DPA
CCPACovered by the same rights toolingAvailable now
Penetration testAnnual third-party testFirst report Q4 2026, summary published to the trust center

Data residency

Primary hosting in the United States; EU data residency (Frankfurt) ships with the hosted backend for Enterprise workspaces. Current subprocessors and regions are listed here.

Reporting a vulnerability

Email security@glimecrm.com. We acknowledge within 24 hours, don't pursue good-faith researchers, and credit fixes in the changelog if you'd like the mention.