Your data is safe. Full stop.

SOC 2 audited. ISO 27001 certified. GDPR compliant. Evergrowth is built for teams that take data seriously — because we do too.

Request a security review
SOC 2Audited annually
ISO 27001Certified
GDPRCompliant

Audited, certified, compliant

Not just logos on a page. Here’s what each one actually requires.

SOC 2

Independent third-party audit of security controls. Covers access controls, change management, risk mitigation, and system monitoring.

Audited annually by an independent auditor.

ISO 27001

International standard for information security management systems. Requires documented policies, risk assessments, and continuous improvement.

Covers the full lifecycle of how data is handled, stored, and protected.

GDPR

EU regulation for personal data protection. Covers lawful data processing, right to access, right to deletion, and data portability.

Applies to all customer data regardless of where Evergrowth operates.

What happens to your data inside Evergrowth

Specific answers, not vague promises.

Encrypted in transit and at rest

All data is protected using encryption both during transmission and while stored. Access is restricted through unique user IDs and role-based permissions.

Never used to train AI models

Your CRM data, research outputs, and agent activity are never used to train or fine-tune any language model. Not ours, not our providers'.

Workspace isolation

Each customer workspace is logically isolated. Your data is never accessible to other customers or shared across workspaces.

Minimal personal data processing

AI agents only process what they need: full name, job title, email, phone, and LinkedIn profile. Processing is limited to contacts matching your approved ICP and buyer personas.

You control retention

When you cancel, your data is returned or deleted at your choice. If no request is made, all personal data is permanently deleted within 30 calendar days.

Logging and monitoring

All access and processing activities are logged and monitored. Evergrowth maintains secure development practices, vulnerability management, and documented incident response procedures.

How AI agents handle your information

You’re trusting AI agents with your CRM data and prospect research. Here’s exactly how that works.

Private AI, not public

Evergrowth uses private, internalized AI systems. Your data stays within Evergrowth’s environment, does not enter the public domain, and is safeguarded against data leaks.

Zero-retention LLM providers

When third-party language models are used for agent reasoning, your data is processed and discarded. It is never stored, retained, or used for training by the provider.

CRM integrations are permission-based

Evergrowth connects to your CRM via OAuth. You choose what data flows in and what writes back. Revoke access anytime.

No autonomous external actions

Agents research and write, but they don’t send emails, make calls, or modify external systems on their own. A human reviews before anything goes out.

Built for teams everywhere

Evergrowth complies with data protection regulations across the EU, US, UK, and Canada.

GDPR EU / UK

Full compliance with Regulation (EU) 2016/679. Evergrowth acts as data processor under a formal DPA. Standard Contractual Clauses (SCCs) used for any transfers outside the EEA/UK.

CCPA / US State Privacy Laws US

Compliant with CCPA/CPRA, VCDPA, CPA, CTDPA, and UCPA. Evergrowth acts as a service provider or processor. Your data is never sold or shared as defined under these laws.

PIPEDA & Provincial Laws Canada

Compliant with PIPEDA and Quebec’s Law 25. Breach notification, access rights, and appropriate safeguards all covered.

When regulations overlap

Where multiple frameworks apply simultaneously, the more protective standard for data subjects governs. Always.

Everything your legal team needs

Security questions we hear most

Yes. SOC 2 and ISO 27001 reports are available to satisfy audit obligations. Request them through your account manager or during a security review.
Only what’s needed: full name, job title, email address, phone number, and LinkedIn profile. Processing is limited to contacts matching your approved ICP and buyer personas, in line with GDPR data minimization principles.
You choose: data is returned or deleted. If no request is made, all personal data is permanently deleted within 30 calendar days of termination.
No. All LLM providers operate under zero-retention agreements. Your data is processed and discarded. It is never stored or used for training.
Only when necessary to provide the service, and always using Standard Contractual Clauses (SCCs) or equivalent safeguards under GDPR Chapter V.
Yes. A GDPR-compliant Data Processing Agreement is included as a standard annex in every customer contract.