Compliance frameworks, security audits, and quality certifications this company maintains.
Heap maintains SOC 2 Type II certification, demonstrating that its product analytics platform meets rigorous security, availability, and confidentiality controls required by the enterprises whose user behavioral data is collected and stored by Heap Autocapture.
Heap is GDPR compliant, providing data processing agreements, configurable data masking, and EU data residency options that allow European enterprise customers to deploy Heap Autocapture without capturing personal data in violation of GDPR obligations.
Heap complies with the California Consumer Privacy Act, providing enterprise customers with data subject deletion tools and contractual processing protections needed to manage behavioral data collected from California residents through Heap Autocapture.
Heap holds ISO 27001 certification, providing enterprise customers with internationally recognized assurance that the information security management system protecting Heap's behavioral data collection and storage infrastructure meets global standards.
Heap supports HIPAA-compliant deployments through Business Associate Agreements and configurable data masking controls, enabling healthcare technology companies to use Heap Autocapture without capturing protected health information from their web and mobile applications.
Security
Penetration Testing
CompliantHeap undergoes annual third-party penetration testing of its platform, data collection endpoints, and Heap Connect pipeline infrastructure, with findings remediated and reports made available to enterprise customers under NDA during security due diligence.
Heap Enterprise supports SAML 2.0 single sign-on with Okta, Azure AD, and Google Workspace, enabling product and analytics teams at enterprise customers to access Heap under centralized identity and access management policies.
Privacy
Data Masking & PII Controls
CompliantHeap provides configurable data masking controls that allow enterprise customers to exclude specific fields, form inputs, and page elements from Heap Autocapture collection, ensuring personally identifiable information is never sent to Heap's servers from sensitive application surfaces.
Heap participates in the Cloud Security Alliance STAR Level 1 program, publishing its security self-assessment so enterprise IT and procurement teams can review cloud security controls before deploying Heap Autocapture on their digital products.
Security
Role-Based Access Control
CompliantHeap implements role-based access control at the project, report, and data governance level, allowing enterprise customers to restrict which product managers, analysts, and engineers can view, export, or configure behavioral data collection in the Heap platform.