Skip to main content
Platform Review
PricingSign in
Pipedream assessment

Pipedream procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Pipedream
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow Pipedream is committed to the privacy and security of your data. Below, we outline how we handle specific data and what we do to secure it. This is not an exhaustive list of practices, but an overview of key policies and procedures. It is also your responsibility as a customer to ensure you’re securing your workflows’ code and data. See our security best practices for more information. Pipedream has demonstrated SOC 2 compliance and can provide a SOC 2 Type 2 report upon request (please reach out to support@pipedream.com ). If you have any questions related to data privacy, please email privacy@pipedream.com . If you have any security-related questions, or if you’d like to report a suspected vulnerability, please email security@pipedream.com . Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Pipedream can sign Business Associate Addendum (BAAs) for customers intending to pass PHI to Pipedream. We can also provide a third-party SOC 2 report detailing our HIPAA-related controls. See our dedicated HIPAA docs for more details. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Pipedream is hosted on the Amazon Web Services (AWS) platform in the us-east-1 region. The physical hardware powering Pipedream, and the data stored by our platform, is hosted in data centers controlled and secured by AWS. You can read more about AWS’s security practices and compliance certifications here . Pipedream further secures access to AWS resources through a series of controls, including but not limited to: using multi-factor authentication to access AWS, hosting services within a private network inaccessible to the public internet, and more. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Pipedream undergoes annual third-party audits. We have demonstrated SOC 2 compliance and can provide a SOC 2 Type 2 report upon request. Please reach out to support@pipedream.com to request the latest report. We use Drata to continuously monitor our infrastructure’s compliance with standards like SOC 2, and you can visit our Security Report to see a list of policies and processes we implement and track within Drata. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Pipedream encrypts customer data at rest in our databases and data stores. We use AWS KMS to manage encryption keys, and all keys are controlled by Pipedream. KMS keys are 256 bit in length and use the Advanced Encryption Standard (AES) in Galois/Counter Mode (GCM). Access to administer these keys is limited to specific members of our team. Keys are automatically rotated once a year. KMS has achieved SOC 1, 2, 3, and ISO 9001, 27001, 27017, 27018 compliance. Copies of these certifications are available from Amazon on request. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow By default, outbound traffic shares the same network as other AWS services deployed in the us-east-1 region. That means network requests from your workflows (e.g. an HTTP request or a connection to a database) originate from the standard range of AWS IP addresses. Pipedream VPCs enable you to run workflows in dedicated and isolated networks with static outbound egress IP addresses that are unique to your workspace (unlike other platforms that provide static IPs common to all customers on the platform). Outbound network requests from workflows that run in a VPC will originate from these IP addresses, and only workflows in your workspace will run there. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Pipedream is considered both a Controller and a Processor as defined by the GDPR. As a Processor, Pipedream implements policies and practices that secure the personal data you send to the platform, and includes a Data Protection Addendum as part of our standard Terms of Service . The Pipedream Data Protection Addendum includes the Standard Contractual Clauses (SCCs) . These clarify how Pipedream handles your data, and they update our GDPR policies to cover the latest standards set by the European Commission. You can find a list of Pipedream subprocessors here . Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Pipedream performs annual pen tests with a third-party security firm. Please reach out to support@pipedream.com to request the latest report. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tierslow If you choose to delete your Pipedream account, Pipedream deletes all customer data and event data associated with your account. We also make a request to all subprocessors to delete any data those vendors store on our behalf. Pipedream deletes customer data in backups within 30 days. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tierslowAccess to administer these keys is limited to specific members of our team. Keys are automatically rotated once a year. KMS has achieved SOC 1, 2, 3, and ISO 9001, 27001, 27017, 27018 compliance. Copies of these certifications are available from Amazon on request. When you link credentials to a specific source or workflow, the credentials are loaded into that program’s execution environment , which runs in its own virtual machine, with access to RAM and disk isolated from other users’ code. No credentials are logged in your source or workflow by default. If you log their values or export data from a step , you can always delete the data for that execution from your source or workflow. These logs will also be deleted automatically based on the event retention for your account. You can delete your OAuth grants or key-based credentials at any time by visiting https://pipedream.com/accounts . Deleting OAuth grants within Pipedream do not revoke Pipedream’s access to your account. You must revoke that access wherever you manage OAuth grants in your third party application. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tierslow Pipedream does not store or log request payloads or response bodies when you use Connect via API or MCP. When your users make requests through Connect (for example, sending a message with Slack), Pipedream processes the request and returns the response, but we do not persist any of the request payload or response body. This ensures that your users’ data remains private and is not retained on Pipedream’s infrastructure. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersmedium Pipedream retains data only for as long as necessary to provide the core service. Pipedream stores your workflow code, data in data stores, and other data indefinitely, until you choose to delete it. Event data and the logs associated with workflow executions are stored according to the retention rules on your account . Pipedream deletes most internal application logs and logs tied to subprocessors within 30 days. We retain a subset of logs for longer periods where required for security investigations. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tierslow When you delete your account , Pipedream deletes all personal data we hold on you in our system and our vendors. If you need to delete data on behalf of one of your users, you can delete the event data yourself in your workflow or event source (for example, by deleting the events, or by removing the data from data stores). Your customer event data is automatically deleted from Pipedream subprocessors. Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Pipedream uses Stripe as our payment processor. When you sign up for a paid plan, the details of your payment method are transmitted to and stored by Stripe according to their security policy . Pipedream stores no information about your payment method. Was this page helpful?Captured 2026-06-08Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.