Scalient IQ runs against your real revenue data, but never inside your environment. Read-only OAuth, AES-256 encryption, US-based cloud hosting, and SOC 2 Type II readiness path in progress. Scalient IQ never writes, modifies, deletes, or sends anything in your systems. There are no external actions because we do not execute, and access is revocable anytime.
Every Scalient IQ engagement connects through standard read-only OAuth. We read, we never write. There is no write path to authorize because there is no write path at all.
Strictly read-only. All OAuth scopes are read-only. Scalient IQ cannot write, modify, delete, or send anything in client systems. Output is delivered as a Signal Health Report. Nothing is ever changed in your CRM or stack.
You stay in control. Access is granted through standard vendor OAuth and can be revoked from your admin panel at any time. There are no external actions because we do not execute, so there is nothing to fire and nothing to approve.
| Authentication | OAuth 2.0 with PKCE (where supported). Standard vendor OAuth flows identical to HubSpot, Salesforce, Gong, and Outreach integrations. |
|---|---|
| Access Level | Strictly read-only. All OAuth scopes are read-only. Scalient IQ cannot write, modify, delete, or send data in client systems. There are no write scopes and no external actions, because we do not execute. |
| Connection Method | REST API over TLS 1.2+ encrypted connections. No direct database access. No VPN tunnels. No agents or code installed in client environments. |
| Scope Transparency | Full list of OAuth scopes provided before authorization. Client reviews and approves each scope explicitly. |
| Revocation | Client can revoke API access at any time from their CRM admin panel. Revocation is immediate and requires no SiQ involvement. |
| Data in Transit | All data transmitted over TLS 1.2+ encrypted connections. No unencrypted data transfer at any point. |
|---|---|
| Data at Rest | Encrypted using AES-256. All client data stored in isolated, logically separated environments. |
| Data Residency | Client data processed and stored within US-based cloud infrastructure operated by our platform providers. No cross-border data transfer without explicit client consent. |
| Data Retention | Assessment data retained for 90 days post-delivery for support purposes, then permanently deleted. For always-on subscription clients, this read-only data is retained for the duration of the contract plus a 30-day grace period. |
| Data Deletion | Client can request full data deletion at any time. Deletion completed within 14 business days with written confirmation. |
| PII Handling | SiQ Cortex processes business contact records (name, email, title, company) as provided by the client's CRM. No consumer PII. No financial data. No health data. |
| Cloud Provider | US-based cloud hosting through our platform providers (US regions). |
|---|---|
| SOC 2 Alignment | SOC 2 Type II readiness path in progress.Readiness Path in Progress |
| Access Control | Role-based access (RBAC). All internal access requires MFA. Principle of least privilege enforced. |
| Logging & Monitoring | All API access logged with timestamps, user identity, and action type. Anomaly detection active on all client data endpoints. |
| Incident Response | Documented incident response plan. Client notification within 72 hours of confirmed breach involving their data. |
| Vulnerability Management | Regular dependency scanning and patching. No software installed in client environments. No VPN tunnels. No direct database access. All integrations are customer-authorized, read-only, outbound API connections from SiQ infrastructure. |
Scalient IQ uses AI to analyze signals across the tools you already run and turn them into a prioritized read that estimates the potential dollar impact where the data supports it. Every finding is delivered as a report. Nothing is executed in your systems.
All access is standard read-only OAuth. Scalient IQ never writes to your CRM, never modifies or deletes data, and never sends outbound communications. There is no write path to approve because there is no write path at all.
Read-only is a core architectural choice, not an optional setting. Access is fully revocable from your admin panel at any time, with no Scalient IQ involvement. There are no external actions because we do not execute.
Disclaimer. Scalient IQ's website-described assessment and subscription model is read-only by design. Scalient IQ does not write, modify, delete, send, or execute actions in customer systems under this access model. Any separate implementation or execution services must be governed by a separate written scope and authorization.
| SOC 2 Type II | SOC 2 Type II readiness path in progress.Readiness Path in Progress |
|---|---|
| CCPA | Compliant. No sale of personal information. Deletion requests honored within 14 business days.Compliant |
| GDPR | DPA available; privacy terms designed to support applicable data-protection requirements.DPA Available |
| Data Processing Agreement | Available on request. Standard DPA covering processing scope, sub-processors, and deletion obligations. |