At Hootsuite, we’re committed to being responsible, trustworthy custodians of our customers’ data. We believe that you have the right to know where your data is stored, how it’s managed, and how it’s used.
Hootsuite's Information Security Management System (ISMS) program is aligned with the NIST Cybersecurity Framework (CSF). We maintain a comprehensive suite of security policies based on NIST CSF, NIST 800-53, ISO 27001, SOC 2 Trust Services Criteria, FedRAMP, and GDPR. The security policies are grounded in the key principles of least privilege, need-to-know, least functionality, and segregation of duties, and govern facility, system, and data access. Our program and policies are reviewed and approved by senior management, reviewed by our external auditors, and reviewed annually and updated as required.
Our independent annual SOC 2 audit report (available under NDA to dedicated security, risk and/or compliance contact) and FedRAMP certification provide details on our ISMS and its relationship with the various standards.
Trust Center Updates
The California Privacy Rights Act (CPRA) will come into effect on January 1, 2023. This amends and enhances the existing privacy law (the California Consumer Privacy Act) and it imposes new requirements on customers handling the personal information of Californian residents. We have prepared an Addendum to help our customers comply with these new requirements, and expanded the scope to include other US state privacy laws that are also coming into effect in 2023. Hootsuite's updated DPA is available here: https://hootsuite.com/legal/data-processing-addendum.
As you may be aware, two high severity vulnerabilities were disclosed by the OpenSSL team this week. Hootsuite did a careful review of our platform and IT infrastructure and determined that we are not currently vulnerable to the OpenSSL 3 vulnerabilities CVE-2022-3602 and CVE-2022-3786 that were disclosed on November 1, 2022. We will continue to monitor the situation and will post updates on our Trust Center as necessary. Please contact firstname.lastname@example.org if you have questions.
As an organization that is security conscious and values security, we are excited to announce the official launch of the Hootsuite Trust Center. By using this portal, you can request access to our compliance documents, review our standardized questionnaires such as the SIG and gain a general understanding of our security & privacy posture.
Over time, our team will be making changes to this portal as we implement new tools and processes in our environment. You can use the Subscribe button to receive email notifications for when our team has an important update, such as if we have an updated compliance report or if we have a status update regarding a major security vulnerability that has been recently discovered.
-Your Hootsuite Security Support Team