Welcome to Hootsuite's Trust Center. Our commitment to data privacy and security is embedded in every part of our business.
Our Information Security Management System and program is aligned with the NIST Cybersecurity Framework (CSF), and Hootsuite has a comprehensive suite of security policies based on NIST CSF, NIST 800-53, ISO 27001, SOC 2 Trust Services Criteria, FedRAMP, and GDPR. The security policies are grounded in the key principles of least privilege, need-to-know, and segregation of duties, and govern access to facilities, systems, and data. The policies are refreshed annually, approved by senior management, and reviewed by our external auditors. Our independent annual SOC 2 audit report, ISO 27001 certification, and FedRAMP certification provide details on our ISMS and its relationship with the various standards.
Use this portal to learn about our security and privacy posture and request access to our security documentation.
Knowledge Base (FAQ)
Trust Center Updates
Earlier today, an update to the CrowdStrike Falcon Sensor caused widespread issues on Windows systems. Crowdstrike’s official response can be found here (https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/). We want to reassure you that we have thoroughly reviewed our IT infrastructure and platform, and we can confirm that this incident has not affected any of our customers.
We will keep you informed of any updates through our Trust Center. If you have any questions or need further assistance, our team is here to help. Feel free to reach out to us at security.support@hootsuite.com
Hootsuite recently acquired Talkwalker and to support our customers in their security & privacy reviews, Talkwalker certifications, FAQs and more are now available in our Trust Center. Check out the Documents section of the Trust Center for more information.
Last week we launched our new Hootsuite Status Page (https://status.hootsuite.com/), your go-to resource for real-time updates and insights into our platform's performance. Bookmark this page for instant access to the latest system status information whenever you need it.
Hootsuite's updated Certificate of Insurance is now available. Please check out the Documents section of the Trust Center to review and download as needed for your records.
Hootsuite is excited to share that we have successfully completed our ISO 27001 certification. Please check out the Documents section of the Trust Center to review and download as needed for your records.
At Hootsuite, we’ll be celebrating Data Privacy Week (https://staysafeonline.org/programs/data-privacy-week/) by hosting some fun and interactive information sessions for all our employees. Our privacy and security teams will be quizzing our employees’ on their knowledge of privacy and security practices.
During the rest of the year we adopt many other practices, including regular privacy and security training for all our employees; distributing privacy and security news updates; and integrating privacy and security at the highest level of our organization with the establishment of a Privacy Council and an Information Security Steering Committee. We also observe privacy by design principles, including conducting privacy impact assessments and reviews when implementing new product functionality, or new processes, or working with new vendors.
Our dedicated security team also continuously monitors our environment to protect our systems and your data. For more information on how we handle personal information, review our Data Privacy section on our Trust Center. For information about our security practices, check out the Whitepaper, “How Hootsuite Keeps Customer Data Safe”. Our Trust Center is continuously updated so please visit regularly to access the latest reports and updates.
Hootsuite's UK Cyber Essentials certificate is now available for your review. Please check out the Documents section of the Trust Center to review and download as needed for your records.
Hootsuite's VPAT reports are now available for your review. Please check out the Documents section of the Trust Center to review and download as needed for your records.
As you may be aware, a security incident was disclosed by the MongoDB team recently. MongoDB has not found evidence of unauthorized access to their customers' data. Hootsuite did a careful review of our platform and IT infrastructure and determined that we are not currently impacted by this security incident. We will continue to monitor the situation and will post updates on our Trust Center as necessary. Please contact security.support@hootsuite.com if you have questions.
Hootsuite's third party led SOC 2 Type II audit reports are now available for your review. Please check out the Documents section of the Trust Center to review and download as needed for your records.
Learn about what matters most when it comes to the security of your social media management solution in our latest whitepaper, "How Hootsuite Keeps Customer Data Safe." Please check out the Reports section of the Trust Center to read the document in full.
As you may be aware, vulnerabilities were disclosed by the Okta team recently. Hootsuite did a careful review of our platform and IT infrastructure and determined that we are not currently impacted by this breach. We will continue to monitor the situation and will post updates on our Trust Center as necessary. Please contact security.support@hootsuite.com if you have questions.
Hootsuite's 2023 HECVAT is now available for your review. Please check out the Documents section of the Trust Center to review and download as needed for your records.
Hootsuite's updated Certificate of Insurance is now available. Please check out the Documents section of the Trust Center to review and download as needed for your records.
Hootsuite's third party led 2023 Penetration Test Summary Letters are now available for your review. Please check out the Documents section of the Trust Center to review and download as needed for your records.
Please note: for confidentiality reasons we do no distribute or share the full penetration report externally.
As you may be aware, vulnerabilities were disclosed by the MOVEit team recently. Hootsuite did a careful review of our platform and IT infrastructure and determined that we are not currently vulnerable to the CVE-2023-34362 and CVE-2023-35036 vulnerabilities that were disclosed on May 31 and June 9, 2023. We will continue to monitor the situation and will post updates on our Trust Center as necessary. Please contact security.support@hootsuite.com if you have questions.
The California Privacy Rights Act (CPRA) will come into effect on January 1, 2023. This amends and enhances the existing privacy law (the California Consumer Privacy Act) and it imposes new requirements on customers handling the personal information of Californian residents. We have prepared an Addendum to help our customers comply with these new requirements, and expanded the scope to include other US state privacy laws that are also coming into effect in 2023. Hootsuite's updated DPA is available here: https://hootsuite.com/legal/data-processing-addendum.
As you may be aware, two high severity vulnerabilities were disclosed by the OpenSSL team this week. Hootsuite did a careful review of our platform and IT infrastructure and determined that we are not currently vulnerable to the OpenSSL 3 vulnerabilities CVE-2022-3602 and CVE-2022-3786 that were disclosed on November 1, 2022. We will continue to monitor the situation and will post updates on our Trust Center as necessary. Please contact security.support@hootsuite.com if you have questions.
As an organization that is security conscious and values security, we are excited to announce the official launch of the Hootsuite Trust Center. By using this portal, you can request access to our compliance documents, review our standardized questionnaires such as the SIG and gain a general understanding of our security & privacy posture.
Over time, our team will be making changes to this portal as we implement new tools and processes in our environment. You can use the Subscribe button to receive email notifications for when our team has an important update, such as if we have an updated compliance report or if we have a status update regarding a major security vulnerability that has been recently discovered.
-Your Hootsuite Security Support Team
If you think you may have discovered a vulnerability, please send us a note.