Security and Compliance at TrebleHook

TrebleHook is a CRM platform purpose-built for architecture, engineering, and construction (AEC) firms. Powered by Salesforce, we offer enterprise-grade security, data protection, and compliance capabilities to meet the needs of large, data-sensitive organizations.

playful kiwi 07759 Illustration of a blueprint or architectur 2e815d63 6f50 4ca1 9707 aecab494d0db 3

Is TrebleHook Secure?

Yes. TrebleHook runs on the Salesforce Platform, which is trusted by global enterprises across regulated industries. By leveraging Salesforce infrastructure, TrebleHook inherits robust security features, including:

  • End-to-end encryption (in transit and at rest)
  • Multi-factor authentication (MFA)
  • Role-based access controls
  • Regular penetration testing and vulnerability scans
Salesforce security

Explore Salesforce’s Trust Site >

What Compliance Standards Does TrebleHook Meet?

Because TrebleHook is built on Salesforce, it benefits from Salesforce’s extensive compliance certifications, including:

SOC Compliance icon

SOC 1

Type II report covering internal constrols over financial reporting systems

SOC Compliance icon

SOC 2

Type II report covering Security, Availability, Integrity, Confidentiality, and Privacy

SOC Compliance icon

SOC 3

Public report of Security, Availability, Integrity, Confidentiality, and Privacy controls

Security Certificate icon

ISO 27001

Compliance with specific information security and risk management requirements

Security Certificate icon

ISO 27017

Adherence with ISO/IEC 27002 Code of Practice controls for cloud services

Security Certificate icon

ISO 27018

Adherence with Code of Practice controls for protection of personal information

FAQ icon

GDPR

How TrebleHook, through Salesforce, helps our customers on their GDPR compliance journeys

How TrebleHook Protects Your Data

TrebleHook follows industry best practices to ensure the confidentiality, integrity, and availability of your data:

  • Data is encrypted using AES-256 standards.
  • Access is restricted using the principle of least privilege.
  • We log and audit key system activities.
  • Regular data backups ensure recoverability.
  • Our teams follow secure development lifecycle practices.

How We Support Procurement Reviews

We understand that large AEC firms often have rigorous security requirements. TrebleHook provides:

  • Access to Salesforce’s downloadable compliance certificates
  • Assistance in completing vendor risk assessments

For enterprise accounts, we also support one-on-one security reviews with our implementation and platform team.

Frequently Asked Questions

Yes. TrebleHook leverages Salesforce, which is SOC 2 certified. Relevant certificates can be downloaded from Salesforce’s compliance site.

TrebleHook data is hosted on Salesforce servers, with global data centers that support region-specific storage as required.

Yes. TrebleHook supports data export, deletion, and access logging in alignment with privacy regulations.