CRM Integration Security & Compliance
Overview
mOS integrates with 20+ CRM platforms through Merge, an industry-standard integration platform trusted by thousands of enterprises. This integration syncs critical mOS opportunity data (MEDDPICC fields) between mOS and your CRM while maintaining strict security controls, data encryption, and compliance standards.
Salesforce and HubSpot are our primary supported platforms with comprehensive testing and documentation.
Supported CRM Platforms
Primary Support (Fully Tested & Documented)
- Salesforce
- HubSpot
Additional Supported Platforms
mOS can integrate with 18+ additional CRM platforms via Merge, including: Accelo, ActiveCampaign, Affinity, Capsule, Close, Copper, Insightly, Keap, Microsoft Dynamics 365 Sales, Nutshell, Pipedrive, Pipeliner, Salesflare, SugarCRM (Beta), Teamleader, Teamwork CRM, Vtiger, Zendesk Sell, and Zoho CRM.
For CRM platforms outside our primary support tier, contact support@meddicc.com to discuss integration requirements and feasibility.
Security Architecture
Data Encryption
- All data transmitted between mOS and your CRM is encrypted in transit using TLS 1.2+
- API keys and tokens are encrypted at rest
- HTTPS enforced for all connections
Data Access & Scope
All opportunity data and fields from your CRM are synced to mOS to prevent future
refresh requirements. However, only fields you explicitly map during setup are
displayed and actively used within mOS.
- Permissions are configured through Merge with read/write access limited to relevant objects
- No access to sensitive data like passwords, authentication tokens, or user credentials
Authentication & Authorization
User access to mOS is controlled through either your Identity Provider (enterprise
SSO) or native mOS user accounts. Your CRM user data is used to associate users
with deals for proper context and attribution.
- Enterprise SSO: SAML 2.0 / OIDC via WorkOS (Okta, Microsoft Entra ID, Google Workspace, and other IdPs)
- OAuth 2.0 authentication with all supported CRM platforms for data access
- Short-lived API keys and tokens with automatic refresh
- CRM API access can be revoked immediately by disconnecting the integration
Data Storage
Merge maintains a copy of synced data as part of its integration service. This
enables reliable synchronization, prevents data loss, and allows historical data
retrieval without requiring full refreshes. Data is stored in secure, encrypted
environments and handled according to Merge's security policies and compliance
standards.
Compliance & Certifications
|
Organization |
Certifications & Standards |
|
MEDDICC |
ISO 27001:2022 certified • GDPR compliant • Regular security audits • Annual penetration testing |
|
Merge |
SOC 2 Type II certified • GDPR compliant • Enterprise-grade infrastructure • Trusted by thousands of organizations |
Access Control & Revocation
API access can be managed and immediately revoked through your CRM's native
integration settings. The process varies by platform:
- Salesforce: Disconnect via Connected Apps settings
- HubSpot: Delete the private app
- Other platforms: Revoke authorization through your CRM's integration or connected apps section
Operational Security
- Field mapping controls precisely what data is displayed in mOS
- Full data refresh capability available in Settings for data consistency
- Sync status and timing are transparent - users see when data was last synced
- No shared credentials or passwords - all authentication is API-based or SSO
Data Residency
mOS and Merge data are processed and stored in the United States. If you have
specific data residency, localization, or regional compliance requirements (e.g., EU
data residency, HIPAA, CCPA), please contact security@meddicc.com. We can
discuss your requirements and provide detailed Data Processing Agreements and
compliance documentation tailored to your jurisdiction.
Questions & Support
For detailed setup instructions, see the mOS CRM Integration Setup Guide. For
security, compliance, or integration questions:
- security@meddicc.com - Security architecture, compliance certifications, audit reports, data residency, SSO configuration
- support@meddicc.com - Integration setup, troubleshooting, operational questions, non-primary CRM platform support
MEDDICC is ISO 27001:2022 certified. Merge is SOC 2 Type II certified. WorkOS is SOC 2
Type II certified. All organizations maintain regular security audits and comply with
GDPR and international data protection standards.