Skip to content
English
  • There are no suggestions because the search field is empty.

CRM Integration Security & Compliance

Overview

mOS integrates with 20+ CRM platforms through Merge, an industry-standard integration platform trusted by thousands of enterprises. This integration syncs critical mOS opportunity data (MEDDPICC fields) between mOS and your CRM while maintaining strict security controls, data encryption, and compliance standards.

Salesforce and HubSpot are our primary supported platforms with comprehensive testing and documentation.

Supported CRM Platforms

Primary Support (Fully Tested & Documented)

  • Salesforce
  • HubSpot

Additional Supported Platforms

mOS can integrate with 18+ additional CRM platforms via Merge, including: Accelo, ActiveCampaign, Affinity, Capsule, Close, Copper, Insightly, Keap, Microsoft Dynamics 365 Sales, Nutshell, Pipedrive, Pipeliner, Salesflare, SugarCRM (Beta), Teamleader, Teamwork CRM, Vtiger, Zendesk Sell, and Zoho CRM.

For CRM platforms outside our primary support tier, contact support@meddicc.com to discuss integration requirements and feasibility.

Security Architecture

Data Encryption

  • All data transmitted between mOS and your CRM is encrypted in transit using TLS 1.2+
  • API keys and tokens are encrypted at rest
  • HTTPS enforced for all connections

Data Access & Scope

All opportunity data and fields from your CRM are synced to mOS to prevent future

refresh requirements. However, only fields you explicitly map during setup are

displayed and actively used within mOS.

  • Permissions are configured through Merge with read/write access limited to relevant objects
  • No access to sensitive data like passwords, authentication tokens, or user credentials

Authentication & Authorization

User access to mOS is controlled through either your Identity Provider (enterprise

SSO) or native mOS user accounts. Your CRM user data is used to associate users

with deals for proper context and attribution.

  • Enterprise SSO: SAML 2.0 / OIDC via WorkOS (Okta, Microsoft Entra ID, Google Workspace, and other IdPs)
  • OAuth 2.0 authentication with all supported CRM platforms for data access
  • Short-lived API keys and tokens with automatic refresh
  • CRM API access can be revoked immediately by disconnecting the integration

Data Storage

Merge maintains a copy of synced data as part of its integration service. This

enables reliable synchronization, prevents data loss, and allows historical data

retrieval without requiring full refreshes. Data is stored in secure, encrypted

environments and handled according to Merge's security policies and compliance

standards.

Compliance & Certifications

Organization

Certifications & Standards

MEDDICC

ISO 27001:2022 certified • GDPR

compliant • Regular security audits •

Annual penetration testing

Merge

SOC 2 Type II certified • GDPR compliant

• Enterprise-grade infrastructure • Trusted by thousands of organizations

Access Control & Revocation

API access can be managed and immediately revoked through your CRM's native

integration settings. The process varies by platform:

  • Salesforce: Disconnect via Connected Apps settings
  • HubSpot: Delete the private app
  • Other platforms: Revoke authorization through your CRM's integration or connected apps section

Operational Security

  • Field mapping controls precisely what data is displayed in mOS
  • Full data refresh capability available in Settings for data consistency
  • Sync status and timing are transparent - users see when data was last synced
  • No shared credentials or passwords - all authentication is API-based or SSO

Data Residency

mOS and Merge data are processed and stored in the United States. If you have

specific data residency, localization, or regional compliance requirements (e.g., EU

data residency, HIPAA, CCPA), please contact security@meddicc.com. We can

discuss your requirements and provide detailed Data Processing Agreements and

compliance documentation tailored to your jurisdiction.

Questions & Support

For detailed setup instructions, see the mOS CRM Integration Setup Guide. For

security, compliance, or integration questions:

  • security@meddicc.com - Security architecture, compliance certifications, audit reports, data residency, SSO configuration
  • support@meddicc.com - Integration setup, troubleshooting, operational questions, non-primary CRM platform support

MEDDICC is ISO 27001:2022 certified. Merge is SOC 2 Type II certified. WorkOS is SOC 2

Type II certified. All organizations maintain regular security audits and comply with

GDPR and international data protection standards.