Executive Summary
AI-generated analysis for Gong
Gong (gong.io) is a Revenue AI platform assessed at Tier 3 (Moderate Risk) with a 91% confidence score, reflecting a vendor with meaningful security infrastructure and compliance claims alongside several unresolved verification gaps that warrant buyer attention before full onboarding. Gong demonstrates a number of positive signals across its security posture:
Key Findings
- Domain and IP reputation are clean across all threat intelligence sources, with no malware, phishing, or blacklist entries detected
- Infrastructure exposure is minimal, with only 2 open ports (80 and 443) and zero known CVEs — well below the SaaS industry average of 8–12 open ports
- No sanctions matches, adverse media, or regulatory enforcement actions were identified
- The vendor publishes a detailed trust center (trust.gong.io) and subprocessor list, and all 7 disclosed subprocessors — including Amazon Web Services, Google Cloud, Snowflake, and Microsoft — are clean across sanctions and safety checks
- Gong's trust page references a broad compliance portfolio including SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27017, ISO/IEC 42001, PCI DSS (SAQ-D), CSA STAR Level 1, and EU-US Data Privacy Framework Several concerns temper the overall picture. None of the claimed certifications — including SOC 2, PCI DSS, HIPAA, and CSA STAR — could be independently verified through public registries during this investigation; all remain vendor-attested. The marketing site (gong.io) received a C- grade from HTTP security scanner (45/100) due to missing security headers, including Strict-Transport-Security, Content-Security-Policy, and X-Frame-Options. Notably, the application domain (app.gong.io) was not scanned and may have a stronger configuration. Gong's AI data usage policy indicates that customer data may be used for AI model training unless customers actively opt out — a material consideration for organizations with sensitive data governance requirements. AI data retention periods are not clearly specified in the policy. Overall, Gong presents as a commercially mature vendor with substantive compliance claims and a clean threat intelligence profile, but the absence of independently verified certifications and the opt-out AI training model introduce enough uncertainty to warrant conditional approval pending documentation review.
Independence Statement
All evidence in this report was independently sourced from external data providers, public registries, and open-source intelligence feeds without vendor participation or notification.