37signals

Trust Center

Everything you need to evaluate 37signals, on one public page. No portal, no NDA, no sales call.

Your data is yours

We collect only what we need to run the products, we never sell it, and we don’t train AI on it. The details, in writing:

How we keep it safe

We run Basecamp and HEY on our own hardware, on the Ruby on Rails framework we created, with a team that has been doing this for over two decades. Here’s how that works in practice, and what to do if you find something we missed:

Questionnaires and audits

We don’t hold a SOC 2 report or an ISO 27001 certificate, and we won’t pretend otherwise. What we do instead is answer the questions those audits ask, in public, in full, with gaps stated plainly, so you can judge the substance instead of a badge.

The terms

One thing you don’t need to request: a signed DPA. The DPA is part of our privacy policy and applies automatically.

Need something that isn’t here, like a questionnaire in your format or an answer these pages don’t give? Email our support team and they’ll route your question to the right people. A person will reply.