Zoho CRM · Trust Center

Zoho Crm Trust Center

Trust center

Zoho CRM maintains a public trust center documenting ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, ISO 9001, ISO/IEC 20000-1, ISO 22301, SOC 1 Type 2 (SSAE 18 / ISAE 3402), SOC 2 Type 2, SOC 2 + HIPAA Type 2, PCI DSS (SAQ-D), CSA STAR Self-Assessment, Cyber Essentials Plus, TX-RAMP, ENS (Esquema Nacional de Seguridad, Spain), NCA Class B (Saudi Arabia), NHS DSPT (UK) v8, GoBD (Germany), 21 CFR Part 11 / EudraLex Annex 11, and WCAG 2.2 AA compliance.

CRMSalesMarketing AutomationLead ManagementCustomer EngagementSales AutomationContact ManagementPipeline ManagementSoftware-as-a-ServiceOpenAPIAuthentication
Trust center: https://www.zoho.com/compliance.html

Certifications & Compliance

ISO/IEC 27001ISO/IEC 27017ISO/IEC 27018ISO/IEC 27701ISO 9001ISO/IEC 20000-1ISO 22301SOC 1 Type 2 (SSAE 18 / ISAE 3402)SOC 2 Type 2SOC 2 + HIPAA Type 2PCI DSS (SAQ-D)CSA STAR Self-AssessmentCyber Essentials PlusTX-RAMPENS (Esquema Nacional de Seguridad, Spain)NCA Class B (Saudi Arabia)NHS DSPT (UK) v8GoBD (Germany)21 CFR Part 11 / EudraLex Annex 11WCAG 2.2 AA

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
url: https://www.zoho.com/compliance.html
scope: >-
  Zoho Corporation-wide compliance portfolio. Zoho does not run a per-product trust
  centre; Zoho CRM inherits this posture. Recorded at the corporate level, which is
  where Zoho publishes it.
certifications:
- ISO/IEC 27001
- ISO/IEC 27017
- ISO/IEC 27018
- ISO/IEC 27701
- ISO 9001
- ISO/IEC 20000-1
- ISO 22301
- SOC 1 Type 2 (SSAE 18 / ISAE 3402)
- SOC 2 Type 2
- SOC 2 + HIPAA Type 2
- PCI DSS (SAQ-D)
- CSA STAR Self-Assessment
- Cyber Essentials Plus
- TX-RAMP
- ENS (Esquema Nacional de Seguridad, Spain)
- NCA Class B (Saudi Arabia)
- NHS DSPT (UK) v8
- GoBD (Germany)
- 21 CFR Part 11 / EudraLex Annex 11
- WCAG 2.2 AA
regulatory_programs:
- GDPR
- CCPA
- HIPAA
security_whitepaper: https://www.zoho.com/security.html
gdpr_page: https://www.zoho.com/gdpr.html
evidence:
- source: https://www.zoho.com/compliance.html
  status: 200
  keywords: [iso 27001, soc 2 type 2, pci dss, hipaa, gdpr, csa star, tx-ramp]
- source: https://www.zoho.com/security.html
  status: 200
  keywords: [owasp, nist, security whitepaper]
- source: https://www.zoho.com/gdpr.html
  status: 200
not_found:
- url: https://trust.zoho.com/
  note: no dedicated trust.<domain> host; the compliance portfolio at /compliance.html is the equivalent surface
- url: https://www.zoho.com/trust/
  status: 404
related:
- security/zoho-crm-vulnerability-disclosure.yml
- conformance/zoho-crm-conformance.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/zoho-crm-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.