Pipe17 Trust Center

Pipe17 runs your order operations, and protecting your data is foundational to how we build. Get the certifications, reports, and documentation your security and risk teams need to assess Pipe17, including SOC 2 Type II, penetration testing, insurance, and data protection, available on request.

Why teams trust Pipe17 with their operations

Connecting every channel, warehouse, partner, and AI agent to one platform should tighten control of your data, not scatter it. With Pipe17 it does. Every connection runs inside one secured environment with encryption, isolation, and monitoring applied throughout.

  • Always Secure

    Security is built into every layer of Pipe17. Certified under the Security criteria of our SOC 2 Type II report, Pipe17 pairs enterprise SSO (Okta, Microsoft Entra ID, and more) and multi-factor authentication with secure development practices and a dedicated, background-checked security team. Access follows your identity provider and is revoked the moment you remove someone.

  • Always Accessible

    Your operations never stop. Pipe17 is built for availability: orders, inventory, and dashboards stay reachable and current in real time, backed by the Availability controls in our SOC 2 Type II report, redundant AWS infrastructure, and around-the-clock monitoring. Check platform health any time on our public status page.

  • Always Compliant

    Compliance keeps pace with your growth. Pipe17 meets GDPR and CCPA, backs international data transfers with a Data Processing Addendum and Standard Contractual Clauses, and gives you granular control over sensitive data, including PII removal on exports and scrubbing before data reaches a data lake. Every configuration change is auditable, and our subprocessor list is public.

  • SOC 2 Type II
  • GDPR
  • CCPA
  • Hosted on AWS

How we protect your data

  • Encryption everywhere

    Data is encrypted at rest and in transit, with TLS 1.2 for connections and 256-bit encryption for stored credentials.

  • Hardened network

    A Web Application Firewall fronts a multi-tier architecture hosted on AWS, with logical isolation between environments.

  • Resilient by design

    Pipe17 runs across redundant AWS Availability Zones with database replication to a standby system and a tested business continuity and disaster recovery program.

  • Always watched

    24/7 security monitoring with automated alerting on anomalous activity.

  • Tested by outsiders

    Independent third parties run penetration testing against Pipe17 every year, backed by regular internal vulnerability scans.

  • Access on your terms

    Single Sign-On (SSO) and role-based access keep the right people, and only the right people, in your operational data.

  • Incident response

    A documented Security Incident Response Plan governs detection and response, and affected customers are notified of a personal data breach within 72 hours.

Security for AI agents

Open your order data to AI without giving up control of it.

AI clients like Claude, ChatGPT, and Gemini connect through the Pipe17 MCP server on the onX open standard. The server accesses your data without storing or processing it, and every request is isolated and monitored. The AI models Pipe17 uses are contractually prohibited from training on your data.

Pipe17’s AI Controls keep AI usage under administrator control, and every change is logged. Each capability can be switched on or off independently:

  • Generate explanations from your data
  • Generate automation rules and routing
  • Take actions on your behalf
  • Allow external access via the MCP server
Explore Pipe17 AI
AI clients Claude, ChatGPT, and Gemini connect through the Pipe17 MCP server security gate to reach your order data, governed by Pipe17's AI Controls

What you can request

For security, risk, and procurement teams evaluating Pipe17. Request any of the following using the request form below.

  • AuditSOC 2 Type II report

    Independent third-party audit of our controls over time.

  • TestingPenetration test summary

    Results of our annual third-party penetration testing.

  • PoliciesInformation security policies

    Our corporate and security policy set, including access control, incident response, business continuity and disaster recovery, secure development, and encryption.

  • InsuranceCertificate of Insurance (COI)

    Coverage details for vendor risk files.

  • LegalData Processing Addendum (DPA)

    With Standard Contractual Clauses for international transfers.

Request Pipe17 security documentation

For security, risk, and procurement teams evaluating Pipe17. Select the documents you need for your review and we will follow up. Documents marked “shared under NDA” are released once an NDA is in place.

Pipe17 security and compliance FAQ

Is Pipe17 SOC 2 certified?

Pipe17 is SOC 2 Type II certified, covering the Security, Availability, and Confidentiality Trust Services Criteria. The report reflects an independent audit of our controls over time, and you can request it using the request form under NDA.

How do I get Pipe17's SOC 2 report?

Request the SOC 2 Type II report using the request form. Documents are shared under NDA, and most security and procurement teams get what they need to complete a third-party risk assessment from there.

Does Pipe17 perform penetration testing?

Independent third parties run penetration testing against Pipe17 every year, supported by regular internal vulnerability scans. You can request the latest summary using the request form.

Does Pipe17 carry insurance, and can you provide a COI?

Yes, Pipe17 carries insurance and provides a Certificate of Insurance (COI) for your vendor risk file on request.

Is my data encrypted?

Pipe17 encrypts your data both at rest and in transit. Connections use TLS 1.2, and stored credentials are protected with 256-bit encryption, so your order, customer, and inventory data is covered at every layer.

Is Pipe17 GDPR and CCPA compliant?

Pipe17 is built to meet GDPR and CCPA requirements and offers a Data Processing Addendum with Standard Contractual Clauses for international data transfers. You also control sensitive data directly: remove PII on exports, or scrub it before anything streams to your data lake.

How long does Pipe17 retain my data?

Pipe17 retains your data for as long as your account is active, so your operations always have the history they need. After an account is closed, data is retained for a defined period and then deleted, and you can request deletion at any time.

How does Pipe17 keep data secure when AI agents access it?

Pipe17 connects AI clients through its MCP server, which accesses your data without storing or processing it, following the onX open standard. Access is logically isolated and actively monitored, and sensitive fields can be removed or scrubbed before data leaves your environment. Administrators can also enable or disable AI features, including MCP access, from Pipe17's AI Controls.

Who are Pipe17's subprocessors?

Pipe17 publishes its current subprocessor list and keeps it updated as vendors change, so you always have an accurate view of who processes data on our behalf.

Where can I check Pipe17's uptime and system status?

Pipe17 publishes real-time system status, uptime, and incident history on our status page, so you can monitor platform health and subscribe to updates without contacting support.

How quickly does Pipe17 report a data breach?

Pipe17 notifies affected customers of a personal data breach within 72 hours of becoming aware of it, in line with our Data Processing Addendum and GDPR obligations.

Run your operations on a platform you can trust

Brands and 3PLs trust Pipe17 with their most critical order operations, backed by the security, compliance, and control enterprise teams require. See what Pipe17 can do for yours.