Gong AI Vendor Risk Profile

Revenue intelligence platform that records, transcribes, and analyzes sales conversations. Uses AI to surface deal insights, forecast revenue, coach reps, and identify winning behaviors across calls, emails, and meetings.

Visit Gong website

HQ: United States · Integrator

Risk overview

Risk score: 37/100

Risk tier: Moderate

Safety rating: 63/100 (higher is better)

Lower risk scores indicate lower assessed risk.

Last verified: Apr 19, 2026 (106 days ago) Aging · 9 cited sources

Risk dimensions

DimensionRisk score
Data Handling42/100
IP Exposure31/100
Jurisdiction13/100
Security26/100
Regulatory Compliance60/100
Transparency80/100
Business Stability37/100
Dependency Chain32/100
Agent GovernanceNot assessed

Analyst summary

Rating: Acceptable

Gong is the category leader in revenue-intelligence AI, capturing sales calls, emails, and deals to drive forecasting and coaching. Data handling is solid (no training on customer data, SOC 2, ISO 27001, GDPR DPA), and built-in consent capture helps with two-party-consent jurisdictions. The absence of a HIPAA BAA limits healthcare use and the vendor's Israel-based engineering presence introduces some operational risk factors.

Bottom line: Category leader for sales AI; solid data posture for non-healthcare enterprise use.

Strengths

Concerns

Best for

Avoid if

Citations

  1. Data Handling — Hipaa Baa Available (primary · medium confidence)
    https://www.gong.io/trust-center/
    Verified 2026-04-19
    Gong does not currently offer HIPAA Business Associate Agreements; HIPAA workloads are not supported.
  2. Data Handling — Third Party Data Sharing (primary · high confidence)
    https://www.gong.io/trust-center/
    Verified 2026-04-19
    Gong AI uses a combination of in-house and third-party LLMs under zero-retention subprocessor agreements.
  3. Data Handling — Trains On User Data (primary · high confidence)
    https://www.gong.io/trust-center/
    Verified 2026-04-19
    Gong does not use customer conversation data to train generative AI foundation models, and does not share customer data across tenants.
  4. Governance — Wiretap Compliance (primary · high confidence)
    https://help.gong.io/docs/consent-capture
    Verified 2026-04-19
    Gong supports two-party-consent jurisdictions with built-in consent capture and recording disclosures to support compliance with state and federal wiretap laws.
  5. Ip Profiles — User Owns Outputs (primary · high confidence)
    https://www.gong.io/terms-of-service/
    Verified 2026-04-19
    Customer retains all ownership rights in Customer Data, including conversation recordings and AI-generated summaries derived from Customer Data.
  6. Jurisdiction Profiles — Incorporation Country (primary · high confidence)
    https://www.gong.io/about/
    Verified 2026-04-19
    Gong.io Inc. is a Delaware corporation with headquarters in San Francisco, California, and significant operations in Tel Aviv, Israel.
  7. Security Compliance — Gdpr Compliant (primary · high confidence)
    https://www.gong.io/data-processing-addendum/
    Verified 2026-04-19
    Gong provides a GDPR-compliant Data Processing Addendum and supports EU data residency for qualifying customers.
  8. Security Compliance — Iso 27001 (primary · high confidence)
    https://www.gong.io/trust-center/
    Verified 2026-04-19
    Gong holds ISO/IEC 27001, 27017, 27018, and 27701 certifications.
  9. Security Compliance — Soc2 Type2 (primary · high confidence)
    https://www.gong.io/trust-center/
    Verified 2026-04-19
    Gong maintains SOC 2 Type II certification with annual independent audits.