Expand your pipeline, not risk exposure
Capture hundreds of leads on the show floor. Popl secures each one through the sales handoff.
Secure event lead capture for GTM teams
Fast-track your review from SOC 2 to signed DPA
Protect your pipeline with SOC 2 Type II attested event lead capture. Popl encrypts every lead at rest and in transit. Your data stays in the U.S., not scattered across the globe. And every lead lands where it belongs: your CRM.
Connect Popl to Salesforce & HubSpot
Sign in with Okta, Entra ID, or Google
Review Popl's audited security controls
DATA PROTECTION, BY DESIGN
Enterprise-grade security, at show-floor speed
Popl locks down your data, not your workflow. Every lead your team captures is protected with independently audited security, contractual commitments, and continuous control monitoring.
ATTESTATION
Insight Assurance · Security criterion
DATA RESIDENCY
AWS California · Google Cloud Oregon
IDENTITY
Okta · Entra · Microsoft · Google
ENCRYPTION
Continuously monitored encryption controls
BREACH NOTICE
Contractual, in our public DPA
LEGAL
Published subprocessor list in our Trust Center
PROOF, NOT PROMISES
Is Popl SOC 2 compliant?
Yes. Popl is SOC 2 Type II attested for the Security criterion. Insight Assurance, an independent auditor, spent a full year examining how Popl protects customer data, from access controls and encryption to monitoring and incident response. The audit came back spotless. Zero exceptions. Request the full report in Popl's Trust Center.

SECURE FROM SCAN TO CRM
How Popl protects your data
Every lead is enriched with licensed data, encrypted, and synced to your CRM. Capture with consent when you need it. Your admins control the connection. Your data is hosted in the U.S., start to finish.
CRM INTEGRATION ARCHITECTURE
Built to keep your CRM clean
Popl gives your admin control over which fields get written. Connection is a one-time, company-level OAuth app. Not a managed package. Reps never enter CRM credentials. Duplicate prevention matches on email and phone. Test in a sandbox before production. Check every record in Sync Logs.
DATA STORAGE & RESIDENCY
Your data lives in the U.S. — and stays there
Popl hosts customer data in the United States, on AWS in California and Google Cloud in Oregon. Data is encrypted in transit and at rest. Access to production systems is restricted, logged, and revoked the day someone leaves. Need to verify? Inventory our controls in the Trust Center.
AI DATA ENRICHMENT
Licensed data, always validated
If we enrich it, your team can act on it. Popl queries Apollo, RocketReach, and 18+ licensed data partners in a waterfall, returning verified contact and company data with 99%+ email match rates. All in seconds. And the AI behind it? Built with Anthropic's Claude, named right on our public subprocessor list.
CRM SYNC
Fill your CRM from the floor
Every contact record enters your CRM clean and complete. All in seconds. Prospects route to the right AE in real time. Tags tie closed-won back to the rep and event for crystal-clear attribution.
Trusted by startups & enterprises
Join 2.5M+ professionals, 20K companies, and 90% of the Fortune 500 keeping lead data secure with Popl.
THE SECURITY STACK BEHIND EVERY SCAN
Control your team's access. Know who handles your data
Popl supports SAML SSO and SCIM provisioning, names every subprocessor publicly, and commits to breach notification in its public DPA. For shorter reviews. And faster rollouts.
One login for onboarding, offboarding, and everything in between.
Provider
Protocol
Provisioning
14 subprocessors. The full list and DPA are public in our Trust Center.
Subprocessor
Purpose
Location
If something breaks, you hear about it — in hours, not weeks.
72 hours
Contractual breach notification in our public DPA
Capture hundreds of leads on the show floor. Popl secures each one through the sales handoff.
Justify every event dollar. Verify every security control
Watch a badge scan become a complete, verified lead in your CRM in seconds.
CASE STUDIES
Why event teams switch to Popl
Why event teams switch to Popl
ONBOARDING SUPPORT
Go from evaluation to event in 3 steps
Step 1
Structured evaluation on your timeline
Step 2
SSO and CRM setup with your IT team
Step 3
Three one-hour calls to get your team live within 30 days
Yes. Popl holds a SOC 2 Type II attestation (Security criterion), audited by Insight Assurance with a clean opinion and no exceptions noted. Request the full report in Popl's Trust Center.
Popl hosts customer data in the United States, on AWS in California and Google Cloud in Oregon. Data is encrypted in transit and at rest.
Yes. Popl supports SAML 2.0 SSO with Okta and Azure/Entra, plus Microsoft and Google SSO. SCIM provisioning is supported for member management, with documented walkthroughs for Okta and Entra ID. Current scope: name and email attributes only; group provisioning is not yet supported.
No. The Salesforce connection is a one-time OAuth authorization initiated by your admin; end users capturing leads aren't part of the connection flow. The full setup is documented at docs.popl.co, including object-level permissions for the integration user and the enumerated OAuth scopes, written to be forwarded to your Salesforce administrator.
Yes. Sandbox or production is an explicit choice at connection time, documented in the setup guide, so your team can validate the full workflow (capture, enrichment, sync, field mapping) in your test environment before touching production.
Yes. Popl publishes its full DPA as a public web page, so you don't have to request it. The DPA includes SCCs with the UK addendum and defines the data categories Popl processes. The complete subprocessor list is published from a single canonical source and shows each vendor's function and location, including hosting (AWS, GCP) and AI enrichment (Anthropic). See all subprocessors.
Popl commits to breach notification within 72 hours, published in full in its public DPA. Annual penetration testing with remediation SLAs is part of its monitored controls, published in the Trust Center. Visit the Trust Center.
Popl's GDPR Sensitivity Mode displays a consent prompt before any scan, whether via badge, card, or QR code. The prompt text is customizable, capture forms include an automatic consent checkbox, and it's all admin-controlled. When a contact revokes consent, their lead is deleted in Popl. Read the privacy policy.
Onboarding runs on a custom 30-day plan with a dedicated CSM for certain Event Lead Capture Teams plans. Week one covers setup: team training, your first Event Flow, and connecting your integrations. By week two, your team captures, enriches, and syncs leads at your first event. The CRM connection is made once, at the company level, with no package to install. During week three, your CSM guides the team through measuring event ROI.