Try HighLevel

GoHighLevel security: certifications and account protections

Platform-wide on every plan. HIPAA safeguards and a BAA need the separate HIPAA add-on (included in Enterprise). Included. The optional HIPAA add-on is $297/month.

We earn a commission if you buy HighLevel through our links, at no extra cost to you. How we make money

Our pick for most agencies

HighLevel Unlimited

$297 a month, or $2,970 a year

  • Unlimited client sub-accounts, unlimited users and contacts
  • CRM, funnels, websites, calendars, reviews
  • Texting, calling and email billed by usage
  • Upgrade to Agency Pro for SaaS Mode
Try HighLevel

HighLevel offers a 14 day free trial on every plan. Card required.

The short answer

GoHighLevel security, as HighLevel describes it, rests on a SOC 2 Type II attestation covering security, confidentiality and availability, announced in February 2026, an ISO/IEC 27001:2022 certificate listed in its security overview, and encryption with TLS 1.2 or higher in transit and AES-256 at rest. Accounts can use two-factor authentication by phone, email or an authenticator app, plus single sign-on, user permissions and audit logs. HighLevel states it is not PCI-DSS compliant because it does not store card data; payments run through processors.

Plans Platform-wide on every plan. HIPAA safeguards and a BAA need the separate HIPAA add-on (included in Enterprise).
Cost Included. The optional HIPAA add-on is $297/month.
Checked 2026-09-29, against HighLevel's help center and pricing page

Certifications and attestations

HighLevel announced its SOC 2 Type II attestation on February 5, 2026, covering the Security, Confidentiality and Availability criteria. It says its information security management program began in April 2025 and the attestation was completed by the end of that year, and its privacy and security page states that it undergoes annual SOC 2 Type II assessments. HighLevel's security and compliance overview also lists an ISO/IEC 27001:2022 certificate, and the privacy and security page lists EU-U.S. Data Privacy Framework certification. The overview points to a Trust Center holding the SOC 2 report, security policies and other compliance material for vendor reviews.

Encryption and hosting

Data moving to and from HighLevel uses TLS 1.2 or 1.3 with 2,048-bit keys or better, and stored platform data is encrypted with AES-256. Passwords are hashed and encrypted at rest. HighLevel hosts its infrastructure with Google Cloud Platform and Amazon Web Services and says its product infrastructure resides in the United States. The privacy and security page adds DDoS mitigation and a web application firewall. HighLevel states it does not store, process or collect card information submitted to it and is not PCI-DSS compliant, so card payments go through connected processors such as Stripe.

Account protections you control

The settings that matter most are simple. Require 2FA for every user in the agency and in client sub-accounts, and prefer an authenticator app over text or email codes; HighLevel says app-based codes protect better against phishing and SIM-swap attacks. Then give each user the narrowest role and permissions that fit their job, and remove logins when staff leave. Audit logs record user logins, HighLevel employee access, security activity and content activity, which helps when a client asks who changed something.

  • Two-factor authentication by phone, email or any TOTP authenticator app, such as Google Authenticator, Microsoft Authenticator or Authy
  • Ten single-use backup codes, which can be regenerated from your profile
  • Portal administrators can require 2FA for all users
  • 2FA is required whenever a user's phone number is changed
  • Single sign-on, granular user permissions and audit logs

Testing, staff access and disclosure

HighLevel says it runs annual penetration tests against its applications and infrastructure, and its privacy and security page mentions regular third-party penetration testing and automated vulnerability scanning. It operates a responsible disclosure program, with vulnerability reports accepted at gohighlevel.com/reportbug. HighLevel staff reach customer portals through logged, just-in-time access requests limited to a maximum of 24 hours, and employee access uses role-based controls. Service incidents and outages are posted publicly on status.gohighlevel.com, which is worth checking before blaming a client's setup for a delivery problem.

Where platform security stops

Platform security and compliant use are separate questions. SOC 2 and ISO 27001 describe HighLevel's own controls; they do not make a client's texting program meet TCPA rules or a clinic meet HIPAA. For protected health information, HighLevel sells a HIPAA add-on at $297 a month that includes a BAA, and US business texting on local numbers requires A2P 10DLC registration. Buyers who need evidence for a vendor security review can start with HighLevel's security and compliance overview and its Trust Center rather than relying on a sales summary.

Costs add up differently for every account. Put your numbers into the HighLevel cost calculator, or browse every HighLevel feature.

Cost your account Try HighLevel

Questions

Is GoHighLevel SOC 2 compliant?
HighLevel reports a SOC 2 Type II attestation covering security, confidentiality and availability, announced on February 5, 2026, and says it undergoes annual SOC 2 Type II assessments. Its security overview points to a Trust Center for the SOC 2 report and related documents, which is where a buyer running a vendor review should look.
Does GoHighLevel support two-factor authentication?
Yes. Users can verify with a phone number, email or any TOTP authenticator app such as Google Authenticator, Microsoft Authenticator or Authy, and get ten single-use backup codes. Portal administrators can require 2FA for all users, and HighLevel requires 2FA whenever a user's phone number is changed.
Where is GoHighLevel data stored?
HighLevel says its product infrastructure is hosted by Google Cloud Platform and Amazon Web Services and resides in the United States. Data is encrypted with TLS 1.2 or higher in transit and AES-256 at rest. Clients with data residency requirements outside the US should raise them with HighLevel before signing up.
Is GoHighLevel PCI compliant?
No. HighLevel's security overview states that it does not store, process or collect credit card information submitted to it and is not PCI-DSS compliant. Card payments are handled by the payment processor you connect, such as Stripe, PayPal, NMI, Authorize.net or Square, under that processor's own compliance.

Sources

  1. HighLevel: Security and compliance overview
  2. HighLevel: SOC 2 Type II certification
  3. HighLevel blog: HighLevel is now SOC 2 Type II certified
  4. HighLevel: Data privacy and security
  5. HighLevel: Authenticator app support for 2FA
  6. HighLevel: Mandatory 2FA for phone number updates
  7. HighLevel pricing page

HighLevel from $97 a month14 day free trial on every plan

Try HighLevel