Gradual Community
Ask

Let’s talk specifics

Security, SSO, integrations, accessibility, and other key details to help you evaluate whether Gradual is the right fit.

SOC 2 Certified

Role-based Access

20+ Native Connectors

Frequently asked questions

Security & Privacy

Is Gradual SOC2 compliant?

Yes. Gradual maintains SOC2 Type II certification. Gradual is audited annually by Prescient Assurance.

Additionally, we conduct annual penetration testing on the platform and have a formal vulnerability reporting program.

Copies of Gradual's SOC2 reports are available via request by emailing [email protected].

Explore our full security and compliance summary.

Where is Gradual-hosted data stored?

Our services are hosted and operated in the United States, and personal data is hosted on U.S. servers.

For each of our customers, we have a Data Processing Agreement (DPA) that covers international transfers, the categories of data we collect, how we share it, how long we retain it, and the privacy rights that may apply.

How long do you retain personal data?

Data is retained for the duration of your agreement with Gradual or until you request deletion.

You may request deletion at any time. Once the request is confirmed, we remove their profile and personal information, event registrations and tickets, course progress, and reward data. Posts and comments that remain are anonymized and attributed to “Deleted User.”

If your team needs retention periods by data category, including backups, please reach out to our team via [email protected].

Review account deletion details.

Can members view, delete, or update their data?

Yes. Members can download, update, or delete their own data.

Members can view, edit, and download their personal data directly from their account settings within Gradual. Members can also request account deletion via their community settings as well.

Any other deletion or data subject access rights requests can be sent to [email protected].

Read more about downloading member data and user deletion.

How do you handle cookies and consent?

We include tenant-level cookie controls for public pages. Visitors can accept all cookies, reject optional cookies, or choose which categories to allow. We also offer native connections with OneTrust and Ketch.

Review cookie and consent management

Is a DPA available?

Yes. Request our current DPA, subprocessor list, and international-transfer documentation by reaching out to our team. International transfers may be covered by a data-processing agreement that incorporates the European Commission’s standard contractual clauses.

Can we export our data?

Yes. Administrators can export member lists as CSV files, including profile fields and activity dates. Event reports can also be exported for registrations, attendance, session viewing, check-ins, chat, Q&A, polls, matching, and other activity depending on the event type.

Member records are also available through our public API.

More on member exports.

Access & Permissions

Do you support single sign-on?

Yes. Gradual supports SSO integrations using OAuth 2.0 (including OpenID Connect / OIDC), JWT, and SAML 2.0 protocols.

SSO can be configured for both community-side (member login) and dashboard-side (admin login) authentication.

Review our SSO integration guide.

Do you support role-based access?

Yes. We provide different permission levels for dashboard administrators, collaborators, individual events, clubs, and specific content. This lets you grant full administrative access where it’s needed and narrower permissions for people responsible for limited work.

Review administrator roles and permissions.

Can member access also be restricted?

Yes. We support approved, pending, and unapproved account states, along with Standard, Guest, and Limited Approval member types. You can restrict content and experiences further through groups and Spaces.

Learn more.

Data & Integrations

Which connectors and integrations are available?

We have over 20 connectors and integration options across CRM, marketing, analytics, support, consent management, commerce, calendars, and learning.

These include Salesforce, HubSpot, Marketo, Google Analytics, Zapier, Slack, Zendesk, Intercom, and more.

Explore the complete catalog.

Can data sync in both directions?

It depends on the connector and the type of data moving between systems.

For example, we support one-way or bidirectional member-profile synchronization with Salesforce. Whereas our HubSpot integration sends activity from Gradual to HubSpot, while inbound HubSpot event registration uses a separate webhook flow.

Learn more.

Do you provide an API?

Yes. We maintain a public API. Tenant API credentials are available on request, and our documentation includes pagination and request-limit guidance for retrieving larger member lists.

Review our public API details or, see developer documentation.

Do you support outbound webhooks?

Yes. We can send real-time HTTP webhooks when supported events occur, including member creation, event registration, event attendance, waitlist activity, space membership changes, and forum posts.

Learn more.

How are webhook requests secured?

We include a timestamped signature with each webhook. Receiving systems can verify the signature using HMAC-SHA256 and the tenant’s secret key. Administrators can rotate that secret; during the documented 48-hour overlap, we create signatures with both the old and new secrets.

See: Webhook signature verification for more.

Can you connect to a system that is not listed?

Possibly. Our API, outbound webhooks, and documented automation options can support additional systems when the required data and events are available.

Before committing to a custom connection, confirm the required endpoints or webhook events, direction of data flow, expected timing, authentication, rate limits, error handling, and who will build and maintain it first.

Review public API and webhook details.

Accessibility

What accessibility standards do you support?

Gradual strives to meet or exceed Web Content Accessibility Guidelines (WCAG) 2.1, Level AA. This is a continuous process and we collaborate closely with our customers and user as we work toward this standard.

We support auto-generated English captions for livestreams, webinars, meeting rooms, and breakout rooms. Livestreams can also use human-generated CEA-608 captions embedded in an H.264 stream. Videos embedded from supported hosting services retain native controls such as captions, playback speed, quality, and volume.

Our branding guidance recommends selecting colors with sufficient contrast to meet WCAG 2 standards.

View our complete accessibility statement.