{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"clio","name":"Clio","domain":"clio.com","category":"Legal tech","one_liner":null,"trust_center_url":"https://trust.clio.com/","security_page_url":null,"url":"https://certreports.com/vendors/clio/security","last_verified_at":"2026-09-19T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"hipaa","framework_name":"HIPAA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states that it will sign a business associate agreement on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/clio/hipaa","evidence":[{"source_type":"trust_center","source_name":"Clio trust centre (Drata)","url":"https://trust.clio.com/","fetched_at":"2026-09-19 07:33:15.86312+00","content_hash":"f890351b266b8b5fb1451a55940cc451d064d02210099c6f123ce44a07bffe4a","wayback_url":null,"quote":"HIPAA","confidence":1}]},{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Drata) as of 19 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/clio/soc-2","evidence":[{"source_type":"trust_center","source_name":"Clio trust centre (Drata)","url":"https://trust.clio.com/","fetched_at":"2026-09-19 07:33:15.86312+00","content_hash":"f890351b266b8b5fb1451a55940cc451d064d02210099c6f123ce44a07bffe4a","wayback_url":null,"quote":"SOC 2 Type 2","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/clio/gdpr","evidence":[{"source_type":"trust_center","source_name":"Clio trust centre (Drata)","url":"https://trust.clio.com/","fetched_at":"2026-09-19 07:33:15.86312+00","content_hash":"f890351b266b8b5fb1451a55940cc451d064d02210099c6f123ce44a07bffe4a","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"soc-1","framework_name":"SOC 1","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 1 Type II report on its trust centre (Drata) as of 19 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 1 Type 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/clio/security","evidence":[{"source_type":"trust_center","source_name":"Clio trust centre (Drata)","url":"https://trust.clio.com/","fetched_at":"2026-09-19 07:33:15.86312+00","content_hash":"f890351b266b8b5fb1451a55940cc451d064d02210099c6f123ce44a07bffe4a","wayback_url":null,"quote":"SOC 1 Type 2","confidence":1}]},{"framework":"txramp","framework_name":"TX-RAMP","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an TX-RAMP certification on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states TX-RAMP on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/clio/security","evidence":[{"source_type":"trust_center","source_name":"Clio trust centre (Drata)","url":"https://trust.clio.com/","fetched_at":"2026-09-19 07:33:15.86312+00","content_hash":"f890351b266b8b5fb1451a55940cc451d064d02210099c6f123ce44a07bffe4a","wayback_url":null,"quote":"TX-RAMP","confidence":1}]}],"brief":{"summary":"Clio's trust centre states, as of 19 Sep 2026, that the company displays a HIPAA badge, though the evidence on file does not confirm whether a BAA is offered. According to Clio's trust centre, as of 19 Sep 2026, the company has a SOC 2 Type II report on file. Clio's trust centre also states, as of 19 Sep 2026, that the company meets GDPR requirements. As of 19 Sep 2026, Clio states on its trust centre that it has a SOC 1 Type II report on file. Clio's trust centre further states, as of 19 Sep 2026, that the company holds TX-RAMP.","bullets":["HIPAA: vendor displays a badge on trust centre; BAA availability not confirmed, as of 19 Sep 2026","SOC 2 Type II and SOC 1 Type II reports: vendor states on trust centre, as of 19 Sep 2026","GDPR and TX-RAMP: vendor states on trust centre, as of 19 Sep 2026"],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 10:38:09.906817+00"},"legal_docs":[],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T11:57:29.714Z"}