{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"cs-disco","name":"CS Disco","domain":"csdisco.com","category":"Legal tech","one_liner":"DISCO's AI-driven legal software and services raise the bar by offering cloud-based solutions developed by lawyers for","trust_center_url":"https://trust.csdisco.com/","security_page_url":null,"url":"https://certreports.com/vendors/cs-disco/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/cs-disco/soc-2","evidence":[{"source_type":"trust_center","source_name":"CS Disco trust centre (Drata)","url":"https://trust.csdisco.com/","fetched_at":"2026-09-18 22:45:17.150265+00","content_hash":"960478e1a65be1912921040fae234f16fe12347674f1e553d0a0a723be16c9a6","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/cs-disco/iso-27001","evidence":[{"source_type":"trust_center","source_name":"CS Disco trust centre (Drata)","url":"https://trust.csdisco.com/","fetched_at":"2026-09-18 22:45:17.150265+00","content_hash":"960478e1a65be1912921040fae234f16fe12347674f1e553d0a0a723be16c9a6","wayback_url":null,"quote":"ISO/IEC 27001:2022","confidence":1}]},{"framework":"iso-27701","framework_name":"ISO/IEC 27701","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27701 certificate on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27701 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/cs-disco/iso-27701","evidence":[{"source_type":"trust_center","source_name":"CS Disco trust centre (Drata)","url":"https://trust.csdisco.com/","fetched_at":"2026-09-18 22:45:17.150265+00","content_hash":"960478e1a65be1912921040fae234f16fe12347674f1e553d0a0a723be16c9a6","wayback_url":null,"quote":"ISO/IEC 27701","confidence":1}]},{"framework":"soc-3","framework_name":"SOC 3","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a public SOC 3 report on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 3 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/cs-disco/security","evidence":[{"source_type":"trust_center","source_name":"CS Disco trust centre (Drata)","url":"https://trust.csdisco.com/","fetched_at":"2026-09-18 22:45:17.150265+00","content_hash":"960478e1a65be1912921040fae234f16fe12347674f1e553d0a0a723be16c9a6","wayback_url":null,"quote":"SOC 3","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: EU-US Certification, SW-US Certification, UK Extension Certification","issued_at":"2018-07-30","expires_at":"2027-06-25","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/cs-disco/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/6110","fetched_at":"2026-09-17 15:49:21.86271+00","content_hash":"e015d4e11c019409e9b796feca1b896bc6f48bdbdbd27ca2b4546da9f006d09e","wayback_url":null,"quote":"CS Disco, Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification","confidence":1}]}],"brief":null,"legal_docs":[{"kind":"subprocessors","url":"https://trust.csdisco.com/","availability":"public","detail":"1 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Status Monitoring Amazon Web Services","domain":null,"purpose":null,"location":null,"vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T00:18:47.104Z"}