{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"deepnote","name":"Deepnote","domain":"deepnote.com","category":"AI tools","one_liner":"A better data science notebook.","trust_center_url":"https://security.deepnote.com/","security_page_url":null,"url":"https://certreports.com/vendors/deepnote/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"hipaa","framework_name":"HIPAA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states that it will sign a business associate agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/deepnote/hipaa","evidence":[{"source_type":"trust_center","source_name":"Deepnote trust centre (Vanta)","url":"https://security.deepnote.com/","fetched_at":"2026-09-18 23:17:33.28364+00","content_hash":"0a8b8bd606c1167ba8d331c54f4410e0bb13a0b76bb5abd732ef790b507c723b","wayback_url":null,"quote":"HIPAA","confidence":1}]},{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type II on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/deepnote/soc-2","evidence":[{"source_type":"trust_center","source_name":"Deepnote trust centre (Vanta)","url":"https://security.deepnote.com/","fetched_at":"2026-09-18 23:17:33.28364+00","content_hash":"0a8b8bd606c1167ba8d331c54f4410e0bb13a0b76bb5abd732ef790b507c723b","wayback_url":null,"quote":"SOC 2 Type I","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/deepnote/gdpr","evidence":[{"source_type":"trust_center","source_name":"Deepnote trust centre (Vanta)","url":"https://security.deepnote.com/","fetched_at":"2026-09-18 23:17:33.28364+00","content_hash":"0a8b8bd606c1167ba8d331c54f4410e0bb13a0b76bb5abd732ef790b507c723b","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/deepnote/security","evidence":[{"source_type":"trust_center","source_name":"Deepnote trust centre (Vanta)","url":"https://security.deepnote.com/","fetched_at":"2026-09-18 23:17:33.28364+00","content_hash":"0a8b8bd606c1167ba8d331c54f4410e0bb13a0b76bb5abd732ef790b507c723b","wayback_url":null,"quote":"CCPA","confidence":1}]}],"brief":null,"legal_docs":[{"kind":"subprocessors","url":"https://security.deepnote.com/","availability":"public","detail":"19 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Amazon Web Services","domain":"amazon.com","purpose":"Cloud infrastructure","location":"United States","vendor_url":"https://certreports.com/vendors/amazon/security"},{"name":"Anthropic","domain":"anthropic.com","purpose":"AI services","location":"United States","vendor_url":null},{"name":"ChartMogul","domain":"chartmogul.com","purpose":"Revenue analytics","location":"EU","vendor_url":null},{"name":"Google Cloud Platform","domain":"google.com","purpose":"Cloud infrastructure","location":"United States","vendor_url":null},{"name":"Google Workspace","domain":"google.com","purpose":"Productivity & communication tools","location":"United States","vendor_url":null},{"name":"Hetzner Cloud","domain":"hetzner.com","purpose":"Cloud infrastructure\t","location":"EU","vendor_url":null},{"name":"HubSpot","domain":"hubspot.com","purpose":"CRM & marketing automation","location":"United States","vendor_url":"https://certreports.com/vendors/hubspot/security"},{"name":"Intercom","domain":"intercom.com","purpose":"Customer support","location":"United States","vendor_url":"https://certreports.com/vendors/intercom/security"},{"name":"Mailgun","domain":"mailgun.com","purpose":"Transactional email","location":"United States","vendor_url":"https://certreports.com/vendors/mailgun/security"},{"name":"Microsoft Azure","domain":"microsoft.com","purpose":"Cloud infrastructure & AI","location":"United States","vendor_url":"https://certreports.com/vendors/microsoft/security"},{"name":"Mistral AI","domain":"mistral.ai","purpose":"AI Service","location":"EU","vendor_url":null},{"name":"Open AI","domain":"openai.com","purpose":"AI services","location":"United States","vendor_url":"https://certreports.com/vendors/openai/security"},{"name":"PostHog","domain":"posthog.com","purpose":"Product analytics","location":"United States","vendor_url":"https://certreports.com/vendors/posthog/security"},{"name":"ProductBoard","domain":"productboard.com","purpose":"Product management","location":"United States","vendor_url":"https://certreports.com/vendors/productboard/security"},{"name":"Sentry","domain":"sentry.com","purpose":"Error monitoring","location":"United States","vendor_url":null},{"name":"Sprig","domain":"sprig.com","purpose":"Product feedback","location":"United States","vendor_url":"https://certreports.com/vendors/sprig/security"},{"name":"Stitch","domain":"stitchdata.com","purpose":"Data pipelines (ETL)","location":"United States","vendor_url":"https://certreports.com/vendors/stitch-inc/security"},{"name":"Stripe","domain":"stripe.com","purpose":"Payment processing","location":"United States","vendor_url":"https://certreports.com/vendors/stripe/security"},{"name":"WorkOS","domain":"workos.com","purpose":"Authentication (SSO, SCIM)","location":"United States","vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T09:49:30.582Z"}