{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"elevenlabs","name":"ElevenLabs","domain":"elevenlabs.io","category":"AI tools","one_liner":"ElevenLabs Inc. is a software company that specializes in developing natural-sounding speech synthesis software using deep learning","trust_center_url":"https://compliance.elevenlabs.io:443/","security_page_url":null,"url":"https://certreports.com/vendors/elevenlabs/security","last_verified_at":"2026-09-19T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"hipaa","framework_name":"HIPAA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states that it will sign a business associate agreement on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/hipaa","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"HIPAA","confidence":1}]},{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 19 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/soc-2","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"SOC 2 Type 2","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/gdpr","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS 4.0.1 Level 1 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/pci-dss","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"PCI DSS 4.0.1 Level 1","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/iso-27001","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"ISO 27001:2022","confidence":1}]},{"framework":"csa-star","framework_name":"CSA STAR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a CSA STAR Level 1 self-assessment on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states CSA STAR L1 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/csa-star","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"CSA STAR L1","confidence":1}]},{"framework":"iso-27701","framework_name":"ISO/IEC 27701","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27701 certificate on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27701:2019 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/iso-27701","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"ISO 27701:2019","confidence":1}]},{"framework":"iso-42001","framework_name":"ISO/IEC 42001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 42001 certificate on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 42001:2023 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/iso-42001","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"ISO/IEC 42001:2023","confidence":1}]},{"framework":"iso-27017","framework_name":"ISO/IEC 27017","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27017 certificate on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27017:2015 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/security","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"ISO 27017:2015","confidence":1}]},{"framework":"iso-27018","framework_name":"ISO/IEC 27018","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27018 certificate on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27018:2019 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/security","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"ISO 27018:2019","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states CPRA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/security","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"CCPA","confidence":1}]},{"framework":"txramp","framework_name":"TX-RAMP","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an TX-RAMP certification on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states TX-RAMP Level 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/security","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"TX-RAMP Level 2","confidence":1}]},{"framework":"cyber-essentials-plus","framework_name":"Cyber Essentials Plus","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an Cyber Essentials Plus certificate on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states UK Cyber Essentials Plus on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/security","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"UK Cyber Essentials Plus","confidence":1}]},{"framework":"hds","framework_name":"HDS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an HDS certificate on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states HDS on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/security","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"HDS","confidence":1}]},{"framework":"nhs-dspt","framework_name":"NHS DSPT","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an NHS DSPT assessment on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states NHS DSPT on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/elevenlabs/security","evidence":[{"source_type":"trust_center","source_name":"ElevenLabs trust centre (Vanta)","url":"https://compliance.elevenlabs.io:443/","fetched_at":"2026-09-19 07:32:38.002395+00","content_hash":"42f1c04cf3fdc9f6b777f9f5d391b92926039df7e10ad444c929da18deb9cb33","wayback_url":null,"quote":"NHS DSPT","confidence":1}]}],"brief":{"summary":"ElevenLabs states on its trust centre, as of 19 Sep 2026, that it has a SOC 2 Type II report, alongside stated GDPR and CCPA/CPRA compliance. As of 19 Sep 2026, the vendor also states ISO/IEC 27001:2022, ISO/IEC 27701:2019, ISO/IEC 27017:2015, ISO/IEC 27018:2019, and ISO/IEC 42001:2023 on its trust centre. As of 19 Sep 2026, ElevenLabs states PCI DSS 4.0.1 Level 1 and CSA STAR L1 on its trust centre. As of 19 Sep 2026, the vendor also states TX-RAMP Level 2, UK Cyber Essentials Plus, HDS, and NHS DSPT on its trust centre. As of 19 Sep 2026, ElevenLabs displays a HIPAA badge on its trust centre, though BAA availability is not captured in the evidence.","bullets":["SOC 2 Type II, ISO/IEC 27001:2022, 27701:2019, 27017:2015, 27018:2019, 42001:2023: vendor states on its trust centre, as of 19 Sep 2026.","PCI DSS 4.0.1 Level 1, CSA STAR L1, TX-RAMP Level 2, UK Cyber Essentials Plus, HDS, NHS DSPT, GDPR, CCPA/CPRA: vendor states on its trust centre, as of 19 Sep 2026.","HIPAA: vendor displays a badge on its trust centre as of 19 Sep 2026; BAA availability not captured in evidence."],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 10:36:06.130913+00"},"legal_docs":[{"kind":"privacy","url":"https://elevenlabs.io/privacy-policy","availability":"public","detail":null,"as_of":"2026-09-19"},{"kind":"security_txt","url":"https://compliance.elevenlabs.io:443/","availability":"public","detail":"Public documents on the trust centre: 2025 SOC 3 Report Final.pdf; ISO 27001/17/18 - ISMS Certificate - ElevenLabs.pdf; ISO 27701 - PIMS Certificate - Eleven Labs.pdf; ISO 42001 - AIMS Certificate - Eleven Labs.pdf; Cyber Essentials Plus Certificate 2025.pdf; Cyber Essentials Certificate 2025.pdf","as_of":"2026-09-19"},{"kind":"subprocessors","url":"https://compliance.elevenlabs.io:443/","availability":"public","detail":"29 subprocessors listed on the trust centre","as_of":"2026-09-19"}],"subprocessors":[{"name":"Anthropic","domain":"anthropic.com","purpose":"LLM Services","location":"United States","vendor_url":"https://certreports.com/vendors/anthropic/security"},{"name":"Asana","domain":"asana.com","purpose":"Collaboration","location":"US","vendor_url":"https://certreports.com/vendors/asana/security"},{"name":"AWS","domain":"aws.com","purpose":"Cloud infrastructure & data storage ","location":"Enterprise: US or Customer's Selected Hosting Location; Non-Enterprise: US, EU or Singapore","vendor_url":null},{"name":"Azure","domain":"azure.com","purpose":"Cloud infrastructure, data storage & LLM Services","location":"India","vendor_url":null},{"name":"ByteDance","domain":"bytedance.com","purpose":"Generation and processing of synthetic media content","location":"Indonesia, Malaysia, EU","vendor_url":null},{"name":"Cinder","domain":"cinder.co","purpose":"Moderation","location":"EU","vendor_url":null},{"name":"Creatify","domain":"creatify.ai","purpose":"Generation and processing of synthetic media content","location":"United States","vendor_url":null},{"name":"ElevenLabs Affiliates","domain":"elevenlabs.io","purpose":"Affiliates","location":"Global","vendor_url":"https://certreports.com/vendors/elevenlabs/security"},{"name":"Fal","domain":"fal.ai","purpose":"Generation and processing of synthetic media content","location":"Global","vendor_url":null},{"name":"Fivetran","domain":"fivetran.com","purpose":"Data processing","location":"US","vendor_url":"https://certreports.com/vendors/fivetran/security"},{"name":"Google Cloud Platform","domain":"google.com","purpose":"Cloud infrastructure, security, data storage & LLM Services","location":"Enterprise: US or Customer's Selected Hosting Location; Non-Enterprise: US, EU or Singapore","vendor_url":"https://certreports.com/vendors/google/security"},{"name":"Hive","domain":"thehive.ai","purpose":"AI Safety","location":"United States","vendor_url":null},{"name":"Kling","domain":"kling.ai","purpose":"Generation and processing of synthetic media content","location":"Singapore","vendor_url":null},{"name":"MongoDB","domain":"mongodb.com","purpose":"Engineering","location":"Enterprise: US or Customer's Selected Hosting Location; Non-Enterprise: US, EU or Singapore","vendor_url":"https://certreports.com/vendors/mongodb/security"},{"name":"OpenAI","domain":null,"purpose":"LLM Services","location":"US/EU","vendor_url":null},{"name":"OWND ApS (ParaHelp)","domain":"parahelp.com","purpose":"Customer support","location":"US","vendor_url":"https://certreports.com/vendors/parahelp/security"},{"name":"Plain","domain":"plain.com","purpose":"Customer support","location":"United Kingdom","vendor_url":null},{"name":"PostHog","domain":null,"purpose":"Cloud monitoring","location":"EU","vendor_url":null},{"name":"Pylon","domain":"usepylon.com","purpose":"Customer support","location":"US","vendor_url":"https://certreports.com/vendors/pylon-usepylon/security"},{"name":"Runway","domain":"runwayml.com","purpose":"Generation and processing of synthetic media content","location":"United States","vendor_url":"https://certreports.com/vendors/runway/security"},{"name":"Sigma","domain":null,"purpose":"Analytics","location":"US","vendor_url":null},{"name":"Slack","domain":"slack.com","purpose":"Collaboration","location":"US","vendor_url":"https://certreports.com/vendors/slack-technologies/security"},{"name":"Stripe","domain":null,"purpose":"Payments","location":"US","vendor_url":null},{"name":"Sync","domain":"sync.so","purpose":"Generation and processing of synthetic media content","location":"United States","vendor_url":"https://certreports.com/vendors/sync/security"},{"name":"Trustpilot","domain":"trustpilot.com","purpose":"Reviews","location":"EU","vendor_url":null},{"name":"Twilio","domain":"twilio.com","purpose":"Communications","location":"US","vendor_url":"https://certreports.com/vendors/twilio/security"},{"name":"xAI","domain":"x.ai","purpose":"LLM Services","location":"US","vendor_url":"https://certreports.com/vendors/xai/security"},{"name":"Zapier","domain":"zapier.com","purpose":"Collaboration","location":"US","vendor_url":"https://certreports.com/vendors/zapier/security"},{"name":"Zendesk","domain":null,"purpose":"Customer Support","location":"US","vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-20T22:36:39.970Z"}