{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"everlaw","name":"Everlaw","domain":"everlaw.com","category":"Legal tech","one_liner":"Transform your approach to litigation and","trust_center_url":"https://trust.everlaw.com/","security_page_url":null,"url":"https://certreports.com/vendors/everlaw/security","last_verified_at":"2026-09-19T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/everlaw/soc-2","evidence":[{"source_type":"trust_center","source_name":"Everlaw trust centre (Vanta)","url":"https://trust.everlaw.com/","fetched_at":"2026-09-18 23:04:25.322961+00","content_hash":"2536582e537135a26dc439934e6f2bfcfd61f0265485c9c44df6fdb9b39eacec","wayback_url":null,"quote":"SOC 2 Type 2","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/everlaw/gdpr","evidence":[{"source_type":"trust_center","source_name":"Everlaw trust centre (Vanta)","url":"https://trust.everlaw.com/","fetched_at":"2026-09-18 23:04:25.322961+00","content_hash":"2536582e537135a26dc439934e6f2bfcfd61f0265485c9c44df6fdb9b39eacec","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"fedramp","framework_name":"FedRAMP","state":"verified_registry","state_label":"Verified","sentence":"Listed in the FedRAMP Marketplace as of 19 Sep 2026.","kind":"authorization","status_text":"FedRAMP Authorized","issued_at":"2020-07-17","expires_at":null,"period_start":null,"period_end":null,"auditor":"Kratos","impact_level":"Moderate","as_of":"2026-09-19","under_review":false,"source":"fedramp","url":"https://certreports.com/vendors/everlaw/fedramp","evidence":[{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR1916055736","fetched_at":"2026-09-19 08:30:01.700532+00","content_hash":"b2bb3e031fda16f1f3201a5640ae64a639a15e4997f9d1ca43ef13a2942600e6","wayback_url":null,"quote":"Everlaw, Inc. - Everlaw Platform: FedRAMP Authorized","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR1916055736","fetched_at":"2026-09-18 22:35:17.44827+00","content_hash":"db2d03fa40cba0e5287b9cc7361e71b7c30c7ca9d51efb7b540477105fb30c7b","wayback_url":null,"quote":"Everlaw, Inc. - Everlaw Platform: FedRAMP Authorized","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR1916055736","fetched_at":"2026-09-17 15:44:39.301965+00","content_hash":"395e7ad35dd25d1c547414140161c47ec22827b7ffae3bdbbd5256c38a3b940f","wayback_url":null,"quote":"Everlaw, Inc. - Everlaw Platform: FedRAMP Authorized","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/everlaw/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Everlaw trust centre (Vanta)","url":"https://trust.everlaw.com/","fetched_at":"2026-09-18 23:04:25.322961+00","content_hash":"2536582e537135a26dc439934e6f2bfcfd61f0265485c9c44df6fdb9b39eacec","wayback_url":null,"quote":"ISO 27001:2022","confidence":1}]},{"framework":"soc-3","framework_name":"SOC 3","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a public SOC 3 report on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 3 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/everlaw/security","evidence":[{"source_type":"trust_center","source_name":"Everlaw trust centre (Vanta)","url":"https://trust.everlaw.com/","fetched_at":"2026-09-18 23:04:25.322961+00","content_hash":"2536582e537135a26dc439934e6f2bfcfd61f0265485c9c44df6fdb9b39eacec","wayback_url":null,"quote":"SOC 3","confidence":1}]},{"framework":"iso-27017","framework_name":"ISO/IEC 27017","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27017 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27017:2015 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/everlaw/security","evidence":[{"source_type":"trust_center","source_name":"Everlaw trust centre (Vanta)","url":"https://trust.everlaw.com/","fetched_at":"2026-09-18 23:04:25.322961+00","content_hash":"2536582e537135a26dc439934e6f2bfcfd61f0265485c9c44df6fdb9b39eacec","wayback_url":null,"quote":"ISO 27017:2015","confidence":1}]},{"framework":"iso-27018","framework_name":"ISO/IEC 27018","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27018 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27018:2019 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/everlaw/security","evidence":[{"source_type":"trust_center","source_name":"Everlaw trust centre (Vanta)","url":"https://trust.everlaw.com/","fetched_at":"2026-09-18 23:04:25.322961+00","content_hash":"2536582e537135a26dc439934e6f2bfcfd61f0265485c9c44df6fdb9b39eacec","wayback_url":null,"quote":"ISO 27018:2019","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: EU-US Certification, SW-US Certification, UK Extension Certification","issued_at":"2024-05-08","expires_at":"2027-04-01","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/everlaw/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/8835","fetched_at":"2026-09-17 15:50:45.907184+00","content_hash":"4dedf9a046bce626566bd4df0d809d466ecb0a966ab8fb130b6226f2ae6951e3","wayback_url":null,"quote":"Everlaw: Active: EU-US Certification, SW-US Certification, UK Extension Certification","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/everlaw/security","evidence":[{"source_type":"trust_center","source_name":"Everlaw trust centre (Vanta)","url":"https://trust.everlaw.com/","fetched_at":"2026-09-18 23:04:25.322961+00","content_hash":"2536582e537135a26dc439934e6f2bfcfd61f0265485c9c44df6fdb9b39eacec","wayback_url":null,"quote":"CCPA","confidence":1}]},{"framework":"govramp","framework_name":"GovRAMP","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an GovRAMP authorization on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GovRAMP on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/everlaw/security","evidence":[{"source_type":"trust_center","source_name":"Everlaw trust centre (Vanta)","url":"https://trust.everlaw.com/","fetched_at":"2026-09-18 23:04:25.322961+00","content_hash":"2536582e537135a26dc439934e6f2bfcfd61f0265485c9c44df6fdb9b39eacec","wayback_url":null,"quote":"GovRAMP","confidence":1}]},{"framework":"cyber-essentials-plus","framework_name":"Cyber Essentials Plus","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an Cyber Essentials Plus certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states Cyber Essentials Plus on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/everlaw/security","evidence":[{"source_type":"trust_center","source_name":"Everlaw trust centre (Vanta)","url":"https://trust.everlaw.com/","fetched_at":"2026-09-18 23:04:25.322961+00","content_hash":"2536582e537135a26dc439934e6f2bfcfd61f0265485c9c44df6fdb9b39eacec","wayback_url":null,"quote":"Cyber Essentials Plus","confidence":1}]}],"brief":{"summary":"As of 17 Sep 2026, Everlaw is listed in the FedRAMP registry as FedRAMP Authorized, with an original authorization date of 17 Jul 2020 and audit involvement from Kratos. As of 17 Sep 2026, Everlaw is listed in the EU-US Data Privacy Framework registry as Active, covering EU-US, Swiss-US, and UK Extension Certifications, issued 8 May 2024 and expiring 1 Apr 2027. As of 17 Sep 2026, no public evidence found for SOC 2 for Everlaw. As of 17 Sep 2026, no public evidence found for HIPAA for Everlaw. As of 17 Sep 2026, no subprocessor records were found in the evidence provided for Everlaw.","bullets":["FedRAMP: listed in FedRAMP registry as FedRAMP Authorized (issued 17 Jul 2020; auditor Kratos) as of 17 Sep 2026.","EU-US Data Privacy Framework: listed in DPF registry as Active (EU-US, SW-US, UK Extension), issued 8 May 2024, expires 1 Apr 2027, as of 17 Sep 2026.","SOC 2 and HIPAA: no public evidence found as of 17 Sep 2026."],"model":"claude-sonnet-5","generated_at":"2026-09-17 18:49:42.629599+00"},"legal_docs":[{"kind":"subprocessors","url":"https://trust.everlaw.com/","availability":"public","detail":"5 subprocessors listed on the trust centre","as_of":"2026-09-18"},{"kind":"privacy","url":"https://www.everlaw.com/legal/customer-terms-of-service/","availability":"public","detail":null,"as_of":"2026-09-18"},{"kind":"security_txt","url":"https://trust.everlaw.com/","availability":"public","detail":"Public documents on the trust centre: Everlaw SOC 3; ISO 27001:2022 Certificate; ISO/IEC 27017:2015; ISO 27018:2019; Cyber Essentials Plus","as_of":"2026-09-18"}],"subprocessors":[{"name":"AWS","domain":"aws.com","purpose":"Cloud provider","location":"United States, United Kingdom, EU (Germany), Canada, and Australia","vendor_url":null},{"name":"Google Workspace","domain":"google.com","purpose":"Identity provider","location":"United States  EU (only for Customers on Everlaw’s UK or EU instances)","vendor_url":null},{"name":"OpenAI, L.L.C.","domain":"openai.com","purpose":"Engineering","location":"United States  EU (only for Customers on Everlaw’s UK or EU instances)","vendor_url":"https://certreports.com/vendors/openai/security"},{"name":"Pinecone","domain":"pinecone.io","purpose":"Vector Database","location":"United States","vendor_url":null},{"name":"Zendesk - Everlaw HR Support","domain":"zendesk.com","purpose":"Customer support","location":"United States                                               ","vendor_url":"https://certreports.com/vendors/zendesk/security"}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-20T06:08:13.957Z"}