{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"facilityos","name":"FacilityOS","domain":"facilityos.com","category":"IT management","one_liner":"FacilityOS is the leading visitor & facility management platform, trusted by global enterprises to optimize key facility processes for","trust_center_url":"https://trust.facilityos.com/","security_page_url":null,"url":"https://certreports.com/vendors/facilityos/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"hipaa","framework_name":"HIPAA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states that it will sign a business associate agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/facilityos/hipaa","evidence":[{"source_type":"trust_center","source_name":"FacilityOS trust centre (Vanta)","url":"https://trust.facilityos.com/","fetched_at":"2026-09-18 23:08:33.244533+00","content_hash":"f5149264cd334238d091dc164fca1a9ff658dad922024e64da3884ca7a0e9ee0","wayback_url":null,"quote":"HIPAA","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/facilityos/gdpr","evidence":[{"source_type":"trust_center","source_name":"FacilityOS trust centre (Vanta)","url":"https://trust.facilityos.com/","fetched_at":"2026-09-18 23:08:33.244533+00","content_hash":"f5149264cd334238d091dc164fca1a9ff658dad922024e64da3884ca7a0e9ee0","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27001 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/facilityos/iso-27001","evidence":[{"source_type":"trust_center","source_name":"FacilityOS trust centre (Vanta)","url":"https://trust.facilityos.com/","fetched_at":"2026-09-18 23:08:33.244533+00","content_hash":"f5149264cd334238d091dc164fca1a9ff658dad922024e64da3884ca7a0e9ee0","wayback_url":null,"quote":"ISO 27001","confidence":1}]},{"framework":"cyber-essentials","framework_name":"Cyber Essentials","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an Cyber Essentials certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states UK Cyber Essentials on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/facilityos/cyber-essentials","evidence":[{"source_type":"trust_center","source_name":"FacilityOS trust centre (Vanta)","url":"https://trust.facilityos.com/","fetched_at":"2026-09-18 23:08:33.244533+00","content_hash":"f5149264cd334238d091dc164fca1a9ff658dad922024e64da3884ca7a0e9ee0","wayback_url":null,"quote":"UK Cyber Essentials","confidence":1}]},{"framework":"iso-27701","framework_name":"ISO/IEC 27701","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27701 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27701 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/facilityos/iso-27701","evidence":[{"source_type":"trust_center","source_name":"FacilityOS trust centre (Vanta)","url":"https://trust.facilityos.com/","fetched_at":"2026-09-18 23:08:33.244533+00","content_hash":"f5149264cd334238d091dc164fca1a9ff658dad922024e64da3884ca7a0e9ee0","wayback_url":null,"quote":"ISO 27701","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: EU-US Certification","issued_at":"2026-06-04","expires_at":"2027-06-04","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/facilityos/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/10064","fetched_at":"2026-09-17 15:51:26.959726+00","content_hash":"6a02a14ec0fbad25bef24db7ed4b44fe32782985d6e97cc0360b7f60a6ecf25a","wayback_url":null,"quote":"FacilityOS: Active: EU-US Certification","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/facilityos/security","evidence":[{"source_type":"trust_center","source_name":"FacilityOS trust centre (Vanta)","url":"https://trust.facilityos.com/","fetched_at":"2026-09-18 23:08:33.244533+00","content_hash":"f5149264cd334238d091dc164fca1a9ff658dad922024e64da3884ca7a0e9ee0","wayback_url":null,"quote":"CCPA","confidence":1}]}],"brief":null,"legal_docs":[{"kind":"subprocessors","url":"https://trust.facilityos.com/","availability":"public","detail":"5 subprocessors listed on the trust centre","as_of":"2026-09-18"},{"kind":"privacy","url":"https://www.facilityos.com/privacy-policy","availability":"public","detail":null,"as_of":"2026-09-18"}],"subprocessors":[{"name":"MailGun","domain":"mailgun.com","purpose":"Email notifications","location":"USA or EU","vendor_url":"https://certreports.com/vendors/mailgun/security"},{"name":"Microsoft Azure","domain":"microsoft.com","purpose":"Cloud Infrastructure provider. ","location":"USA or EU","vendor_url":"https://certreports.com/vendors/microsoft/security"},{"name":"SendGrid","domain":"sendgrid.com","purpose":"Email notifications","location":null,"vendor_url":"https://certreports.com/vendors/sendgrid/security"},{"name":"Twilio","domain":"twilio.com","purpose":"Engineering","location":null,"vendor_url":"https://certreports.com/vendors/twilio/security"},{"name":"Vonage","domain":"vonage.com","purpose":"IT","location":"EU","vendor_url":"https://certreports.com/vendors/vonage/security"}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T00:25:50.595Z"}