{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"formal","name":"Formal","domain":"joinformal.com","category":"Security","one_liner":"Take control of your data in real-time.","trust_center_url":"https://security.joinformal.com/","security_page_url":null,"url":"https://certreports.com/vendors/formal/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"hipaa","framework_name":"HIPAA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states that it will sign a business associate agreement on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/formal/hipaa","evidence":[{"source_type":"trust_center","source_name":"Formal trust centre (Drata)","url":"https://security.joinformal.com/","fetched_at":"2026-09-18 22:49:00.405521+00","content_hash":"582f4424faa8053366e487d9fdab536f4ee02946401aecceb7479f45c8555a84","wayback_url":null,"quote":"HIPAA","confidence":1}]},{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/formal/soc-2","evidence":[{"source_type":"trust_center","source_name":"Formal trust centre (Drata)","url":"https://security.joinformal.com/","fetched_at":"2026-09-18 22:49:00.405521+00","content_hash":"582f4424faa8053366e487d9fdab536f4ee02946401aecceb7479f45c8555a84","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27001 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/formal/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Formal trust centre (Drata)","url":"https://security.joinformal.com/","fetched_at":"2026-09-18 22:49:00.405521+00","content_hash":"582f4424faa8053366e487d9fdab536f4ee02946401aecceb7479f45c8555a84","wayback_url":null,"quote":"ISO/IEC 27001","confidence":1}]}],"brief":null,"legal_docs":[],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T10:48:01.662Z"}