{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"lively-inc","name":"Lively","domain":"livelyme.com","category":"Benefits and insurance","one_liner":"Modern employee benefits & health savings account (HSA) provider","trust_center_url":"https://trust.livelyme.com/","security_page_url":null,"url":"https://certreports.com/vendors/lively-inc/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"hipaa","framework_name":"HIPAA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states that it will sign a business associate agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/lively-inc/hipaa","evidence":[{"source_type":"trust_center","source_name":"Lively trust centre (Vanta)","url":"https://trust.livelyme.com/","fetched_at":"2026-09-18 23:12:40.11734+00","content_hash":"4ddece571e9749e571a03633bb18d0eb554aefe1077a18eecbaeacea7e5b477a","wayback_url":null,"quote":"HIPAA","confidence":1}]},{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/lively-inc/soc-2","evidence":[{"source_type":"trust_center","source_name":"Lively trust centre (Vanta)","url":"https://trust.livelyme.com/","fetched_at":"2026-09-18 23:12:40.11734+00","content_hash":"4ddece571e9749e571a03633bb18d0eb554aefe1077a18eecbaeacea7e5b477a","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS - SAQ D on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/lively-inc/pci-dss","evidence":[{"source_type":"trust_center","source_name":"Lively trust centre (Vanta)","url":"https://trust.livelyme.com/","fetched_at":"2026-09-18 23:12:40.11734+00","content_hash":"4ddece571e9749e571a03633bb18d0eb554aefe1077a18eecbaeacea7e5b477a","wayback_url":null,"quote":"PCI DSS - SAQ D","confidence":1}]},{"framework":"soc-1","framework_name":"SOC 1","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 1 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 1 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/lively-inc/security","evidence":[{"source_type":"trust_center","source_name":"Lively trust centre (Vanta)","url":"https://trust.livelyme.com/","fetched_at":"2026-09-18 23:12:40.11734+00","content_hash":"4ddece571e9749e571a03633bb18d0eb554aefe1077a18eecbaeacea7e5b477a","wayback_url":null,"quote":"SOC 1","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/lively-inc/security","evidence":[{"source_type":"trust_center","source_name":"Lively trust centre (Vanta)","url":"https://trust.livelyme.com/","fetched_at":"2026-09-18 23:12:40.11734+00","content_hash":"4ddece571e9749e571a03633bb18d0eb554aefe1077a18eecbaeacea7e5b477a","wayback_url":null,"quote":"CCPA","confidence":1}]}],"brief":{"summary":"Lively states on its trust centre that it displays a HIPAA badge, as of 18 Sep 2026, though the evidence does not confirm whether a BAA is offered. For SOC 2, Lively states on its trust centre that it holds SOC 2, as of 18 Sep 2026. For PCI DSS, Lively states on its trust centre PCI DSS - SAQ D, as of 18 Sep 2026. For SOC 1, Lively states on its trust centre that it holds SOC 1, as of 18 Sep 2026. For CCPA / CPRA, Lively states on its trust centre CCPA, as of 18 Sep 2026.","bullets":["HIPAA: vendor states a HIPAA badge on its trust centre as of 18 Sep 2026 - BAA availability not confirmed in evidence.","SOC 2: vendor states on its trust centre that it holds SOC 2, as of 18 Sep 2026 - vendor-stated, no Type II or auditor detail given.","PCI DSS: vendor states PCI DSS - SAQ D on its trust centre, as of 18 Sep 2026."],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-20 10:13:27.534747+00"},"legal_docs":[{"kind":"subprocessors","url":"https://trust.livelyme.com/","availability":"public","detail":"30 subprocessors listed on the trust centre","as_of":"2026-09-18"},{"kind":"privacy","url":"https://livelyme.com/privacy-policy","availability":"public","detail":null,"as_of":"2026-09-18"}],"subprocessors":[{"name":"Amazon Web Services","domain":"amazon.com","purpose":"Cloud provider","location":"us-west-1, us-east-2","vendor_url":"https://certreports.com/vendors/amazon/security"},{"name":"Anthropic","domain":"anthropic.com","purpose":"AI tools and models","location":null,"vendor_url":null},{"name":"Arkose Labs","domain":"arkoselabs.com","purpose":"Bot mitigation service","location":null,"vendor_url":"https://certreports.com/vendors/arkose-labs/security"},{"name":"Atlassian","domain":"atlassian.com","purpose":"Internal ticketing","location":null,"vendor_url":"https://certreports.com/vendors/atlassian/security"},{"name":"Charles Schwab","domain":"schwab.com","purpose":"Investment provider","location":null,"vendor_url":null},{"name":"Choice bank","domain":"bankwithchoice.com","purpose":"Banking and ACH services","location":null,"vendor_url":null},{"name":"Cloudflare","domain":"cloudflare.com","purpose":"Cloud provider","location":null,"vendor_url":"https://certreports.com/vendors/cloudflare/security"},{"name":"Devenir","domain":"devenir.com","purpose":"Investment provider","location":null,"vendor_url":null},{"name":"Echo Payments","domain":"echohealthinc.com","purpose":"Bill payment","location":null,"vendor_url":null},{"name":"Fiserv","domain":"fiserv.com","purpose":"Card processing","location":null,"vendor_url":"https://certreports.com/vendors/first-data-cono-sur-srl-fiserv/security"},{"name":"Google Workspace","domain":"google.com","purpose":"Email and office productivity applications","location":null,"vendor_url":null},{"name":"HubSpot","domain":"hubspot.com","purpose":"Marketing and customer emails","location":null,"vendor_url":"https://certreports.com/vendors/hubspot/security"},{"name":"Lincoln Financial","domain":"lincolnfinancial.com","purpose":"Investment provider","location":null,"vendor_url":null},{"name":"Mastercard","domain":"mastercard.com","purpose":"Card transactions","location":null,"vendor_url":null},{"name":"OpenAI","domain":"openai.com","purpose":"AI tools and models","location":null,"vendor_url":"https://certreports.com/vendors/openai/security"},{"name":"Oscilar","domain":"oscilar.com","purpose":"Fraud risk platform","location":null,"vendor_url":null},{"name":"Pendo","domain":"pendo.io","purpose":"Software Experience Management","location":null,"vendor_url":"https://certreports.com/vendors/pendo/security"},{"name":"Plaid","domain":"plaid.com","purpose":"Bank connectivity","location":null,"vendor_url":null},{"name":"salesforce","domain":"salesforce.com","purpose":"CRM","location":null,"vendor_url":null},{"name":"Segment","domain":"segment.com","purpose":"Customer analytics platform","location":null,"vendor_url":"https://certreports.com/vendors/segment/security"},{"name":"SendGrid","domain":"sendgrid.com","purpose":"Marketing and customer emails","location":null,"vendor_url":"https://certreports.com/vendors/sendgrid/security"},{"name":"SendSafely","domain":"sendsafely.com","purpose":"Secure email","location":null,"vendor_url":null},{"name":"Sift","domain":"sift.com","purpose":"Fraud risk platform","location":null,"vendor_url":"https://certreports.com/vendors/sift/security"},{"name":"Splunk","domain":"splunk.com","purpose":"Cloud SIEM provider","location":null,"vendor_url":"https://certreports.com/vendors/splunk/security"},{"name":"Talkdesk","domain":"talkdesk.com","purpose":"Voice calls","location":null,"vendor_url":"https://certreports.com/vendors/talkdesk/security"},{"name":"The Bancorp","domain":"thebancorp.com","purpose":"Card processing","location":null,"vendor_url":null},{"name":"TPA Stream","domain":"tpastream.com","purpose":"Claims sync","location":null,"vendor_url":null},{"name":"Visa","domain":"visa.com","purpose":"Card transactions","location":null,"vendor_url":null},{"name":"Zendesk","domain":"zendesk.com","purpose":"Customer support tools","location":null,"vendor_url":"https://certreports.com/vendors/zendesk/security"},{"name":"Zscaler","domain":"zscaler.com","purpose":"Network security service","location":null,"vendor_url":"https://certreports.com/vendors/zscaler/security"}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-21T20:06:50.533Z"}