{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"model-n","name":"Model N","domain":"modeln.com","category":"Finance and accounting","one_liner":"Model N supports the complex business needs of the world’s leading brands in pharmaceutical, medical device, high tech, manufacturing and","trust_center_url":"https://trust.modeln.com/","security_page_url":null,"url":"https://certreports.com/vendors/model-n/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Drata) as of 18 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/model-n/soc-2","evidence":[{"source_type":"trust_center","source_name":"Model N trust centre (Drata)","url":"https://trust.modeln.com/","fetched_at":"2026-09-18 22:47:06.482757+00","content_hash":"8da87a61f5cc2a36aa54b7558aaa00cfd23b53848bccbf3d70ece64e7dfa73c3","wayback_url":null,"quote":"SOC 2 Type 2","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/model-n/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Model N trust centre (Drata)","url":"https://trust.modeln.com/","fetched_at":"2026-09-18 22:47:06.482757+00","content_hash":"8da87a61f5cc2a36aa54b7558aaa00cfd23b53848bccbf3d70ece64e7dfa73c3","wayback_url":null,"quote":"ISO/IEC 27001:2022","confidence":1}]},{"framework":"csa-star","framework_name":"CSA STAR","state":"verified_registry","state_label":"Verified","sentence":"Listed in the CSA STAR registry as of 17 Sep 2026.","kind":"level2","status_text":"STAR Level 2 attestation","issued_at":"2022-04-06","expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"csa_star","url":"https://certreports.com/vendors/model-n/csa-star","evidence":[{"source_type":"registry","source_name":"CSA STAR registry","url":"https://cloudsecurityalliance.org/star/registry/model-n","fetched_at":"2026-09-17 15:44:42.254747+00","content_hash":"e7f124247f5399c92ba048620a83c0b6cca1f9a2f97419f32566e462a3b1bda7","wayback_url":null,"quote":"model n: STAR Level 2 attestation","confidence":1}]},{"framework":"soc-1","framework_name":"SOC 1","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 1 Type II report on its trust centre (Drata) as of 18 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 1 Type 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/model-n/security","evidence":[{"source_type":"trust_center","source_name":"Model N trust centre (Drata)","url":"https://trust.modeln.com/","fetched_at":"2026-09-18 22:47:06.482757+00","content_hash":"8da87a61f5cc2a36aa54b7558aaa00cfd23b53848bccbf3d70ece64e7dfa73c3","wayback_url":null,"quote":"SOC 1 Type 2","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"expired","state_label":"Expired","sentence":"Certificate expiry unknown date passed; no renewal found as of 17 Sep 2026.","kind":"listing","status_text":"Inactive","issued_at":"2018-05-29","expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/model-n/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/5366","fetched_at":"2026-09-17 15:48:57.120938+00","content_hash":"522d13e053d4098cec27474c170b49c1aafcd97548a4da86c93e5f0eeb26be8d","wayback_url":null,"quote":"Model N: Inactive","confidence":1}]}],"brief":null,"legal_docs":[{"kind":"subprocessors","url":"https://trust.modeln.com/","availability":"public","detail":"5 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"According to AWS","domain":null,"purpose":null,"location":null,"vendor_url":null},{"name":"Drift integration enabled within Salesforce","domain":null,"purpose":null,"location":null,"vendor_url":null},{"name":"Model N became aware that AWS","domain":null,"purpose":null,"location":null,"vendor_url":null},{"name":"Subscribe Model N Not Impacted by UAE AWS","domain":null,"purpose":null,"location":null,"vendor_url":null},{"name":"Widespread Data Theft Targets Salesforce","domain":null,"purpose":null,"location":null,"vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T03:28:33.028Z"}