{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"openroll","name":"Openroll","domain":"openroll.com","category":"AI tools","one_liner":"The AI workforce for People and Finance teams","trust_center_url":"https://security.openroll.com/","security_page_url":null,"url":"https://certreports.com/vendors/openroll/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type II on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/openroll/soc-2","evidence":[{"source_type":"trust_center","source_name":"Openroll trust centre (Vanta)","url":"https://security.openroll.com/","fetched_at":"2026-09-18 23:23:46.822443+00","content_hash":"2acab61058a93c9742f931b8e254897c6b6e493add56e022746de3fffd11228b","wayback_url":null,"quote":"SOC 2 Type I","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/openroll/gdpr","evidence":[{"source_type":"trust_center","source_name":"Openroll trust centre (Vanta)","url":"https://security.openroll.com/","fetched_at":"2026-09-18 23:23:46.822443+00","content_hash":"2acab61058a93c9742f931b8e254897c6b6e493add56e022746de3fffd11228b","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/openroll/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Openroll trust centre (Vanta)","url":"https://security.openroll.com/","fetched_at":"2026-09-18 23:23:46.822443+00","content_hash":"2acab61058a93c9742f931b8e254897c6b6e493add56e022746de3fffd11228b","wayback_url":null,"quote":"ISO 27001:2022","confidence":1}]}],"brief":null,"legal_docs":[{"kind":"privacy","url":"https://www.openroll.com/privacy-policy","availability":"public","detail":null,"as_of":"2026-09-18"},{"kind":"subprocessors","url":"https://security.openroll.com/","availability":"public","detail":"11 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Anthropic","domain":"anthropic.com","purpose":"Provision of AI models","location":null,"vendor_url":null},{"name":"AWS","domain":"aws.com","purpose":"Provision of AI models","location":null,"vendor_url":null},{"name":"Google Cloud","domain":"google.com","purpose":"Provision of AI models","location":null,"vendor_url":null},{"name":"Microsoft Azure","domain":"azure.com","purpose":"Hosting, infrastructure and AI models","location":null,"vendor_url":null},{"name":"Modal","domain":"modal.com","purpose":"Secure code execution & infrastructure","location":null,"vendor_url":null},{"name":"OpenAI","domain":"openai.com","purpose":"Provision of AI models","location":null,"vendor_url":"https://certreports.com/vendors/openai/security"},{"name":"PostHog","domain":"posthog.com","purpose":"Provision of product analytics","location":null,"vendor_url":"https://certreports.com/vendors/posthog/security"},{"name":"Sentry","domain":"sentry.io","purpose":"System health and crash reporting","location":null,"vendor_url":null},{"name":"Temporal","domain":"temporal.io","purpose":"System reliability and state management","location":null,"vendor_url":null},{"name":"Vanta","domain":"vanta.com","purpose":"Security","location":null,"vendor_url":"https://certreports.com/vendors/vanta/security"},{"name":"Vercel","domain":"vercel.com","purpose":"Hosting","location":null,"vendor_url":"https://certreports.com/vendors/vercel/security"}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T19:51:03.857Z"}