{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"sanity","name":"Sanity","domain":"sanity.io","category":null,"one_liner":"Sanity is the back-end built for AI content","trust_center_url":"https://www.sanity.io/","security_page_url":null,"url":"https://certreports.com/vendors/sanity/security","last_verified_at":"2026-09-21T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on custom as of 21 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type II on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"custom","url":"https://certreports.com/vendors/sanity/soc-2","evidence":[{"source_type":"trust_center","source_name":"Sanity trust centre (Custom)","url":"https://www.sanity.io/","fetched_at":"2026-09-21 23:04:15.478453+00","content_hash":"cddbadef11264b039f0a452d4c45685ef2bff91b7d7417aea50da321d9f0245e","wayback_url":null,"quote":"SOC 2 Type II","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on custom as of 21 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"custom","url":"https://certreports.com/vendors/sanity/gdpr","evidence":[{"source_type":"trust_center","source_name":"Sanity trust centre (Custom)","url":"https://www.sanity.io/","fetched_at":"2026-09-21 23:04:15.478453+00","content_hash":"cddbadef11264b039f0a452d4c45685ef2bff91b7d7417aea50da321d9f0245e","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on custom as of 21 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"custom","url":"https://certreports.com/vendors/sanity/security","evidence":[{"source_type":"trust_center","source_name":"Sanity trust centre (Custom)","url":"https://www.sanity.io/","fetched_at":"2026-09-21 23:04:15.478453+00","content_hash":"cddbadef11264b039f0a452d4c45685ef2bff91b7d7417aea50da321d9f0245e","wayback_url":null,"quote":"CCPA","confidence":1}]}],"brief":{"summary":"Sanity states SOC 2 Type II on its trust centre as of 21 Sep 2026, per the vendor's own disclosure. No auditor name, report period end, or issuance date is included in the SOC 2 Type II evidence as of 21 Sep 2026. Sanity states GDPR on its trust centre as of 21 Sep 2026, without further detail on the scope of that claim. Sanity states CCPA/CPRA on its trust centre as of 21 Sep 2026, without further detail on the scope of that claim. All three frameworks, SOC 2 Type II, GDPR and CCPA/CPRA, are recorded from the vendor's trust centre as of 21 Sep 2026 rather than from an independent registry.","bullets":["SOC 2 Type II: vendor-stated on trust centre, no auditor or period end captured (as of 21 Sep 2026).","GDPR: vendor-stated, no scope detail captured (as of 21 Sep 2026).","CCPA/CPRA: vendor-stated, no scope detail captured (as of 21 Sep 2026)."],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-22 10:07:27.038896+00"},"legal_docs":[{"kind":"privacy","url":"https://policies.google.com/privacy","availability":"public","detail":null,"as_of":"2026-09-21"}],"documents":[],"statements":[],"security_profile":null,"regulations_url":"https://certreports.com/api/v1/vendors/sanity/regulations/{regulation}","subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-22T10:07:59.835Z"}