{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"sardine","name":"Sardine","domain":"sardine.ai","category":"Security","one_liner":"The top agentic risk platform used by leading banks and merchants worldwide to stop fraud in real-time, prevent AI-driven attacks, automate","trust_center_url":"https://security.sardine.ai/","security_page_url":null,"url":"https://certreports.com/vendors/sardine/security","last_verified_at":"2026-09-19T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/sardine/soc-2","evidence":[{"source_type":"trust_center","source_name":"Sardine trust centre (Vanta)","url":"https://security.sardine.ai/","fetched_at":"2026-09-19 07:33:04.775167+00","content_hash":"d9da7abafc96665865a0aa47278a4d07cc283caada4a5ff5219e22affcd008ad","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/sardine/gdpr","evidence":[{"source_type":"trust_center","source_name":"Sardine trust centre (Vanta)","url":"https://security.sardine.ai/","fetched_at":"2026-09-19 07:33:04.775167+00","content_hash":"d9da7abafc96665865a0aa47278a4d07cc283caada4a5ff5219e22affcd008ad","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS - SAQ A on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/sardine/pci-dss","evidence":[{"source_type":"trust_center","source_name":"Sardine trust centre (Vanta)","url":"https://security.sardine.ai/","fetched_at":"2026-09-19 07:33:04.775167+00","content_hash":"d9da7abafc96665865a0aa47278a4d07cc283caada4a5ff5219e22affcd008ad","wayback_url":null,"quote":"PCI DSS - SAQ A","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Vanta) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states CPRA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/sardine/security","evidence":[{"source_type":"trust_center","source_name":"Sardine trust centre (Vanta)","url":"https://security.sardine.ai/","fetched_at":"2026-09-19 07:33:04.775167+00","content_hash":"d9da7abafc96665865a0aa47278a4d07cc283caada4a5ff5219e22affcd008ad","wayback_url":null,"quote":"CCPA","confidence":1}]}],"brief":{"summary":"Sardine states on its trust centre that it has a SOC 2 report, as of 19 Sep 2026. Sardine also states on its trust centre that it addresses the GDPR, as of 19 Sep 2026. Sardine further states on its trust centre that it self-attests to PCI DSS - SAQ A, as of 19 Sep 2026. Sardine additionally states on its trust centre that it addresses the CPRA, as of 19 Sep 2026. All four of these SOC 2, GDPR, PCI DSS and CPRA disclosures for Sardine are vendor-stated claims on its trust centre rather than registry listings, as of 19 Sep 2026.","bullets":["SOC 2 and GDPR: vendor-stated on trust centre, as of 19 Sep 2026","PCI DSS - SAQ A self-attestation: vendor-stated on trust centre, as of 19 Sep 2026","CPRA: vendor-stated on trust centre, as of 19 Sep 2026; no registry-listed evidence found for Sardine"],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 10:40:41.150238+00"},"legal_docs":[{"kind":"privacy","url":"https://www.sardine.ai/privacy-policy","availability":"public","detail":null,"as_of":"2026-09-19"},{"kind":"subprocessors","url":"https://security.sardine.ai/","availability":"public","detail":"9 subprocessors listed on the trust centre","as_of":"2026-09-19"}],"subprocessors":[{"name":"Amplitude, Inc.","domain":"amplitude.com","purpose":"Data storage and processing","location":"US","vendor_url":"https://certreports.com/vendors/amplitude/security"},{"name":"Datadog","domain":"datadoghq.com","purpose":"Service Monitoring and Logging","location":"US","vendor_url":"https://certreports.com/vendors/datadog/security"},{"name":"Elastic Search","domain":"elastic.co","purpose":"Cloud resource management","location":"US, EU","vendor_url":"https://certreports.com/vendors/elastic/security"},{"name":"Experian Information Solutions, Inc.","domain":"experian.com","purpose":"Data storage and processing","location":"US","vendor_url":"https://certreports.com/vendors/csidentity/security"},{"name":"Google Cloud Platform","domain":"google.com","purpose":"Cloud provider","location":"US, EU, CA, IN, and AU","vendor_url":"https://certreports.com/vendors/google/security"},{"name":"Plaid Inc.","domain":"plaid.com","purpose":"Data storage and processing","location":"US","vendor_url":"https://certreports.com/vendors/plaid/security"},{"name":"Pylon","domain":"usepylon.com","purpose":"Ticketing and customer service","location":"US","vendor_url":"https://certreports.com/vendors/pylon-usepylon/security"},{"name":"WorkOS","domain":"workos.com","purpose":"Engineering","location":"US","vendor_url":null},{"name":"Zendesk","domain":"zendesk.com","purpose":"Customer support","location":"US","vendor_url":"https://certreports.com/vendors/zendesk/security"}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-20T22:35:56.837Z"}