{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"sim","name":"Sim","domain":"sim.ai","category":"AI infrastructure","one_liner":"The AI Workspace for Building and Managing AI Agents.","trust_center_url":"https://trust.sim.ai/","security_page_url":null,"url":"https://certreports.com/vendors/sim/security","last_verified_at":"2026-09-17T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 17 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type II on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/sim/soc-2","evidence":[{"source_type":"trust_center","source_name":"Sim trust centre (Vanta)","url":"https://trust.sim.ai/","fetched_at":"2026-09-17 16:28:14.960201+00","content_hash":"621fbcf86d73124d3240be874d30a0dacd7359b87175d53a5cc109e000d572f3","wayback_url":null,"quote":"SOC 2 Type II","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 17 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/sim/gdpr","evidence":[{"source_type":"trust_center","source_name":"Sim trust centre (Vanta)","url":"https://trust.sim.ai/","fetched_at":"2026-09-17 16:28:14.960201+00","content_hash":"621fbcf86d73124d3240be874d30a0dacd7359b87175d53a5cc109e000d572f3","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Vanta) as of 17 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/sim/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Sim trust centre (Vanta)","url":"https://trust.sim.ai/","fetched_at":"2026-09-17 16:28:14.960201+00","content_hash":"621fbcf86d73124d3240be874d30a0dacd7359b87175d53a5cc109e000d572f3","wayback_url":null,"quote":"ISO 27001:2022","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: EU-US Certification, SW-US Certification, UK Extension Certification","issued_at":"2026-09-03","expires_at":"2027-09-03","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/sim/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/10304","fetched_at":"2026-09-17 15:51:34.974343+00","content_hash":"0caee73c8fbc12c270a24d6822b8f47641e6106c3f732fb1891e7ae70ed6f72c","wayback_url":null,"quote":"Sim: Active: EU-US Certification, SW-US Certification, UK Extension Certification","confidence":1}]}],"brief":{"summary":"As of 17 Sep 2026, Sim (sim.ai) states on its trust centre that it holds a SOC 2 Type II report. As of 17 Sep 2026, Sim states on its trust centre that it complies with GDPR. As of 17 Sep 2026, Sim states on its trust centre that it holds ISO 27001:2022 certification. As of 17 Sep 2026, Sim is listed in the EU-US Data Privacy Framework registry with an active status covering EU-US, SW-US, and UK Extension certifications, issued 3 Sep 2026 and expiring 3 Sep 2027. No public evidence found for a HIPAA BAA as of 17 Sep 2026.","bullets":["SOC 2 Type II: vendor states on its trust centre (as of 17 Sep 2026); no independent registry confirmation provided.","EU-US Data Privacy Framework: listed in registry as Active, issued 3 Sep 2026, expires 3 Sep 2027 (as of 17 Sep 2026).","ISO/IEC 27001:2022 and GDPR: vendor states on its trust centre (as of 17 Sep 2026); HIPAA has no public evidence found."],"model":"claude-sonnet-5","generated_at":"2026-09-17 18:35:49.201036+00"},"legal_docs":[{"kind":"subprocessors","url":"https://trust.sim.ai/","availability":"public","detail":"7 subprocessors listed on the trust centre","as_of":"2026-09-17"},{"kind":"privacy","url":"https://www.sim.ai/privacy","availability":"public","detail":null,"as_of":"2026-09-17"}],"subprocessors":[{"name":"Amazon Web Services","domain":"amazon.com","purpose":"Cloud provider","location":null,"vendor_url":"https://certreports.com/vendors/amazon/security"},{"name":"GitHub","domain":"github.com","purpose":"Version control","location":null,"vendor_url":null},{"name":"Google Workspace","domain":"google.com","purpose":"Identity provider","location":null,"vendor_url":null},{"name":"Grafana","domain":"grafana.com","purpose":"Cloud monitoring","location":null,"vendor_url":"https://certreports.com/vendors/grafana-labs/security"},{"name":"Slack","domain":"slack.com","purpose":"Collaboration","location":null,"vendor_url":"https://certreports.com/vendors/slack-technologies/security"},{"name":"Stripe","domain":"stripe.com","purpose":"Finance and payments","location":null,"vendor_url":"https://certreports.com/vendors/stripe/security"},{"name":"Trigger.dev","domain":"trigger.dev","purpose":"Background Tasks","location":null,"vendor_url":"https://certreports.com/vendors/trigger-dev/security"}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-18T17:28:48.405Z"}