{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"valence","name":"Valence","domain":"valence.co","category":null,"one_liner":"Valences AI Powered Leadership Coach allows enterprises to offer executive level coaching at","trust_center_url":"https://trust.valence.co/","security_page_url":null,"url":"https://certreports.com/vendors/valence/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type II on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/valence/soc-2","evidence":[{"source_type":"trust_center","source_name":"Valence trust centre (Vanta)","url":"https://trust.valence.co/","fetched_at":"2026-09-18 23:11:23.902616+00","content_hash":"84a5d832431677c1a3a02e4dd0181a6e4357bc90ecc9d7bb101c9919a00162cf","wayback_url":null,"quote":"SOC 2 Type II","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR Compliant on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/valence/gdpr","evidence":[{"source_type":"trust_center","source_name":"Valence trust centre (Vanta)","url":"https://trust.valence.co/","fetched_at":"2026-09-18 23:11:23.902616+00","content_hash":"84a5d832431677c1a3a02e4dd0181a6e4357bc90ecc9d7bb101c9919a00162cf","wayback_url":null,"quote":"GDPR Compliant","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/valence/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Valence trust centre (Vanta)","url":"https://trust.valence.co/","fetched_at":"2026-09-18 23:11:23.902616+00","content_hash":"84a5d832431677c1a3a02e4dd0181a6e4357bc90ecc9d7bb101c9919a00162cf","wayback_url":null,"quote":"ISO 27001:2022","confidence":1}]},{"framework":"iso-42001","framework_name":"ISO/IEC 42001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 42001 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 42001:2023 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/valence/iso-42001","evidence":[{"source_type":"trust_center","source_name":"Valence trust centre (Vanta)","url":"https://trust.valence.co/","fetched_at":"2026-09-18 23:11:23.902616+00","content_hash":"84a5d832431677c1a3a02e4dd0181a6e4357bc90ecc9d7bb101c9919a00162cf","wayback_url":null,"quote":"ISO/IEC 42001:2023","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"expired","state_label":"Expired","sentence":"Certificate expiry unknown date passed; no renewal found as of 17 Sep 2026.","kind":"listing","status_text":"Inactive","issued_at":"2019-03-05","expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/valence/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/6972","fetched_at":"2026-09-17 15:49:52.728611+00","content_hash":"8015ddada2bf510e74f46d33b7b647bccc7d53b2978dc894830815a879490ea7","wayback_url":null,"quote":"Valence: Inactive","confidence":1}]}],"brief":{"summary":"Valence states on its trust centre that it holds a SOC 2 Type II report, with that claim recorded as of 18 Sep 2026. Valence also states on its trust centre that it is GDPR compliant, as recorded on 18 Sep 2026. Valence states on its trust centre that it holds ISO/IEC 27001:2022 certification, as of 18 Sep 2026. Valence states on its trust centre that it holds ISO/IEC 42001:2023, the AI management systems standard, as of 18 Sep 2026. Valence's EU-US Data Privacy Framework listing is marked Inactive as of 17 Sep 2026, with an original issue date of 5 Mar 2019.","bullets":["SOC 2: vendor states it holds a SOC 2 Type II report on its trust centre (as of 18 Sep 2026)","ISO/IEC 27001:2022 and ISO/IEC 42001:2023 stated on trust centre (as of 18 Sep 2026)","EU-US Data Privacy Framework: Inactive as of 17 Sep 2026 (originally issued 5 Mar 2019)"],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 11:21:33.317266+00"},"legal_docs":[{"kind":"privacy","url":"https://www.valence.co/other/privacy","availability":"public","detail":null,"as_of":"2026-09-18"},{"kind":"subprocessors","url":"https://trust.valence.co/","availability":"public","detail":"11 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Amazon Web Services","domain":"amazon.com","purpose":"Cloud hosting","location":null,"vendor_url":"https://certreports.com/vendors/amazon/security"},{"name":"Anthropic","domain":"anthropic.com","purpose":"Large language models. ","location":null,"vendor_url":null},{"name":"Auth0","domain":"auth0.com","purpose":"SSO provider","location":null,"vendor_url":null},{"name":"customer.io","domain":"customer.io","purpose":"Email sending","location":null,"vendor_url":"https://certreports.com/vendors/peaberry-software/security"},{"name":"FullStory","domain":"fullstory.com","purpose":"CS Insight Tool","location":null,"vendor_url":"https://certreports.com/vendors/fullstory/security"},{"name":"Google","domain":"google.com","purpose":"Productivity & large language models","location":null,"vendor_url":null},{"name":"Intercom","domain":"intercom.com","purpose":"Customer support","location":null,"vendor_url":"https://certreports.com/vendors/intercom/security"},{"name":"MailGun","domain":"mailgun.com","purpose":"Email sending","location":null,"vendor_url":"https://certreports.com/vendors/mailgun/security"},{"name":"OpenAI","domain":"openai.com","purpose":"Large language models","location":null,"vendor_url":"https://certreports.com/vendors/openai/security"},{"name":"PostHog","domain":"posthog.com","purpose":"Data analytics","location":null,"vendor_url":"https://certreports.com/vendors/posthog/security"},{"name":"Sentry","domain":"sentry.io","purpose":"Error monitoring","location":null,"vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T11:47:49.074Z"}