{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"vtex","name":"VTEX","domain":"vtex.com","category":"E-commerce","one_liner":"Modernize your stack and drive operational results with an AI-Native unified commerce","trust_center_url":"https://compliance.vtex.com/","security_page_url":null,"url":"https://certreports.com/vendors/vtex/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"hipaa","framework_name":"HIPAA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states that it will sign a business associate agreement on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/vtex/hipaa","evidence":[{"source_type":"trust_center","source_name":"VTEX trust centre (Drata)","url":"https://compliance.vtex.com/","fetched_at":"2026-09-18 22:43:08.75057+00","content_hash":"c4d2ee29cba724c0d5f7bf0450ed3d9a14fb6669eecc779c7531000a02c3a0f8","wayback_url":null,"quote":"HIPAA","confidence":1}]},{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Drata) as of 18 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type II on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/vtex/soc-2","evidence":[{"source_type":"trust_center","source_name":"VTEX trust centre (Drata)","url":"https://compliance.vtex.com/","fetched_at":"2026-09-18 22:43:08.75057+00","content_hash":"c4d2ee29cba724c0d5f7bf0450ed3d9a14fb6669eecc779c7531000a02c3a0f8","wayback_url":null,"quote":"SOC 2 Type II","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/vtex/gdpr","evidence":[{"source_type":"trust_center","source_name":"VTEX trust centre (Drata)","url":"https://compliance.vtex.com/","fetched_at":"2026-09-18 22:43:08.75057+00","content_hash":"c4d2ee29cba724c0d5f7bf0450ed3d9a14fb6669eecc779c7531000a02c3a0f8","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Visa Global Registry of Service Providers as of 17 Sep 2026.","kind":"attestation","status_text":"Listed on the Visa Global Registry as PCI DSS validated through 2027-05-31","issued_at":"2024-08-01","expires_at":"2027-05-31","period_start":null,"period_end":null,"auditor":"CIPHER","impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"visa_grsp","url":"https://certreports.com/vendors/vtex/pci-dss","evidence":[{"source_type":"registry","source_name":"Visa Global Registry of Service Providers","url":"https://www.visa.com/splisting/","fetched_at":"2026-09-17 15:59:49.028041+00","content_hash":"ede7baddcff9c2e3ed9772a3eaf98dcd4df5a66d79a7ebc8b696cb371b3216ef","wayback_url":null,"quote":"VTEX BRASIL TECNOLOGIA PARA E-COMMERCE LTDA: PCI DSS, assessor CIPHER, valid through 2027-05-31","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27001 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/vtex/iso-27001","evidence":[{"source_type":"trust_center","source_name":"VTEX trust centre (Drata)","url":"https://compliance.vtex.com/","fetched_at":"2026-09-18 22:43:08.75057+00","content_hash":"c4d2ee29cba724c0d5f7bf0450ed3d9a14fb6669eecc779c7531000a02c3a0f8","wayback_url":null,"quote":"ISO 27001","confidence":1}]},{"framework":"iso-27701","framework_name":"ISO/IEC 27701","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27701 certificate on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27701 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/vtex/iso-27701","evidence":[{"source_type":"trust_center","source_name":"VTEX trust centre (Drata)","url":"https://compliance.vtex.com/","fetched_at":"2026-09-18 22:43:08.75057+00","content_hash":"c4d2ee29cba724c0d5f7bf0450ed3d9a14fb6669eecc779c7531000a02c3a0f8","wayback_url":null,"quote":"ISO/IEC 27701","confidence":1}]},{"framework":"soc-1","framework_name":"SOC 1","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 1 Type II report on its trust centre (Drata) as of 18 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 1 Type II on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/vtex/security","evidence":[{"source_type":"trust_center","source_name":"VTEX trust centre (Drata)","url":"https://compliance.vtex.com/","fetched_at":"2026-09-18 22:43:08.75057+00","content_hash":"c4d2ee29cba724c0d5f7bf0450ed3d9a14fb6669eecc779c7531000a02c3a0f8","wayback_url":null,"quote":"SOC 1 Type II","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: EU-US Certification, SW-US Certification, UK Extension Certification","issued_at":"2024-07-12","expires_at":"2027-07-06","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/vtex/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/3927","fetched_at":"2026-09-17 15:48:15.877249+00","content_hash":"d7e9391935723ab66ebed475e89bda40114d50218c13b92b8464e2f408b27c6c","wayback_url":null,"quote":"VTEX: Active: EU-US Certification, SW-US Certification, UK Extension Certification","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Drata) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"drata","url":"https://certreports.com/vendors/vtex/security","evidence":[{"source_type":"trust_center","source_name":"VTEX trust centre (Drata)","url":"https://compliance.vtex.com/","fetched_at":"2026-09-18 22:43:08.75057+00","content_hash":"c4d2ee29cba724c0d5f7bf0450ed3d9a14fb6669eecc779c7531000a02c3a0f8","wayback_url":null,"quote":"CCPA","confidence":1}]}],"brief":{"summary":"As of 17 Sep 2026, VTEX is listed in the Visa Global Registry as PCI DSS validated, with the record issued 1 Aug 2024 and running through 31 May 2027 under auditor CIPHER. As of 17 Sep 2026, VTEX is listed in the DPF registry as maintaining active EU-US Certification, SW-US Certification, and UK Extension Certification, issued 12 Jul 2024 and expiring 6 Jul 2027. As of 17 Sep 2026, no public evidence found for SOC 2 for VTEX. As of 17 Sep 2026, no public evidence found for HIPAA for VTEX. As of 17 Sep 2026, no subprocessor entries were found in the evidence provided for VTEX.","bullets":["PCI DSS: listed in Visa Global Registry as validated, issued 1 Aug 2024, expires 31 May 2027 (as of 17 Sep 2026).","EU-US Data Privacy Framework: listed in DPF registry as active (EU-US, SW-US, UK Extension), issued 12 Jul 2024, expires 6 Jul 2027 (as of 17 Sep 2026).","SOC 2 and HIPAA: no public evidence found for VTEX as of 17 Sep 2026."],"model":"claude-sonnet-5","generated_at":"2026-09-17 18:52:51.985299+00"},"legal_docs":[{"kind":"subprocessors","url":"https://compliance.vtex.com/","availability":"public","detail":"2 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Audits Cyber Insurance View more Platform","domain":null,"purpose":null,"location":null,"vendor_url":null},{"name":"Status Monitoring Amazon Web Services","domain":null,"purpose":null,"location":null,"vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T02:21:57.598Z"}