{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"within","name":"Within","domain":"within.ai","category":"AI tools","one_liner":"Company Brain for people and agents to work in harmony.","trust_center_url":"https://trust.within.ai/","security_page_url":null,"url":"https://certreports.com/vendors/within/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type II on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/within/soc-2","evidence":[{"source_type":"trust_center","source_name":"Within trust centre (Vanta)","url":"https://trust.within.ai/","fetched_at":"2026-09-18 23:30:00.950005+00","content_hash":"6e615f6e59098746770eae54e4c6161ab1e269d9ba33effcc10c98e2e1756ae6","wayback_url":null,"quote":"SOC 2 Type II","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/within/gdpr","evidence":[{"source_type":"trust_center","source_name":"Within trust centre (Vanta)","url":"https://trust.within.ai/","fetched_at":"2026-09-18 23:30:00.950005+00","content_hash":"6e615f6e59098746770eae54e4c6161ab1e269d9ba33effcc10c98e2e1756ae6","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/within/security","evidence":[{"source_type":"trust_center","source_name":"Within trust centre (Vanta)","url":"https://trust.within.ai/","fetched_at":"2026-09-18 23:30:00.950005+00","content_hash":"6e615f6e59098746770eae54e4c6161ab1e269d9ba33effcc10c98e2e1756ae6","wayback_url":null,"quote":"CCPA","confidence":1}]}],"brief":null,"legal_docs":[{"kind":"privacy","url":"https://www.within.ai/legal/privacy-policy-product","availability":"public","detail":null,"as_of":"2026-09-18"},{"kind":"subprocessors","url":"https://trust.within.ai/","availability":"public","detail":"15 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Amazon Web Services","domain":"amazon.com","purpose":"Within's infrastructure is entirely hosted on AWS.","location":"United States","vendor_url":"https://certreports.com/vendors/amazon/security"},{"name":"Asana","domain":"asana.com","purpose":"Within uses Asana to track customer feature requests and bug reports.","location":"United States","vendor_url":"https://certreports.com/vendors/asana/security"},{"name":"Cartesia","domain":"cartesia.ai","purpose":"Within uses Cartesia for text-to-speech voice synthesis within its product.","location":"United States","vendor_url":null},{"name":"Connor Group","domain":"connorgp.com","purpose":"Within uses Connor Group for advisory and technology services.","location":"United States","vendor_url":null},{"name":"Daily","domain":"daily.co","purpose":"Provides secure, real-time audio and video communication services used within our application.","location":"United States","vendor_url":"https://certreports.com/vendors/daily/security"},{"name":"Gong","domain":"gong.io","purpose":"Within uses Gong to record calls.","location":"United States","vendor_url":null},{"name":"Google","domain":"google.com","purpose":"Within uses Google to communicate with customers and in its document processing pipeline.","location":"United States","vendor_url":null},{"name":"Klarity India","domain":"within.ai","purpose":"Klarity India is Within's fully-controlled subsidiary headquartered in Bangalore, India.","location":"India","vendor_url":"https://certreports.com/vendors/within/security"},{"name":"Linear","domain":"linear.app","purpose":"Within uses Linear products for software development.","location":"United States","vendor_url":null},{"name":"Microsoft Azure","domain":"microsoft.com","purpose":"Within uses Microsoft Azure products in its document processing pipeline.","location":"United States","vendor_url":"https://certreports.com/vendors/microsoft/security"},{"name":"Okta","domain":"okta.com","purpose":"Within uses Okta for Single Sign On (SSO) services.","location":"United States","vendor_url":"https://certreports.com/vendors/okta/security"},{"name":"OpenAI","domain":"openai.com","purpose":"Within uses OpenAI products in its document processing pipeline.","location":"United States","vendor_url":"https://certreports.com/vendors/openai/security"},{"name":"Slack","domain":"slack.com","purpose":"Within uses Slack for customer support.","location":"United States","vendor_url":"https://certreports.com/vendors/slack-technologies/security"},{"name":"Superhuman","domain":"superhuman.com","purpose":"Within uses Superhuman for email management.","location":"United States","vendor_url":"https://certreports.com/vendors/superhuman-labs-inc/security"},{"name":"WorkOS","domain":"workos.com","purpose":"Within uses WorkOS for Single Sign On (SSO) and authentication services.","location":"United States","vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T09:49:53.073Z"}