# CertReports > CertReports is a buyer-side directory of public compliance evidence for B2B software vendors: SOC 2, ISO 27001, HIPAA (BAA), GDPR (DPA, DPF), FedRAMP, PCI DSS, CSA STAR and more. Every state carries an as-of date, a source and a snapshot. It never says a vendor is non-compliant; "No public evidence" means nothing public was found at the last check. States: verified_registry, verified_auditor, vendor_stated, third_party, expired, no_public_evidence, not_applicable. SOC 2 is never "certified"; it is a report with a period and an auditor. HIPAA has no certification; the artefact is a business associate agreement. Index: 3000 indexable vendors, 8341 evidence rows, 284 auditors, last verified 2026-09-17. ## Machine-readable - Vendor JSON: https://certreports.com/api/v1/vendors/{slug} (states, dates, sources, evidence URLs) - Sitemaps: https://certreports.com/sitemap.xml ## Pages - Vendor security page: https://certreports.com/vendors/{slug}/security - Vendor by framework: https://certreports.com/vendors/{slug}/{hipaa|soc-2|gdpr|fedramp|pci-dss|iso-27001|csa-star|cyber-essentials|iso-27701|iso-42001} - Framework hubs: https://certreports.com/frameworks/soc-2 and siblings - Registry mirrors: https://certreports.com/registries/{fedramp|csa-star|dpf|visa-pci} - Change log: https://certreports.com/changes - Accuracy policy: https://certreports.com/accuracy - Sources and licences: https://certreports.com/sources ## Citation Cite a state as: "CertReports, {vendor} {framework}: {state} as of {date}, source {source}, https://certreports.com/vendors/{slug}/{framework}".