Compliance grid
- HIPAAVendor-stated
Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)
as of 17 Sep 20261 source
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 17 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 17 Sep 20261 source - FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · Fortreum, LLC
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001:2022 on its trust centre
as of 17 Sep 20261 source- CSA STARVerified
STAR Level 2 attestation, Trusted Cloud Provider
as of 17 Sep 20261 source
Cyber EssentialsVendor-statedVendor states Cyber Essentials on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27701Vendor-statedVendor states ISO/IEC 27701:2019 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 42001Vendor-statedVendor states ISO/IEC 42001:2023 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27017Vendor-statedVendor states ISO/IEC 27017:2015 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27018Vendor-statedVendor states ISO/IEC 27018:2019 on its trust centre
as of 17 Sep 20261 source
ISO 22301Vendor-statedVendor states ISO 22301:2019 on its trust centre
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkExpiredInactive
as of 17 Sep 20261 source
TX-RAMPVendor-statedVendor states TX-RAMP on its trust centre
as of 17 Sep 20261 source
Cyber Essentials PlusVendor-statedVendor states Cyber Essentials Plus on its trust centre
as of 17 Sep 20261 source
BSI C5Vendor-statedVendor states C5 on its trust centre
as of 17 Sep 20261 source
ENSVendor-statedVendor states ENS on its trust centre
as of 17 Sep 20261 source
IRAPVendor-statedVendor states IRAP on its trust centre
as of 17 Sep 20261 source
No public evidence yet for PCI DSS. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Official framework marks identify the scheme each row is about; the CertReports state chip beside each mark is our assessment of the public evidence. How states are decided.