
Summary
Boomi has 3 registry-verified rows and 1 third-party reported row in the CertReports index, last verified 17 Sep 2026. The strongest row is SOC 2: CSA STAR Level 2 attestation on the registry, which is built on a SOC 2 examination. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, Boomi is listed in the CSA STAR registry with a Level 2 attestation issued 11 Sep 2024, which the registry entry notes is built on a SOC 2 examination. As of 17 Sep 2026, Boomi is listed in the FedRAMP registry as FedRAMP Authorized, with authorization dated 12 Aug 2019 and audited by A-LIGN Compliance and Security, Inc. dba A-LIGN. As of 17 Sep 2026, Boomi is listed in the CSA STAR registry with a Level 2 attestation issued 11 Sep 2024. As of 17 Sep 2026, Boomi is listed in the EU-US Data Privacy Framework registry as Active, covering EU-US, UK Extension, and Swiss-US Certifications, issued 6 Dec 2024 and expiring 22 Jan 2027. As of 17 Sep 2026, no public evidence found for HIPAA compliance or a BAA offering for Boomi.
- SOC 2: listed in CSA STAR registry (Level 2 attestation, issued 11 Sep 2024, built on a SOC 2 examination) as of 17 Sep 2026
- FedRAMP: listed in FedRAMP registry as Authorized (issued 12 Aug 2019, audited by A-LIGN) as of 17 Sep 2026
- EU-US Data Privacy Framework: listed in DPF registry as Active (issued 6 Dec 2024, expires 22 Jan 2027) as of 17 Sep 2026
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among cloud and hosting vendors
3verified rows
Category median 1, across 93 indexed cloud and hosting vendors. Boomi has more verified rows than 99 percent of them.
api managementdata connectivityintegrationipaas
Compare with similar vendors
Pick your own comparisonCompliance grid
SOC 2ReportedCSA STAR Level 2 attestation on the registry, which is built on a SOC 2 examination
as of 17 Sep 20261 source- FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · A-LIGN Compliance and Security, Inc. dba A-LIGN - CSA STARVerified
STAR Level 2 attestation
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkVerifiedActive: EU-US Certification, UK Extension Certification, SW-US Certification
as of 17 Sep 20261 source
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this. Check the vendor trust centre.
Subprocessors
No subprocessor list captured yet.
Similar vendors with evidence
Related by product tags and the Cloud and hosting category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.