Skip to main content
Cyera logo

Cyera

Security and trust center evidence

cyera.ioSecurityLast verified 17 Sep 2026

Summary

Cyera has 3 registry-verified rows and 8 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.

Reviewer brief

As of 17 Sep 2026, Cyera states on its trust centre that it holds SOC 2, and no auditor or report date is provided in the evidence. As of 17 Sep 2026, Cyera displays a HIPAA badge on its trust centre, described as a claim with BAA availability not yet captured, so this should be treated as offers a BAA pending confirmation rather than a verified attestation. As of 17 Sep 2026, Cyera is listed in the FedRAMP registry with status 'Agency In Process', with Schellman Compliance, LLC named as auditor. As of 17 Sep 2026, Cyera is listed in the CSA STAR registry with a Level 1 self-assessment (CAIQ) issued 6 Dec 2023, and is listed in the EU-US Data Privacy Framework registry as active (EU-US Certification, UK Extension Certification) issued 23 Oct 2025 and expiring 23 Oct 2026. As of 17 Sep 2026, Cyera also states on its trust centre that it holds GDPR, PCI DSS, ISO/IEC 27001:2022, CCPA/CPRA, BSI C5, and ENS coverage, with no public evidence found to independently verify these vendor statements.

  • SOC 2: vendor states on its trust centre that it holds a SOC 2 report (as of 17 Sep 2026); no auditor or report period supplied.
  • FedRAMP: listed in FedRAMP registry as 'Agency In Process' with auditor Schellman Compliance, LLC (as of 17 Sep 2026); CSA STAR Level 1 self-assessment issued 6 Dec 2023; EU-US Data Privacy Framework listing active from 23 Oct 2025 to 23 Oct 2026 (as of 17 Sep 2026).
  • HIPAA: vendor displays a HIPAA badge on its trust centre described as a claim, with BAA availability not yet captured (as of 17 Sep 2026); ISO/IEC 27001:2022, GDPR, PCI DSS, CCPA/CPRA, BSI C5, and ENS are all vendor-stated on its trust centre with no public evidence found to verify them independently.

Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.

Among security vendors

3verified rows

Category median 1, across 174 indexed security vendors. Cyera has more verified rows than 100 percent of them.

data classificationdata discoverydata protectiondlp

Compliance grid

Subprocessors (1)

  • SM
    Status Monitoring Amazon Web Services

Change history

  1. 17 Sep 2026BSI C5 evidence addedA BSI C5 row entered the index with state Vendor-stated.
  2. 17 Sep 2026CCPA / CPRA evidence addedA CCPA / CPRA row entered the index with state Vendor-stated.
  3. 17 Sep 2026ENS evidence addedA ENS row entered the index with state Vendor-stated.
  4. 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
  5. 17 Sep 2026HIPAA evidence addedA HIPAA row entered the index with state Vendor-stated.
  6. 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
  7. 17 Sep 2026PCI DSS evidence addedA PCI DSS row entered the index with state Vendor-stated.
  8. 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
  9. 17 Sep 2026Subprocessor added: Status Monitoring Amazon Web ServicesStatus Monitoring Amazon Web Services appeared on the subprocessor list.

Similar vendors with evidence

Related by product tags and the Security category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.