
Gemshelf
Security and trust center evidence
Eliminate bad data before it becomes the wrong
Summary
Gemshelf has 5 vendor-stated rows, and 1 expired in the CertReports index, last verified 18 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 18 Sep 2026, CertReports holds 5 vendor-stated rows and 1 expired row for Gemshelf, drawn from its trust centre (Vanta) and the Data Privacy Framework list. Gemshelf states on its trust centre that it holds that it will sign a business associate agreement, a SOC 2 Type II report, a data processing agreement, a PCI DSS attestation of compliance and an CCPA / CPRA privacy notice, captured 18 Sep 2026; these are vendor statements, not independent confirmations. Gemshelf previously appeared with EU-US Data Privacy Framework evidence, but the listing is no longer active and CertReports found no renewal as of 17 Sep 2026. No public evidence was found for ISO/IEC 27001 and FedRAMP as of 18 Sep 2026; that is a gap in the public record, not a finding of non-coverage, and the vendor can supply it under NDA.
- HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured), vendor-stated as of 18 Sep 2026
- SOC 2: Vendor states SOC 2 on its trust centre, vendor-stated as of 18 Sep 2026
- EU-US Data Privacy Framework: Inactive, expired as of 17 Sep 2026
Facts only, each dated; nothing here is inferred, scored or advised.
Evidence count
0verified rows
content governancedata governancegenai answersknowledge management
Compare with similar vendors
Pick your own comparisonCompliance grid
- HIPAAVendor-stated
Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)
as of 18 Sep 20261 source
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 18 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 18 Sep 20261 source
PCI DSSVendor-statedVendor states PCI DSS - SAQ A on its trust centre
as of 18 Sep 20261 source
EU-US Data Privacy FrameworkExpiredInactive
as of 17 Sep 20261 source- CCPA / CPRAVendor-stated
Vendor states CCPA on its trust centre
as of 18 Sep 20261 source
Legal artefacts
Subprocessors (7)
Amazon Web ServicesCloud Computing, Storage, and Infrastructure Services- AUAuth0Authentication Services
- ECElastic CloudSearch and Analytics Services
- GCGoogle CloudCloud provider
Microsoft AzureAI Processing Services
MongoDB AtlasData storage and processing- TUTurboPufferSearch infrastructure
Change history
- 18 Sep 2026HIPAA evidence addedA HIPAA row entered the index with state Vendor-stated.
- 18 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
- 18 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 18 Sep 2026PCI DSS evidence addedA PCI DSS row entered the index with state Vendor-stated.
- 18 Sep 2026CCPA / CPRA evidence addedA CCPA / CPRA row entered the index with state Vendor-stated.
- 18 Sep 2026Subprocessor added: TurboPufferTurboPuffer appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: MongoDB AtlasMongoDB Atlas appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: Microsoft AzureMicrosoft Azure appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: Google CloudGoogle Cloud appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: Elastic CloudElastic Cloud appeared on the subprocessor list.
Similar vendors with evidence
Related by product tags, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.
Collibra
Research and data providers
Your system of record for
OneTrust
Compliance and GRC
OneTrust’s mission is to enable organizations to use data and AI
Egnyte
Cloud storage
Egnyte is the only file sharing platform that adheres to data gravity - the simple idea that not all files were meant to be "up in the
iManage
Legal tech
iManage was founded in 1995 and initially merged with Interwoven in