
Compliance grid
- HIPAAVendor-stated
Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)
as of 17 Sep 20261 source
SOC 2Vendor-statedVendor states SOC 2 Type 2 on its trust centre
as of 17 Sep 20261 source- FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · Fortreum, LLC
PCI DSSVendor-statedVendor states PCI-DSS 4.0 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001:2022 on its trust centre
as of 17 Sep 20261 source- CSA STARVerified
STAR Level 1 self-assessment (CAIQ)
as of 17 Sep 20261 source
ISO/IEC 42001Vendor-statedVendor states ISO/IEC 42001:2023 on its trust centre
as of 17 Sep 20261 source
SOC 1Vendor-statedVendor states SOC 1 Type 2 on its trust centre
as of 17 Sep 20261 source
ISO 9001Vendor-statedVendor states ISO/IEC 9001 : 2015 on its trust centre
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkVerifiedActive: UK Extension Certification, EU-US Certification, SW-US Certification
as of 17 Sep 20261 source
IRAPVendor-statedVendor states IRAP (Protected) on its trust centre
as of 17 Sep 20261 source
No public evidence yet for GDPR, Cyber Essentials, ISO 27701. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Official framework marks identify the scheme each row is about; the CertReports state chip beside each mark is our assessment of the public evidence. How states are decided.