Weaviate
Security and trust center evidence
Bring AI-native applications to life with less hallucination, data leakage, and vendor
Summary
Weaviate has 1 registry-verified row in the CertReports index, last verified 29 Sep 2026. The strongest row is CSA STAR: STAR Level 1 self-assessment (CAIQ). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 29 Sep 2026, CertReports holds 1 registry-verified row for Weaviate, drawn from the CSA STAR registry. Weaviate is listed in the CSA STAR registry for CSA STAR (STAR Level 1 self-assessment (CAIQ)), dated 14 Oct 2024. No public evidence was found for SOC 2, ISO/IEC 27001, HIPAA and GDPR as of 29 Sep 2026; that is a gap in the public record, not a finding of non-coverage, and the vendor can supply it under NDA.
- CSA STAR: STAR Level 1 self-assessment (CAIQ), verified as of 29 Sep 2026
Facts only, each dated; nothing here is inferred, scored or advised.
Among ai infrastructure vendors
1verified rows
Category median 1, across 32 indexed ai infrastructure vendors. Weaviate has more verified rows than 34 percent of them.
Compliance grid
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this. Check the vendor trust centre.
Subprocessors
No subprocessor list captured yet.
Change history
- 29 Sep 2026First indexed by CertReports1 evidence row across 1 framework entered the index.
Evidence against regulations
All regulations for WeaviateHow much of each regulation’s vendor requirements Weaviate’s public evidence reaches.
Reviewing a vendor on public evidence
All articlesSOC 2 Type I vs Type II: what each one proves to a buyer
Solomon Amos · 14 Sep 2026 · 10 min read