Skip to content

The datasheet for every AI agent

Research report · data-report

Certifications: a census of 143 listings

63 of 143 listings answer yes for “Certifications”. Counted from our own datasheet, with the query that reproduces every figure.

Sep 23, 2026updated Oct 3, 20262 min readSource-linked research

Certifications, across 143 settled listings

  1. Yes63 of 143

  2. Qualified50 of 143

  3. No4 of 143

  4. Not established26 of 143

Of the 143 Published listings whose datasheet settles “Certifications”, the largest group is “Yes” at 63 (44%). Measured 2026-10-03.

Denominator: 143 Published listings whose datasheet settles “Certifications”.Method: Counted from the stored datasheet answer for “Certifications” across every Published listing, all of which have a recognised stored answer on that row.Measured .
Cite this chart

Reuse this chart anywhere, with credit. Paste this HTML — it links back to the report the numbers come from.

<a href="https://theagentsindex.com/blog/compliance-census/" target="_blank" rel="nofollow noopener"><img src="https://theagentsindex.com/charts/compliance-census.png" alt="Certifications, across 143 settled listings — The Agents Index" title="Certifications, across 143 settled listings — The Agents Index" width="640" loading="lazy" style="max-width:100%;height:auto" /></a>

Explore the matching agents

Certifications · Datasheet criterion compliance · Report counted .

Current listings as of ; this set may differ from the report's original sample. Includes “Yes” and “Qualified” answers only. Read the conditions on qualified answers before treating them as a match. “No”, “Not applicable” and “Not established” answers are excluded.

View 114 current matching records
  • 11x Yes

    The vendor publishes SOC 2 Type II and CASA Tier 3 certifications with a trust portal, plus GDPR alignment with DPAs for EU customers and CCPA compliance.

    Source retrieved 2026-09-23

  • Ada Yes

    The vendor claims SOC 2 Type II, HIPAA and PCI DSS certification, GDPR compliance and AIUC-1, plus annual third-party penetration tests including the LLMs.

    Source retrieved 2026-10-03

  • AgentsKit.js Qualified

    No vendor certification is published, which fits a library with no hosted service; what ships is compliance machinery — a tamper-evident log and erasure helpers.

    Source retrieved 2026-09-09

  • Agno Qualified

    SOC 2 compliance is asserted on the homepage; Enterprise adds security reviews. No ISO 27001 or GDPR claim found.

    Source retrieved 2026-09-02

  • Aide Yes

    SOC 2 Type II verified by an independent auditor over an extended monitoring period with recurring audits, plus GDPR and HIPAA; the report is available on request for vendor review.

    Source retrieved 2026-09-23

  • Aisera Agent Composer (Agent Studio) Yes

    Aisera names a full certification set covering security and privacy frameworks, and adds PII anonymisation; certificates themselves are not published on the page, so the claim rests on the vendor's own statement.

    Source retrieved 2026-09-24

  • Amplemarket Yes

    SOC 2 Type II is maintained and audited annually by external assessors, a public trust portal carries the documentation, and the vendor publishes GDPR and CCPA pages plus a Data Privacy Framework transfer basis.

    Source retrieved 2026-09-10

  • API.market Qualified

    GDPR compliance is claimed with concrete deletion and retention commitments, but I found no SOC 2 or ISO 27001 attestation claimed anywhere on the site or docs.

    Source retrieved 2026-10-03

  • Argorant Qualified

    GDPR, UK GDPR and CCPA are addressed with a standard DPA, SCCs and documented safeguards, but no SOC 2 or ISO 27001 certification is claimed anywhere on the site, docs or help centre.

    Source retrieved 2026-09-26

  • Artisan Yes

    SOC 2 Type II certified and GDPR-aligned with a DPA and EU, UK representatives named; no ISO 27001 claim appears anywhere, and the trust centre keeps the pentest report and policies behind an access request.

    Source retrieved 2026-09-10

  • AudioCodes Live Hub Yes

    The vendor names ISO 27001:2022, ISO 27032:2023 and SOC 2 Type 2 certification and publishes a GDPR notice specific to Live Hub alongside the platform privacy policy.

    Source retrieved 2026-09-24

  • Augment Code Yes

    SOC 2 Type II on both plans, ISO/IEC 42001 certified AI management system, GDPR and CCPA obligations in the terms.

    Source retrieved 2026-09-02

  • Auto-Respond Qualified

    GDPR, UK and Swiss transfers and CCPA service-provider duties are covered contractually by a DPA with the EU SCCs, but the vendor explicitly claims no certification or completed independent audit.

    Source retrieved 2026-09-11

  • Bitsclan IT Solutions Qualified

    The strongest first-party wording is aligned and aware rather than certified, while other pages claim adherence to ISO 27001 and SOC 2; no certificate, audit report or trust page is published to confirm either.

    Source retrieved 2026-09-11

  • Bland Yes

    SOC 2 Type II, HIPAA with BAA, GDPR and PCI DSS v4.0 are all claimed, with reports released under NDA on Enterprise.

    Source retrieved 2026-09-11

  • Bolt Yes

    SOC 2 Type 2 is certified rather than in progress, with GDPR and CCPA compliance claimed and reports released through the trust profile.

    Source retrieved 2026-09-11

  • Botpress Qualified

    SOC 2 and GDPR are claimed with KPMG penetration testing and US/EU/Swiss Data Privacy Framework certification; a DPA comes with Team and up, a HIPAA BAA only with Enterprise, and ISO 27001 is claimed nowhere.

    Source retrieved 2026-09-02

  • Botsify Qualified

    GDPR compliance is claimed on the privacy and GDPR pages and the FAQ claims AES-256 encrypted storage, but no SOC 2, ISO 27001 or third-party audit report is published anywhere on the site.

    Source retrieved 2026-09-13

  • Browserbase Yes

    SOC 2 Type II on every plan; HIPAA BAA and DPA on Scale only; third-party penetration testing.

    Source retrieved 2026-09-02

  • Cartesia Yes

    GDPR, SOC 2 Type II, HIPAA and PCI-DSS service provider, with a public Trust Center; DPAs and BAAs come with Enterprise.

    Source retrieved 2026-09-02

  • Claude Agent SDK Yes

    SOC 2 Type 2 and ISO 27001 artefacts are published through the Trust Center, and the Claude API offers a self-serve BAA for HIPAA readiness; GDPR is not named on this page.

    Source retrieved 2026-09-02

  • Claude Code Yes

    SOC 2 Type 2 and ISO 27001 artefacts are published at the Trust Center; a HIPAA-ready offering and zero data retention are Enterprise options.

    Source retrieved 2026-09-02

  • CodeRabbit Yes

    The trust centre publishes SOC 2 Type 2, ISO 27001:2022 and GDPR, with SOC 3, pentest and zero-data-retention amendments from OpenAI and Anthropic available on request.

    Source retrieved 2026-09-15

  • Codex CLI Yes

    SOC 2 Type 2 report plus ISO 27001, 27017, 27018 and 27701 certification, with GDPR and CCPA listed on the trust portal.

  • CommentKeyword Qualified

    A GDPR-shaped DPA with SCCs, named sub-processors and documented technical measures exists, but the vendor only offers certifications 'if any' — no SOC 2 or ISO 27001 attestation is claimed.

    Source retrieved 2026-09-28

  • Crescendo Yes

    SOC 2 Type II, ISO 27001 and HIPAA attestation with GDPR- and CCPA-aligned controls; certificates and the DPA are requestable from the trust portal, and a BAA is available.

    Source retrieved 2026-09-12

  • Cresta Yes

    Audited to SOC 2 Type II with ISO 27001, 27701 and 42001 certifications, plus PCI DSS Level 1 service-provider status, a HIPAA business associate agreement, a GDPR data processing addendum and TISAX on the trust centre.

    Source retrieved 2026-09-13

  • CrewAI Yes

    The trust centre publishes a SOC 2 Type 2 programme with reports on request, plus a HIPAA audit report and pen test, and Enterprise adds FedRAMP High and SAM deployment options.

    Source retrieved 2026-09-13

  • Cursor Yes

    SOC 2 Type II attestation plus ISO/IEC 27001:2022, ISO/IEC 42001:2023 and AIUC-1; GDPR and CCPA compliance claimed, reports via the trust portal on request.

    Source retrieved 2026-09-02

  • Decagon Yes

    A full enterprise set is claimed and the trust centre carries the underlying reports, including a SOC 2 Type II report and an ISO 27001 certificate.

    Source retrieved 2026-09-14

  • Deepgram Voice Agent API Yes

    SOC 2 Type 1 and Type 2, HIPAA with a BAA for Enterprise, GDPR with an EU endpoint, CCPA and PCI with yearly review. ISO 27001 is not claimed anywhere on the site.

    Source retrieved 2026-09-02

  • Devin Qualified

    SOC 2 Type II since September 2024; the Trust Center additionally lists ISO/IEC 27001:2022 and CCPA, behind an NDA request.

    Source retrieved 2026-09-02

  • Devin Desktop Qualified

    SOC 2 Type II since September 2024, and Devin Desktop is marked available at FedRAMP High, IL4/IL5 and ITAR with Zero Data Retention in federal deployments; the docs claim no ISO 27001 or GDPR position.

    Source retrieved 2026-09-03

  • Dify Qualified

    GDPR handling is documented in the privacy policy (SCCs, EEA/UK/Swiss rights, DPA); SOC 2 Type II and ISO 27001 are asserted only in the Enterprise page metadata, with no trust page or report to verify.

    Source retrieved 2026-09-02

  • Dust Yes

    Dust states GDPR compliance and SOC 2 Type II certification, says it enables HIPAA compliance, and publishes a Trust Center; ISO 27001 is not claimed on the page read.

    Source retrieved 2026-10-01

  • ElevenLabs Agents Yes

    SOC 2, ISO 27001, GDPR and HIPAA are all claimed, with BAAs for HIPAA customers listed on the Enterprise plan and zero-retention available as a configuration.

    Source retrieved 2026-09-02

  • Elicit Yes

    A Vanta trust centre publishes a SOC 2 Type 2 report plus SOC 3, Cyber Essentials, VPAT and HECVAT; GDPR and CCPA are handled through a DPA with standard contractual clauses.

    Source retrieved 2026-09-14

  • Factory Yes

    SOC 2 Type II, ISO 27001 and ISO 42001, with reports and sub-processor lists in the Trust Center.

    Source retrieved 2026-09-02

  • Fin Yes

    The certification set is broad and independently audited, adding an AI-specific pair (ISO 42001 and AIUC-1 for the agent itself) to the usual SOC 2, ISO 27001 and privacy standards, with documentation self-serve in a trust centre.

    Source retrieved 2026-09-18

  • Firecrawl Qualified

    SOC 2 Type II and regular penetration testing are listed as included on every tier, and paid plans get a DPA; no ISO 27001 claim appears on the pages read.

    Source retrieved 2026-09-24

  • GC AI Yes

    SOC 2 Type II, SOC 3 and GDPR are all claimed, with the SOC 2 report available under NDA through the Trust Center and a DPA included in the standard terms for every customer.

    Source retrieved 2026-09-14

  • Gemini Code Assist Yes

    SOC 1, SOC 2 and SOC 3 plus ISO/IEC 27001, 27017, 27018 and 27701, listed for both editions. GDPR is not claimed as a certification; data handling sits under the Cloud Data Processing Addendum.

    Source retrieved 2026-09-02

  • Genspark Qualified

    SOC 2 Type II and ISO 27001 certifications are claimed with a public trust portal, but GDPR is listed as a programme in progress and a DPA is not offered on the Team plan.

    Source retrieved 2026-09-15

  • GitHub Copilot Qualified

    SOC 1, SOC 2, SOC 3, ISO 27001, ISO/IEC 42001, CSA STAR Level 2 and TISAX are listed in the Copilot Trust Center, but the reports and ISMS scope name Business and Enterprise only; GDPR is handled through a Data Protection Agreement.

    Source retrieved 2026-09-02

  • Glean Yes

    SOC 2 Type 2, ISO 27001:2022, ISO/IEC 42001:2023, HIPAA and GDPR, with reports and certificates available on request; the marketing site adds TX-RAMP Level 2.

    Source retrieved 2026-09-02

  • Gumloop Yes

    SOC 2 Type II attestation, HIPAA with BAAs on eligible plans, a GDPR-aligned programme and EU-U.S. Data Privacy Framework certification including the UK extension.

    Source retrieved 2026-09-30

  • HeyRik Qualified

    The vendor commits to GDPR and India DPDP Act rights with a named grievance officer, but publishes no SOC 2, ISO 27001 or any other audited certification on any page or plan.

    Source retrieved 2026-09-10

  • HOL Guard Qualified

    GDPR and CCPA handling is documented in detail with lawful bases, retention periods and self-serve rights, but no SOC 2 or ISO 27001 attestation is claimed on the pricing, enterprise or security trust pages.

    Source retrieved 2026-09-07

  • IrisAgent Yes

    The vendor claims SOC 2 Type II certification plus HIPAA, GDPR, CCPA and PCI DSS alignment, with an air-gapped option for regulated buyers; ISO 27001 is not mentioned.

    Source retrieved 2026-09-24

  • jobfinder-ai Qualified

    GDPR-style access, correction and erasure rights plus AES-256-GCM at rest and TLS in transit are documented, but no SOC 2, ISO 27001 or audited certification is claimed on any page.

    Source retrieved 2026-09-14

  • Julius AI Yes

    SOC 2 Type II and TX-RAMP are claimed with continuous monitoring and a trust centre for report requests; GDPR is addressed through an offered DPA with standard contractual clauses, while ISO 27001 is never claimed.

    Source retrieved 2026-09-17

  • Junie Yes

    The Trust Center lists a SOC 2 Type II report scoped to Junie specifically, alongside GDPR; no ISO 27001 certification appears among the published compliance resources.

    Source retrieved 2026-09-18

  • Kalyvox Qualified

    GDPR compliance is claimed directly with a named DPO contact, AES-256 and TLS 1.3 encryption and regular penetration tests, but the only certification cited is ISO 27001 held by the AWS hosting layer; no SOC 2 or Kalyvox-held ISO certificate is published.

    Source retrieved 2026-09-26

  • Kilo Code Qualified

    SOC 2 Type II is claimed with the report available through the Trust Center; no ISO 27001 or GDPR certification claim appears on the site.

    Source retrieved 2026-09-02

  • LangChain Yes

    The platform claims SOC 2 Type II, GDPR and HIPAA with annual third-party audits and penetration testing, plus AES-256 at rest and TLS 1.2 or higher in transit.

    Source retrieved 2026-09-18

  • LangGraph Yes

    SOC 2 Type II, GDPR and HIPAA, with annual third-party audits and penetration testing; data encrypted AES-256 at rest and TLS 1.2 or higher in transit.

    Source retrieved 2026-09-02

  • Lead Scorer Qualified

    GDPR posture is documented in detail, including an Article 28 processing agreement on request and a named subprocessor annex, but no SOC 2 or ISO 27001 certification is claimed anywhere.

    Source retrieved 2026-09-18

  • Leaping AI Yes

    The vendor claims active GDPR and HIPAA compliance plus SOC 2 certification released on request, and its comparison pages add ISO; no certificate, report or trust page is published on the site itself.

    Source retrieved 2026-09-09

  • Letta Qualified

    GDPR and US state privacy rights are documented; no SOC 2 or ISO 27001 attestation appears anywhere on the site.

    Source retrieved 2026-09-02

  • Lindy Yes

    SOC 2 Type II audited by Johanson Group, plus GDPR, HIPAA and PIPEDA, with a Trust Center for reports; the signed BAA for HIPAA is reserved for the Enterprise plan.

    Source retrieved 2026-09-19

  • LiveKit Agents Qualified

    SOC 2 Type II active, GDPR and CCPA/CPRA compliant, EU-US DPF certified; ISO 27001 and PCI DSS still in progress, HIPAA BAAs only for Scale and Enterprise, and the security reports row is Scale and above.

    Source retrieved 2026-09-02

  • LlamaIndex Yes

    SOC 2 Type 2 certified, HIPAA compliant and GDPR-adherent; BAAs are Enterprise-only.

    Source retrieved 2026-09-02

  • LuMay Yes

    Two certifications are asserted outright rather than as alignment, with GDPR readiness and HIPAA handled through a BAA on private-cloud or on-premises deployments.

    Source retrieved 2026-09-09

  • Manus Yes

    The Trust Center publishes SOC 2 Type I and Type II attestations plus ISO 27001 and ISO 27701 certificates for download, and the privacy policy addresses EU and UK GDPR roles.

    Source retrieved 2026-09-19

  • Mastra Qualified

    SOC 2 documentation is offered from the Teams plan; a DPA covering GDPR, UK GDPR and CCPA/CPRA is published, and a Vanta-hosted trust centre carries the security programme. No ISO 27001 claim found.

    Source retrieved 2026-09-02

  • Maven AGI Yes

    A deep certification stack is claimed and partly independently audited: SOC 2 Type II, ISO 27001:2022, PCI DSS 4.0 Level 1 and HIPAA/HITECH are stated as achieved, while ISO 27701/42001/27017/27018 and the GDPR, CCPA and CPRA privacy attestations are dated as expected Q1 2026.

    Source retrieved 2026-09-25

  • MindStudio Yes

    SOC 2 Type I and Type II reports plus GDPR are published in the trust centre, and SOC 2 Type II and GDPR are ticked on both the Individual and Business columns.

    Source retrieved 2026-09-20

  • Moveworks Yes

    A long certification wall covering SOC 2 Type 2, the ISO 27001 family, ISO 42001, CSA STAR Level 2, GDPR, CCPA and FedRAMP authorisation.

    Source retrieved 2026-09-20

  • n8n Qualified

    SOC 2 audited with external pen tests and a public Trust Center; GDPR is covered by a pre-signed DPA carrying the Standard Contractual Clauses. No ISO 27001 claim appears anywhere on the site.

    Source retrieved 2026-09-02

  • NeverApply Qualified

    GDPR and CCPA rights are honoured for all users and card handling runs on PCI-DSS Level 1 Stripe, but no SOC 2 or ISO 27001 certification is claimed.

    Source retrieved 2026-09-29

  • OmniDimension Qualified

    No certification is published: security assurances are sold as an Enterprise-only custom DPA and security review, and the vendor's own healthcare page states its HIPAA attestation is not published.

    Source retrieved 2026-09-09

  • OpenAI Realtime API Yes

    The API Platform is in scope for OpenAI's SOC 2 Type 2 report and its ISO/IEC 27001:2022 certificate, with 27017, 27018 and 27701 control sets and GDPR listed on the trust portal.

    Source retrieved 2026-09-02

  • OpenCode Qualified

    A SOC 2 Type 2 report is available under NDA through the Trust Center, whose framework list shows SOC 2 Type 1 and Type 2 only.

    Source retrieved 2026-09-02

  • Perplexity Yes

    SOC 2 Type II, HIPAA, GDPR and PCI DSS are named on the Enterprise Pro card; the API docs add a 2025 HIPAA gap assessment and a CAIQlite assessment via the Trust Center.

    Source retrieved 2026-09-02

  • Pickaxe Yes

    The vendor claims a SOC 2 examination plus GDPR and CCPA compliance, with reports offered to enterprise customers through a Trust Center whose link did not resolve when tested.

    Source retrieved 2026-09-09

  • PitchAI Agent Engine Qualified

    GDPR compliance is asserted for processing, but no SOC 2, ISO 27001 or other audited certification is claimed on either published page.

    Source retrieved 2026-10-03

  • PolyAI Yes

    ISO/IEC 27001 and SOC 2 Type II certified, GDPR compliant, HIPAA and PCI-DSS where relevant, plus UK Cyber Essentials and Cyber Essentials Plus.

    Source retrieved 2026-09-02

  • Pydantic AI Qualified

    The certifications cover the hosted platform, not the library: SOC 2 Type 2 audited, GDPR with a DPA, and HIPAA under a signed BAA, with the report itself behind a document request.

    Source retrieved 2026-09-02

  • Qualified Qualified

    A SOC 2 Type II audit is performed annually and the report is available on request, and GDPR compliance is claimed; the ISO 27001 accreditation cited belongs to AWS as host, not to Qualified itself.

    Source retrieved 2026-09-22

  • Relevance AI Yes

    SOC 2 Type II and GDPR are claimed on every tier with third-party assessment reports offered to Enterprise under NDA; no ISO 27001 certification is claimed anywhere read.

    Source retrieved 2026-09-22

  • Replit Agent Qualified

    Replit states its own SOC 2 Type 2 attestation; the ISO 27001 claim on the same page belongs to Google Cloud, not to Replit.

    Source retrieved 2026-09-22

  • Retell AI Yes

    HIPAA, GDPR and SOC 2 Type 1 and Type 2 are claimed, with BAA and DPA self-signing at no extra fee and reports available through a trust centre.

    Source retrieved 2026-09-23

  • Rox Yes

    SOC 2 Type I and Type II and GDPR are claimed, with a self-serve Trust Center carrying the reports under click-wrap NDA; ISO 27001 is marked 'Coming soon', so it is not yet held.

    Source retrieved 2026-09-03

  • SafeNet Creations Qualified

    The only compliance claim is the Sri Lankan Personal Data Protection Act; no SOC 2, ISO 27001 or GDPR certification appears, and the Canada page declines to promise legal compliance.

    Source retrieved 2026-09-28

  • Salesforce Agentforce Yes

    The Agentforce-scoped audits section lists SOC 2, ISO 27001/27017/27018, ISO 42001, EU/UK Binding Corporate Rules and Data Privacy Framework; a footnote excludes Agentforce Vibes and Agentforce for Scale, and FedRAMP sits with Government Cloud Plus.

    Source retrieved 2026-09-03

  • SalesTouch Qualified

    A full GDPR Article 28 processing agreement with audit rights is published, but no SOC 2 or ISO 27001 certification is claimed anywhere on the site.

    Source retrieved 2026-09-25

  • SEObot Qualified

    GDPR is addressed in detail with named data-subject rights and a legal basis, but no SOC 2, ISO 27001 or other audited certification is claimed anywhere on the site.

    Source retrieved 2026-09-25

  • SEOmatic Qualified

    GDPR compliance is substantiated with a published Article 28 DPA and EU rights process, but the vendor states plainly that it holds neither SOC 2 nor ISO 27001.

    Source retrieved 2026-10-03

  • Sierra Yes

    An unusually wide certification set is claimed and mirrored in the Trust Center, covering SOC 2, ISO 27001, ISO 42001, GDPR, HIPAA, PCI and FedRAMP High.

    Source retrieved 2026-09-26

  • Sim Qualified

    SOC2 is claimed on the homepage but the plan table lists 'SOC2 Compliance' only in the Enterprise column; the privacy policy addresses GDPR and CCPA. No ISO 27001 claim found.

    Source retrieved 2026-09-03

  • sipgate flow Yes

    ISO 27001 certification is claimed alongside GDPR and EU AI Act readiness, though SOC 2 is never mentioned and no certificate or audit report is linked from the site.

    Source retrieved 2026-09-26

  • SkipCalls Qualified

    GDPR-oriented data consent appears as a shipped feature, but no SOC 2, ISO 27001 or HIPAA attestation is claimed anywhere on the site.

    Source retrieved 2026-09-26

  • Spiich Yes

    ISO/IEC 27001:2022 certified with a named certificate and scope, plus CASA Tier 2 and a GDPR data processing agreement; SOC 2 is only a roadmap item.

    Source retrieved 2026-09-15

  • StackAI Yes

    The docs claim SOC 2 Type II, HIPAA, GDPR, CCPA-CPRA and ISO 27001, a SOC 2 report is requestable and a BAA is listed as an Enterprise-only row.

    Source retrieved 2026-09-09

  • Synthflow Yes

    ISO 27001:2022, SOC 2, GDPR, HIPAA and PCI DSS v4.0.1, with documents in a Trust Vault.

    Source retrieved 2026-09-03

  • Tale Qualified

    Ruler GmbH holds ISO/IEC 27001 covering Tale Enterprise and offers a GDPR/FADP DPA with a custom DPA on Enterprise, but no SOC 2 report is published.

    Source retrieved 2026-10-03

  • TecAdRise Qualified

    GDPR/RODO compliance and generic security controls are asserted on the terms page, but no SOC 2, ISO 27001 or any third-party audit certification is claimed anywhere on the site.

    Source retrieved 2026-09-12

  • TelEcho Yes

    SOC 2 Type II is claimed as attained with the report shown only under NDA, HIPAA is available through a signed BAA, and GDPR and UK GDPR are covered by a DPA with SCCs; ISO 27001 is not mentioned anywhere on the site.

    Source retrieved 2026-09-16

  • Telnyx Voice AI Agents Yes

    SOC 2 Type II is claimed on the product page, and GDPR, PCI and HIPAA readiness is presented as standard on every plan including pay-as-you-go rather than a paid enterprise add-on.

    Source retrieved 2026-09-09

  • TinyFish Qualified

    ISO 27001:2022 is certified and published in a Vanta trust center; no SOC 2 is listed, and GDPR/CCPA appear only as data-subject rights.

    Source retrieved 2026-09-03

  • UiPath Agent Builder Yes

    The Agent Builder page claims independent ISO 42001 and AIUC-1 certification, and UiPath's privacy page adds ISO 27001 and SOC 2 Type II, a GDPR commitment and a HIPAA business associate agreement; FedRAMP Moderate is scoped to Public Sector only.

    Source retrieved 2026-09-03

  • Undermind Qualified

    No SOC 2, ISO 27001 or GDPR certification is claimed; the published assurance is third-party penetration testing with a letter of attestation under NDA.

    Source retrieved 2026-09-03

  • Unify Qualified

    SOC 2 Type II is maintained with external audits and threat monitoring, and GDPR rights are documented, but no ISO 27001 certification is claimed.

    Source retrieved 2026-09-27

  • Vapi Qualified

    SOC 2 Type II and a HIPAA BAA sit in the Scale contract, and the plan table shows SOC2 only in that column; HIPAA mode is a $2,000/month add-on on either plan.

    Source retrieved 2026-09-03

  • VeraDial Qualified

    The SOC 2 Type II claim belongs to Twilio as the carriage layer, not to VeraDial itself; GDPR, PIPEDA, CCPA and Quebec Law 25 rights are honoured, while HIPAA and regulated-industry features are explicitly excluded at every price.

    Source retrieved 2026-09-22

  • VoiceAgents Qualified

    Compliance is framed entirely on Nigerian law (NDPA 2023, NDPR 2019, NDPC oversight), with a DPA available and TLS 1.2+ and AES-256 asserted. No SOC 2, ISO 27001 or GDPR certification is claimed anywhere on the site.

    Source retrieved 2026-09-03

  • VoiceFleet Qualified

    GDPR posture is documented in depth with a published DPA, SCCs, a subprocessor schedule and baseline security measures, but no SOC 2 or ISO 27001 certification is claimed and third-party assurance is offered only as whatever exists.

    Source retrieved 2026-10-03

  • Warmly Qualified

    SOC 2 Type II certified and GDPR-ready; ISO 27001 is listed as in progress on the enterprise security table.

    Source retrieved 2026-09-03

  • Warp Yes

    SOC 2 Type II attested, report on request via the trust centre; GDPR handled contractually through a DPA with EU SCCs and the UK Addendum. ISO 27001 is claimed only of Google's datacentres, not of Warp.

    Source retrieved 2026-09-03

  • Webhound Qualified

    GDPR and UK GDPR legal bases and data-subject rights are set out in the privacy notice, but no SOC 2, ISO 27001 or other certification is claimed anywhere on the site.

    Source retrieved 2026-09-27

  • Xquik Qualified

    GDPR-style lawful bases, data-subject rights and California rights are documented, but no SOC 2, ISO 27001 or other third-party certification is claimed.

    Source retrieved 2026-10-03

  • Zencoder Yes

    SOC 2 Type II, ISO 27001 and ISO 42001 certification are claimed alongside GDPR compliance, with reports offered through a hosted trust centre.

    Source retrieved 2026-09-09

  • Zendesk AI agents Yes

    SOC 2 Type II (under NDA), ISO 27001:2022 plus ISO 42001 for AI management, GDPR via DPA and BCRs, HIPAA with a BAA.

    Source retrieved 2026-09-03

  • ZTABS Qualified

    They implement SOC 2, HIPAA and GDPR controls in client systems and describe architecture as SOC 2-aligned or SOC 2-ready, but publish no certification held by ZTABS itself.

    Source retrieved 2026-09-25

The population

143 listings in this index are Published. This is the population as of 2026-10-03. 143 of the 143 published listings in this index carry a settled answer for “Certifications”. That row asks: SOC 2, ISO 27001, GDPR? Every listing in the index is settled on this row, so nothing is left out.

Findings

  1. 63 of the 143 settled listings answer “Yes” for “Certifications”. That is 44% of the settled set.

  2. 50 of the 143 settled listings answer “Qualified” for “Certifications”. That is 35% of the settled set.

  3. 4 of the 143 settled listings answer “No” for “Certifications”. That is 3% of the settled set.

  4. 26 of the 143 settled listings answer “Not established” for “Certifications”. That is 18% of the settled set.

1 of those yes answers is Maven AGI, which still answers yes for “Certifications”. Its listing carries the stored answer and links to the source recorded for it. This is one worked example, not an independent audit of every source in the census.

What we counted, and how

Each figure above is a count over the “Certifications” row of the listing datasheet, taken from the same stored answer the listing page renders. The denominator is the 143 listings whose answer is settled, meaning one of yes, qualified, no, does not apply, not established. On this row that is the whole index, because every listing has a recognised stored answer. Every number here is stored with the read-only query that reproduces it and re-run every sixty seconds against the live corpus, so a figure that stops reproducing surfaces as drift rather than as a stale sentence nobody notices. Our full method covers how a datasheet row is settled in the first place.

Limitations

This counts stored datasheet answers, not independently tested capabilities. A sourced answer can record a vendor statement or our reading of published evidence; this census does not re-fetch those sources. “Not established” means we have not established an answer. That can reflect vendor nondisclosure, blocked evidence, or unfinished research, not a no. An absent or unrecognised answer is excluded rather than treated as a researched finding. The figures are restated when the stored corpus changes; the date above is the count used for this published version, not a new verification of the vendors.

Get the next report

New agents rankings and fresh data reports. One short email, one-click unsubscribe.