← Trust Directory

Glean

glean.com · 1 assessment

Glean - organisation
Approve with conditions
1 item to confirm in writing
Assessed Oct 5, 2026 · public evidence coverage 55% · evidence confidence medium · methodology 0.7.0

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

SOC 2 Type II
Vendor claimed only

Claimed on the legal page and AI security page; the DPA commits to annual independent SOC 2-standard audits with the report available on request. Auditor and period not stated.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
ISO/IEC 27001
Claimed, scope unclear

Claimed on the legal page and AI security page; certification body, certificate scope and expiry not stated.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
ISO/IEC 42001
Claimed, scope unclear

Claimed as ISO/IEC 42001:2023 on the legal page and AI security page; certification body, scope and expiry not stated.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
HIPAA
Vendor claimed only

Compliance statement with BAAs offered; HIPAA has no formal certification scheme.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
TX-RAMP Level 2
Claimed, scope unclear

Appears only as a badge on the AI security page; no certification detail.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
EU-U.S. Data Privacy Framework
Claimed & corroborated

Self-certification stated in the website privacy statement (which excludes the Solutions); DPF list not checked in this scan.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • ✓ Registry corroborated
  • — Scope verified
  • — Current

Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Oct 5, 2026

Supply chain

Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.

AI providers: Anthropic PBC, OpenAI OpCo, LLC, Baseten Labs, Inc., Fireworks.ai, Inc., Groq, Inc., Modal Labs, Inc., Snowflake, Inc.
Infrastructure: Amazon Web Services, Inc., Google LLC, Microsoft Corporation
Subprocessors: Palo Alto Networks, Inc. (Prisma AI Runtime Security), Brave Software, Inc., Deepgram, Inc., Exa Labs, Inc., Glean Search Technologies India Private Limited

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Oct 5, 2026.