Certifications
What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.
Security, privacy, availability and confidentiality trust services criteria; report available on request from sales.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Security, privacy, availability and confidentiality; described as a public report.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
ISMS certification claimed; certificate linked but issuer, certified scope and validity not stated on the page.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Cloud services controls claimed; issuer and validity not stated.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
PII protection in the cloud claimed; issuer and validity not stated.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Privacy information management system claimed; issuer and validity not stated.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
AI management system certification claimed for 'responsible AI development and use'; certified scope, issuer and validity not stated.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Transfers of EU, UK and Swiss personal data to the US; registry-checkable at dataprivacyframework.gov but not verified in this scan.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Self-asserted compliance, not a third-party attestation; PHI may only be processed under a signed Business Associate Agreement.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · CSA STAR Registry · checked Oct 5, 2026
Supply chain
Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.
How to read this
This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Oct 5, 2026.
