Certifications
What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.
Self-certification to the U.S. Department of Commerce covering personal data received from the EU, UK (and Gibraltar) and Switzerland; not an independent audit. The privacy policy points to dataprivacyframework.gov; the registry was not checked in this scan.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
- — Vendor claimed
- — Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Oct 5, 2026
Supply chain
Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.
How to read this
This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Oct 5, 2026.
