← Trust Directory

Read AI

read.ai · 1 assessment

Read AI - organisation
Do not approve on current evidence
3 blocking issues to resolve before signing
Assessed Oct 5, 2026 · public evidence coverage 50% · evidence confidence medium · methodology 0.7.0

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

SOC 2 Type II
Vendor claimed only

Stated as an annual independent audit covering access management, encryption, monitoring and incident response. Auditor, report period and system boundary not stated publicly; report said to be available via trust.read.ai.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
HIPAA
Vendor claimed only

Self-stated conformance to HIPAA technical safeguard requirements with a BAA available on request; not described as a third-party certification or attestation.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF)
Vendor claimed only

Self-certification to the DPF Principles for EEA, UK and Swiss personal data; the Data Privacy Framework list was not checked within this scan.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
ISO/IEC 42001
Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

  • — Vendor claimed
  • — Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
EU-U.S. Data Privacy Framework
Claimed & corroborated
  • ✓ Vendor claimed
  • ✓ Evidence cited
  • ✓ Registry corroborated
  • — Scope verified
  • — Current

Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Oct 5, 2026

Supply chain

Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.

AI providers: OpenAI, Anthropic

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Oct 5, 2026.