Oracle

oracle.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
51 / 100D
Procurement decision
Approve with conditions
4 conditions outstanding
  • No formal subprocessor register disclosed
  • No clear commitment that your data will not train their models
  • Data retention window not stated

+1 more

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Partial

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No formal subprocessor register disclosedCondition

Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.

What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Underlying model providers not namedCondition

Why it matters: AI is used but the public sources scanned do not name which foundation models or providers sit in the request path.

What to ask for: Require named providers and model versions, plus notice before any model change.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Requires written confirmation — see Before you sign ↓

!How long do they keep your data?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Requires written confirmation — see Before you sign ↓

!Who else can access your data?Ask the vendor

Subprocessors with access to services personal information are contractually subject to data protection obligations; a public register is not on the pages scanned.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection
Where is your data processed?Clear

Transfers from the EEA, UK and Switzerland can proceed under the framework approved by the U.S. Department of Commerce where contractually agreed - the Data Privacy Framework.

Evidence
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
(Swiss-U.S. DPF) (collectively, the “DPF”) as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of Services Personal Information when You and Oracle have agreed by contract that transfers of such information from the EEA, United Kingdom (and Gibraltar), or Switzerland will be transferred
What happens in a security incident?Clear

The Services Privacy Policy commits Oracle to promptly evaluate and respond to incidents indicating unauthorized access to or handling of services personal information, with breach notification to customers.

Evidence
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
review. 5. Incident Management and data breach notification. Oracle promptly evaluates and responds to incidents that create suspicion of or indicate unauthorized access to or handling of Services Personal Information. If Oracle becomes aware and determines that an incident involving Services Personal Information
Vendor publishedSecurity Policies and Practices | Oracleretrieved Aug 28, 2026
Integrated Cyber Center The entity responsible for centralized coordination of security incident response, customer trust and security communications matters. Report a security incident

Key findingsclick a row for the evidence

Contract-grade privacy commitments publishedStrong

The Services Privacy Policy publicly enumerates incident response with breach notification, subprocessor obligations, audit rights and deletion/return terms.

Publishing the contractual backbone before negotiation is a transparency signal.

Evidence
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
review. 5. Incident Management and data breach notification. Oracle promptly evaluates and responds to incidents that create suspicion of or indicate unauthorized access to or handling of Services Personal Information. If Oracle becomes aware and determines that an incident involving Services Personal Information
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
Incident Management and breach notification Subprocessors Cross-border data transfers Audit rights Deletion or return of Services Personal Information Notifications to customers and users Services Personal Information is personal information that is provided by You, resides
!No AI governance or AI-specific assurance evidencedGap

The AI surfaces scanned are product marketing; no responsible-AI framework, AI governance documentation or AI-specific certification appears in the public sources.

For a vendor selling AI infrastructure and applications, AI governance evidence is conspicuously absent from the scanned surfaces.

Question for vendor: Provide AI governance documentation and any AI-specific certifications or assessments.

Evidence
Vendor publishedArtificial Intelligence (AI) | Oracleretrieved Aug 28, 2026
and NVIDIA Accelerate AI Deployments on OCI See how we’re partnering with NVIDIA to deliver enterprise-grade AI built for real business outcomes. Learn how to deploy and customize OCI AI Accelerator Packs with NVIDIA GPUs. Access the webinar for Live Demo Day: Oracle and NVIDIA Accelerate
!Certifications referenced only via a compliance portalGap

Security pages link to 'Oracle Cloud compliance' but the fetched surfaces name no certificates with identities.

Program pointers are not evidence.

Question for vendor: Provide certificate identities (ISO 27001 et al.) and current SOC report identities.

Evidence
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
review. 5. Incident Management and data breach notification. Oracle promptly evaluates and responds to incidents that create suspicion of or indicate unauthorized access to or handling of Services Personal Information. If Oracle becomes aware and determines that an incident involving Services Personal Information
!Organisation-level scan of a hyperscalerGap

This scan reads oracle.com's public surfaces; product-level assurance (OCI AI services) requires a product-scoped scan. Note also that oracle.com refuses automated collection outright - this report exists only via operator-run collection.

The collection posture itself is a small transparency signal buyers may weigh.

Evidence
Vendor publishedArtificial Intelligence (AI) | Oracleretrieved Aug 28, 2026
and NVIDIA Accelerate AI Deployments on OCI See how we’re partnering with NVIDIA to deliver enterprise-grade AI built for real business outcomes. Learn how to deploy and customize OCI AI Accelerator Packs with NVIDIA GPUs. Access the webinar for Live Demo Day: Oracle and NVIDIA Accelerate
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score60
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedSecurity Policies and Practices | Oracleretrieved Aug 28, 2026
Oracle Software Security Assurance (OSSA) is Oracle’s methodology for building security into the design, build, testing, and maintenance of its products.
Vendor publishedGovernanceretrieved Aug 28, 2026
aligned with the ISO/IEC 27001:2022 (formerly known as ISO/IEC 17799:2005) and ISO/IEC 27002:2022 standards and guide all areas of security within Oracle.

Governance & accountability: vendor-evidenced, not yet independently corroborated.

AI system15% of the score27
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedArtificial Intelligence (AI) | Oracleretrieved Aug 28, 2026
and NVIDIA Accelerate AI Deployments on OCI See how we’re partnering with NVIDIA to deliver enterprise-grade AI built for real business outcomes. Learn how to deploy and customize OCI AI Accelerator Packs with NVIDIA GPUs. Access the webinar for Live Demo Day: Oracle and NVIDIA Accelerate
Vendor publishedArtificial Intelligence (AI) | Oracleretrieved Aug 28, 2026
Choose from managed open source or proprietary LLMs. Fine-tune prebuilt models and augment them with your own enterprise data. Turn intelligence into action with AI agents. Explore generative AI
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedSecurity Policies and Practices | Oracleretrieved Aug 28, 2026
Oracle Software Security Assurance (OSSA) is Oracle’s methodology for building security into the design, build, testing, and maintenance of its products.
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

Change management: not publicly evidenced.

Model10% of the score0
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Not Evidenced

Model provider transparency: not publicly evidenced.

Customer data15% of the score72
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
(Swiss-U.S. DPF) (collectively, the “DPF”) as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of Services Personal Information when You and Oracle have agreed by contract that transfers of such information from the EEA, United Kingdom (and Gibraltar), or Switzerland will be transferred

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the score40
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection
Security foundation15% of the score77
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
review. 5. Incident Management and data breach notification. Oracle promptly evaluates and responds to incidents that create suspicion of or indicate unauthorized access to or handling of Services Personal Information. If Oracle becomes aware and determines that an incident involving Services Personal Information
Vendor publishedSecurity Policies and Practices | Oracleretrieved Aug 28, 2026
Integrated Cyber Center The entity responsible for centralized coordination of security incident response, customer trust and security communications matters. Report a security incident
Vendor publishedGovernanceretrieved Aug 28, 2026
security event and security incident response, compliance with data protection laws, contractual obligations and reporting requirements,

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the score59
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Partial
Evidence — Independent assurance
Vendor publishedGovernanceretrieved Aug 28, 2026
aligned with the ISO/IEC 27001:2022 (formerly known as ISO/IEC 17799:2005) and ISO/IEC 27002:2022 standards and guide all areas of security within Oracle.

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Independent assurance: vendor-evidenced, not yet independently corroborated.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
Incident Management and breach notification Subprocessors Cross-border data transfers Audit rights Deletion or return of Services Personal Information Notifications to customers and users Services Personal Information is personal information that is provided by You, resides
Vendor publishedServices Privacy Policy | Oracleretrieved Aug 28, 2026
(Swiss-U.S. DPF) (collectively, the “DPF”) as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of Services Personal Information when You and Oracle have agreed by contract that transfers of such information from the EEA, United Kingdom (and Gibraltar), or Switzerland will be transferred
Vendor publishedTransparency in our Contracts and Policies | Oracleretrieved Aug 28, 2026
Oracle has two primary agreements used for the sale of its products and services: the Cloud Services Agreement (CSA) and the Oracle Master Agreement (OMA).

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+6Publish Model provider transparency evidenceModel 060
+3Have Customer data treatment disclosures independently corroboratedData 7287
+3Have Governance & accountability disclosures independently corroboratedOrganisation 6075
+3Have Vulnerability & incident handling disclosures independently corroboratedSecurity Foundation 7792
+3Publish Change management evidenceAI System 2747

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 51 → up to 81 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESINFRASTRUCTUREOracleOracleOCI AI servicesOCI AI servicesNVIDIANVIDIA
View as list
OCI AI services Uses Infrastructure NVIDIA

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 4 — registry checks and verification ladders, click to view
EU-U.S. Data Privacy FrameworkClaimed & corroborated

The Services Privacy Policy provides for EEA/UK/Swiss transfers under the Department of Commerce-approved framework where contractually agreed.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry

ISO/IEC 27001Claimed, scope unclear

Policies stated as ALIGNED with ISO/IEC 27001:2022; certification detail lives on the cloud-compliance pages.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry

Sources 14 — click to view
Artificial Intelligence (AI) | Oracle
AI Documentation · Vendor · retrieved Aug 28, 2026
Security Policies and Practices | Oracle
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Transparency in our Contracts and Policies | Oracle
Subprocessor List · Vendor · retrieved Aug 28, 2026
Privacy @ Oracle | Oracle
Privacy Notice · Vendor · retrieved Aug 28, 2026
Governance
Certification Or Compliance Page · Vendor · retrieved Aug 28, 2026
Oracle AI World 2026
AI Documentation · Vendor · retrieved Aug 28, 2026
Security, Privacy, and Compliance | Oracle
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Services Privacy Policy | Oracle
Privacy Notice · Vendor · retrieved Aug 28, 2026
Cloud Compliance | Oracle
Certification Or Compliance Page · Vendor · retrieved Aug 28, 2026
Terms and Conditions | Oracle AI World 2026
AI Documentation · Vendor · retrieved Aug 28, 2026
Security, Identity, and Compliance | Oracle
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Aug 28, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Oracle at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.