Oracle
oracle.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No formal subprocessor register disclosed
- No clear commitment that your data will not train their models
- Data retention window not stated
+1 more
See Before you sign, with what to ask for ↓
Scanned Aug 28, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.
What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.
Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.
What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
Why it matters: AI is used but the public sources scanned do not name which foundation models or providers sit in the request path.
What to ask for: Require named providers and model versions, plus notice before any model change.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
!Will they train on your data?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
!How long do they keep your data?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
!Who else can access your data?Ask the vendor
Subprocessors with access to services personal information are contractually subject to data protection obligations; a public register is not on the pages scanned.
Requires written confirmation — see Before you sign ↓
“Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection”
✓Where is your data processed?Clear
Transfers from the EEA, UK and Switzerland can proceed under the framework approved by the U.S. Department of Commerce where contractually agreed - the Data Privacy Framework.
“(Swiss-U.S. DPF) (collectively, the “DPF”) as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of Services Personal Information when You and Oracle have agreed by contract that transfers of such information from the EEA, United Kingdom (and Gibraltar), or Switzerland will be transferred”
✓What happens in a security incident?Clear
The Services Privacy Policy commits Oracle to promptly evaluate and respond to incidents indicating unauthorized access to or handling of services personal information, with breach notification to customers.
“review. 5. Incident Management and data breach notification. Oracle promptly evaluates and responds to incidents that create suspicion of or indicate unauthorized access to or handling of Services Personal Information. If Oracle becomes aware and determines that an incident involving Services Personal Information”
“Integrated Cyber Center The entity responsible for centralized coordination of security incident response, customer trust and security communications matters. Report a security incident”
Key findingsclick a row for the evidence
✓Contract-grade privacy commitments publishedStrong
The Services Privacy Policy publicly enumerates incident response with breach notification, subprocessor obligations, audit rights and deletion/return terms.
Publishing the contractual backbone before negotiation is a transparency signal.
“review. 5. Incident Management and data breach notification. Oracle promptly evaluates and responds to incidents that create suspicion of or indicate unauthorized access to or handling of Services Personal Information. If Oracle becomes aware and determines that an incident involving Services Personal Information”
“Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection”
“Incident Management and breach notification Subprocessors Cross-border data transfers Audit rights Deletion or return of Services Personal Information Notifications to customers and users Services Personal Information is personal information that is provided by You, resides”
!No AI governance or AI-specific assurance evidencedGap
The AI surfaces scanned are product marketing; no responsible-AI framework, AI governance documentation or AI-specific certification appears in the public sources.
For a vendor selling AI infrastructure and applications, AI governance evidence is conspicuously absent from the scanned surfaces.
Question for vendor: Provide AI governance documentation and any AI-specific certifications or assessments.
“and NVIDIA Accelerate AI Deployments on OCI See how we’re partnering with NVIDIA to deliver enterprise-grade AI built for real business outcomes. Learn how to deploy and customize OCI AI Accelerator Packs with NVIDIA GPUs. Access the webinar for Live Demo Day: Oracle and NVIDIA Accelerate”
!Certifications referenced only via a compliance portalGap
Security pages link to 'Oracle Cloud compliance' but the fetched surfaces name no certificates with identities.
Program pointers are not evidence.
Question for vendor: Provide certificate identities (ISO 27001 et al.) and current SOC report identities.
“review. 5. Incident Management and data breach notification. Oracle promptly evaluates and responds to incidents that create suspicion of or indicate unauthorized access to or handling of Services Personal Information. If Oracle becomes aware and determines that an incident involving Services Personal Information”
!Organisation-level scan of a hyperscalerGap
This scan reads oracle.com's public surfaces; product-level assurance (OCI AI services) requires a product-scoped scan. Note also that oracle.com refuses automated collection outright - this report exists only via operator-run collection.
The collection posture itself is a small transparency signal buyers may weigh.
“and NVIDIA Accelerate AI Deployments on OCI See how we’re partnering with NVIDIA to deliver enterprise-grade AI built for real business outcomes. Learn how to deploy and customize OCI AI Accelerator Packs with NVIDIA GPUs. Access the webinar for Live Demo Day: Oracle and NVIDIA Accelerate”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection”
?Technical dependency observed: GoogleObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score60
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“Oracle Software Security Assurance (OSSA) is Oracle’s methodology for building security into the design, build, testing, and maintenance of its products.”
“aligned with the ISO/IEC 27001:2022 (formerly known as ISO/IEC 17799:2005) and ISO/IEC 27002:2022 standards and guide all areas of security within Oracle.”
Governance & accountability: vendor-evidenced, not yet independently corroborated.
AI system15% of the score27
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“and NVIDIA Accelerate AI Deployments on OCI See how we’re partnering with NVIDIA to deliver enterprise-grade AI built for real business outcomes. Learn how to deploy and customize OCI AI Accelerator Packs with NVIDIA GPUs. Access the webinar for Live Demo Day: Oracle and NVIDIA Accelerate”
“Choose from managed open source or proprietary LLMs. Fine-tune prebuilt models and augment them with your own enterprise data. Turn intelligence into action with AI agents. Explore generative AI”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“Oracle Software Security Assurance (OSSA) is Oracle’s methodology for building security into the design, build, testing, and maintenance of its products.”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
Change management: not publicly evidenced.
Model10% of the score0
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
Model provider transparency: not publicly evidenced.
Customer data15% of the score72
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“(Swiss-U.S. DPF) (collectively, the “DPF”) as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of Services Personal Information when You and Oracle have agreed by contract that transfers of such information from the EEA, United Kingdom (and Gibraltar), or Switzerland will be transferred”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the score40
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Oracle. 6. Subprocessors To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection”
Security foundation15% of the score77
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“review. 5. Incident Management and data breach notification. Oracle promptly evaluates and responds to incidents that create suspicion of or indicate unauthorized access to or handling of Services Personal Information. If Oracle becomes aware and determines that an incident involving Services Personal Information”
“Integrated Cyber Center The entity responsible for centralized coordination of security incident response, customer trust and security communications matters. Report a security incident”
“security event and security incident response, compliance with data protection laws, contractual obligations and reporting requirements,”
Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
Independent assurance evidence10% of the score59
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“aligned with the ISO/IEC 27001:2022 (formerly known as ISO/IEC 17799:2005) and ISO/IEC 27002:2022 standards and guide all areas of security within Oracle.”
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Independent assurance: vendor-evidenced, not yet independently corroborated.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“Incident Management and breach notification Subprocessors Cross-border data transfers Audit rights Deletion or return of Services Personal Information Notifications to customers and users Services Personal Information is personal information that is provided by You, resides”
“(Swiss-U.S. DPF) (collectively, the “DPF”) as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of Services Personal Information when You and Oracle have agreed by contract that transfers of such information from the EEA, United Kingdom (and Gibraltar), or Switzerland will be transferred”
“Oracle has two primary agreements used for the sale of its products and services: the Cloud Services Agreement (CSA) and the Oracle Master Agreement (OMA).”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 51 → up to 81 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 4 — registry checks and verification ladders, click to view
The Services Privacy Policy provides for EEA/UK/Swiss transfers under the Department of Commerce-approved framework where contractually agreed.
Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry
Policies stated as ALIGNED with ISO/IEC 27001:2022; certification detail lives on the cloud-compliance pages.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry
Sources 14 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
Want to go further?
This scan assesses Oracle at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.
Scan a specific product →This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
