Read AI

read.ai

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
49 / 100D
Procurement decision
Do not approve on current evidence
5 conditions outstanding
  • Vendor discloses an unfavourable answer: Will they train on your data?
  • Vendor discloses an unfavourable answer: Who else can access your data?
  • Training-on-customer-data statements conflict across the privacy page, Terms and Privacy Policy

+2 more

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification Partial

Scanned Oct 5, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

Vendor discloses an unfavourable answer: Will they train on your data?Blocking

Why it matters: With the user's consent to connect a Google account, Read AI may collect Gmail, Calendar, Docs, Drive and Chat content and use it to develop, improve or train personalised AI/ML models.

What to ask for: Resolve this directly with the vendor before proceeding — this is a confirmed disclosure, not a gap to fill in.

Evidence
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“When you create a new account, if you consent to connect your Google account to your Read account, we may, either now or in the future, collect your Google user data via Google’s Workspace APIs that we may use for developing, improving, or training personalized AI and/or ML models, including (i) Google account information (email address and name); (ii) Google Calendar data, including event titles, descriptions, dates/times, and guest lists; (iii) Gmail data, including email messages (subject, body, recipients, senders, and other metadata) and settings;”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“Without limiting the foregoing license, you acknowledge that, subject to the terms and limitations described in our Privacy Policy and any applicable opt-in or opt-out mechanisms, Read AI may use your User Content to train, develop, and improve its artificial intelligence and machine learning technologies (" AI/ML Models ").”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“AI training is opt-in Contributing to model improvement is off by default. You decide - and can change your mind any time.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“As part of your account settings, Read offers a Customer Experience Program that you may opt-in to. This program allows Meeting Information and connected data (email, messages) to be used for the purpose of improving the features of our Service. You may choose to opt-in or opt-out at any time, via your account settings.”
Apparent contradictionPrivacy Policy ↗retrieved Oct 5, 2026
“Improve (consistent with your account settings) our Services, including using information to train and improve our models within our Services. We rely on our legitimate interest to be able to improve and develop our Services.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Demographics: We also use audio and visual information, as well as other information like language, to infer certain demographic characteristics about users, which we use to improve our models and increase the accuracy of their output.”
Vendor publishedRead AI MCP Adoption Surges In Launch Phase ↗retrieved Oct 5, 2026
“With the OpenAI Connector, no data training by default. Your data remains private. This promise is extended to OpenAI, which will not use Read AI data to train its AI models.”
Vendor discloses an unfavourable answer: Who else can access your data?Blocking

Why it matters: Data collected through the Google Workspace integration may be passed to unnamed third-party AI tools; Read AI says it does not permit those tools to train generalised models on it.

What to ask for: Resolve this directly with the vendor before proceeding — this is a confirmed disclosure, not a gap to fill in.

Evidence
“Read AI Users Now Have Direct Access to OpenAI's ChatGPT and Anthropic's Claude—For Free Starting today, Read AI is giving free unlimited access to the world's most powerful large language models for paid customers.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Any user data collected via Google Workspace APIs may be transferred to third party AI tools in connection with the Services. We do not, and do not permit third party AI tools to, use user data collected via Google Workspace APIs to develop, improve, or train generalized/non-personalized AI and/or ML models.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Full audit reports, sub-processors, and DPA available at trust.read.ai”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, and consultants who perform services on our behalf, such as companies that assist us with web hosting, data storage, data analytics, payment processing, fraud prevention, customer service, AI tools, and marketing and advertising.”
Training-on-customer-data statements conflict across the privacy page, Terms and Privacy PolicyBlocking

Why it matters: The privacy page says contributing to model improvement is opt-in and off by default, and the Privacy Policy describes an opt-in Customer Experience Program. But the Terms reserve a broad licence to use User Content to train AI/ML models (subject to the Privacy Policy and opt mechanisms); the Privacy Policy states that information is used to train and improve models 'consistent with your account settings' under legitimate interest rather than consent; inferred demographics derived from meeting audio and video are used to improve models with no opt-in mentioned; and connected Google Workspace content may be used to train personalised models. For the user-initiated OpenAI connector, Read AI states OpenAI will not train on Read AI data.

What to ask for: Confirm in writing, for Workspace/enterprise accounts, which data categories (meeting audio/video, transcripts, summaries, inferred demographics, connected Gmail/Drive/Chat content) are used to train or improve any Read AI model when the Customer Experience Program is NOT enabled, the legal basis relied on for each, and whether the DPA excludes customer data from model training.

Evidence
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“When you create a new account, if you consent to connect your Google account to your Read account, we may, either now or in the future, collect your Google user data via Google’s Workspace APIs that we may use for developing, improving, or training personalized AI and/or ML models, including (i) Google account information (email address and name); (ii) Google Calendar data, including event titles, descriptions, dates/times, and guest lists; (iii) Gmail data, including email messages (subject, body, recipients, senders, and other metadata) and settings;”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“Without limiting the foregoing license, you acknowledge that, subject to the terms and limitations described in our Privacy Policy and any applicable opt-in or opt-out mechanisms, Read AI may use your User Content to train, develop, and improve its artificial intelligence and machine learning technologies (" AI/ML Models ").”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“AI training is opt-in Contributing to model improvement is off by default. You decide - and can change your mind any time.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“As part of your account settings, Read offers a Customer Experience Program that you may opt-in to. This program allows Meeting Information and connected data (email, messages) to be used for the purpose of improving the features of our Service. You may choose to opt-in or opt-out at any time, via your account settings.”
Apparent contradictionPrivacy Policy ↗retrieved Oct 5, 2026
“Improve (consistent with your account settings) our Services, including using information to train and improve our models within our Services. We rely on our legitimate interest to be able to improve and develop our Services.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Demographics: We also use audio and visual information, as well as other information like language, to infer certain demographic characteristics about users, which we use to improve our models and increase the accuracy of their output.”
Vendor publishedRead AI MCP Adoption Surges In Launch Phase ↗retrieved Oct 5, 2026
“With the OpenAI Connector, no data training by default. Your data remains private. This promise is extended to OpenAI, which will not use Read AI data to train its AI models.”
No formal subprocessor register disclosedCondition

Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.

What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.

Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We store your audio and video information, including information derived therefrom, in accordance with our internal policies, but in no case for longer than 2 years. For paid accounts, we will store your data until you (i) stop paying, or (ii) request that we delete some or all of your data.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Meeting participants can opt out of Read at any time. The meeting data is immediately and permanently deleted.”

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

✗Will they train on your data?Concern / gap

With the user's consent to connect a Google account, Read AI may collect Gmail, Calendar, Docs, Drive and Chat content and use it to develop, improve or train personalised AI/ML models.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“When you create a new account, if you consent to connect your Google account to your Read account, we may, either now or in the future, collect your Google user data via Google’s Workspace APIs that we may use for developing, improving, or training personalized AI and/or ML models, including (i) Google account information (email address and name); (ii) Google Calendar data, including event titles, descriptions, dates/times, and guest lists; (iii) Gmail data, including email messages (subject, body, recipients, senders, and other metadata) and settings;”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“Without limiting the foregoing license, you acknowledge that, subject to the terms and limitations described in our Privacy Policy and any applicable opt-in or opt-out mechanisms, Read AI may use your User Content to train, develop, and improve its artificial intelligence and machine learning technologies (" AI/ML Models ").”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“AI training is opt-in Contributing to model improvement is off by default. You decide - and can change your mind any time.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“As part of your account settings, Read offers a Customer Experience Program that you may opt-in to. This program allows Meeting Information and connected data (email, messages) to be used for the purpose of improving the features of our Service. You may choose to opt-in or opt-out at any time, via your account settings.”
Apparent contradictionPrivacy Policy ↗retrieved Oct 5, 2026
“Improve (consistent with your account settings) our Services, including using information to train and improve our models within our Services. We rely on our legitimate interest to be able to improve and develop our Services.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Demographics: We also use audio and visual information, as well as other information like language, to infer certain demographic characteristics about users, which we use to improve our models and increase the accuracy of their output.”
Vendor publishedRead AI MCP Adoption Surges In Launch Phase ↗retrieved Oct 5, 2026
“With the OpenAI Connector, no data training by default. Your data remains private. This promise is extended to OpenAI, which will not use Read AI data to train its AI models.”
!How long do they keep your data?Ask the vendor

Audio and video information and anything derived from it is kept no longer than two years; paid-account data is otherwise retained until the customer stops paying or requests deletion. No retention period is stated for transcripts or summaries as such.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We store your audio and video information, including information derived therefrom, in accordance with our internal policies, but in no case for longer than 2 years. For paid accounts, we will store your data until you (i) stop paying, or (ii) request that we delete some or all of your data.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Meeting participants can opt out of Read at any time. The meeting data is immediately and permanently deleted.”
✗Who else can access your data?Concern / gap

Data collected through the Google Workspace integration may be passed to unnamed third-party AI tools; Read AI says it does not permit those tools to train generalised models on it.

Requires written confirmation — see Before you sign ↓

Evidence
“Read AI Users Now Have Direct Access to OpenAI's ChatGPT and Anthropic's Claude—For Free Starting today, Read AI is giving free unlimited access to the world's most powerful large language models for paid customers.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Any user data collected via Google Workspace APIs may be transferred to third party AI tools in connection with the Services. We do not, and do not permit third party AI tools to, use user data collected via Google Workspace APIs to develop, improve, or train generalized/non-personalized AI and/or ML models.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Full audit reports, sub-processors, and DPA available at trust.read.ai”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, and consultants who perform services on our behalf, such as companies that assist us with web hosting, data storage, data analytics, payment processing, fraud prevention, customer service, AI tools, and marketing and advertising.”
!Where is your data processed?Ask the vendor

Users agree that their information may be processed, transferred and stored in the United States and unspecified other countries.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“In order for us to provide our Services, you agree that we may process, transfer, and store information about you in the United States and other countries, where you may not have the same rights and protections as you do under local law.”
“Read AI Brings International Data Processing and Storage To Global Customers Multi-region deployments are now available to hundreds of thousands of international companies, setting a new compliance standard for AI assistants and notetakers.”
✓What happens in a security incident?Clear

Read AI publishes a security.txt with dedicated vulnerability and security contact addresses, pointing to a policy at its Trust Center, valid to August 2027.

Evidence
Vendor publishedread.ai ↗retrieved Oct 5, 2026
“Contact: mailto:[email protected] Contact: https://trust.read.ai Contact: mailto:[email protected] Expires: 2027-08-18T00:00:00.000Z Policy: https://trust.read.ai”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“A third-party auditor has verified that our security controls - access management, encryption, monitoring, and incident response - work as intended.”

Email to send the vendor11 items to confirm in writing

Subject: Supplier assessment: written confirmation requested
Hello Read AI team,

We are assessing Read AI as part of our supplier review. Before we proceed, please confirm the following in writing:

1. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan.
2. Please provide your current, dated subprocessor list and explain how you notify customers of changes.
3. Please address the following: Training-on-customer-data statements conflict across the privacy page, Terms and Privacy Policy.
4. How long do you retain our data, in days, for each type (inputs, outputs, logs and backups), and how is it deleted?
5. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose?
6. Provide the current SOC 2 Type II report (auditor, period, any exceptions) and confirm whether AI/ML processing components and the Agentic Features are within the audited system boundary.
7. Share model evaluation documentation: transcription accuracy by language, bias and fairness testing for Read Score and demographic inference, pre-release testing and guardrails for Agentic Features, and how customers are notified of material model or feature changes.
8. Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
9. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
10. Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
11. Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date.

Thank you,
Audit evidence: a verified report maps its findings to ISO/IEC 27001 supplier controls, ISO/IEC 42001 third-party controls and APRA CPS 230. See verified reports →

Key findingsclick a row for the evidence

✓Independent security assurance is in place and vulnerability reporting is publishedStrong

Read AI states it undergoes an annual SOC 2 Type II audit covering access management, encryption, monitoring and incident response, offers a HIPAA BAA and a GDPR Article 28 DPA with SCCs, self-certifies to the EU-U.S. Data Privacy Framework, and publishes an RFC 9116 security.txt with dedicated vulnerability and security contacts. Audit reports, the sub-processor list and the DPA are said to be available through its Trust Center.

A recurring third-party audit with incident response in scope, plus contractual instruments (DPA, BAA) and a published disclosure channel, gives a buyer verifiable artefacts to request rather than relying on marketing statements. All of these remain vendor-stated in the collected pages: the auditor is not named and the report and sub-processor list sit behind the Trust Center.

Question for vendor: Provide the current SOC 2 Type II report (auditor, period, any exceptions) and confirm whether AI/ML processing components and the Agentic Features are within the audited system boundary.

Evidence
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Read AI is independently audited against SOC 2 Type II standards every year.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Read AI meets HIPAA's technical safeguard requirements for protected health information. Healthcare and human services teams can request a Business Associates Agreement (BAA) to formalize our shared compliance obligations before getting started.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“As described in our Frameworks certification, Read AI has certified that it adheres to the Frameworks Principles with regard to the processing of personal information received from the EEA, Switzerland, and the UK in reliance on the Frameworks.”
Vendor publishedread.ai ↗retrieved Oct 5, 2026
“Contact: mailto:[email protected] Contact: https://trust.read.ai Contact: mailto:[email protected] Expires: 2027-08-18T00:00:00.000Z Policy: https://trust.read.ai”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“A third-party auditor has verified that our security controls - access management, encryption, monitoring, and incident response - work as intended.”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“To the extent you are an entity or enterprise using our Services, the terms of our Data Processing Addendum will apply.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“For eligible Workspace customers in the EU and EEA, Read AI acts as a data processor under GDPR Article 28 and offers a Data Processing Agreement. Where applicable, Read relies on recognized safeguards for international data transfers, including the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.”
✗Training-on-customer-data statements conflict across the privacy page, Terms and Privacy PolicyGap

The privacy page says contributing to model improvement is opt-in and off by default, and the Privacy Policy describes an opt-in Customer Experience Program. But the Terms reserve a broad licence to use User Content to train AI/ML models (subject to the Privacy Policy and opt mechanisms); the Privacy Policy states that information is used to train and improve models 'consistent with your account settings' under legitimate interest rather than consent; inferred demographics derived from meeting audio and video are used to improve models with no opt-in mentioned; and connected Google Workspace content may be used to train personalised models. For the user-initiated OpenAI connector, Read AI states OpenAI will not train on Read AI data.

A buyer cannot tell from public materials whether meeting recordings, transcripts and connected mailbox content are excluded from model training unless they opt in, or are used by default under legitimate interest with only the Customer Experience Program being opt-in. The distinction determines whether the product can be approved for confidential meetings without a contractual carve-out.

Question for vendor: Confirm in writing, for Workspace/enterprise accounts, which data categories (meeting audio/video, transcripts, summaries, inferred demographics, connected Gmail/Drive/Chat content) are used to train or improve any Read AI model when the Customer Experience Program is NOT enabled, the legal basis relied on for each, and whether the DPA excludes customer data from model training.

Evidence
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“When you create a new account, if you consent to connect your Google account to your Read account, we may, either now or in the future, collect your Google user data via Google’s Workspace APIs that we may use for developing, improving, or training personalized AI and/or ML models, including (i) Google account information (email address and name); (ii) Google Calendar data, including event titles, descriptions, dates/times, and guest lists; (iii) Gmail data, including email messages (subject, body, recipients, senders, and other metadata) and settings;”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“Without limiting the foregoing license, you acknowledge that, subject to the terms and limitations described in our Privacy Policy and any applicable opt-in or opt-out mechanisms, Read AI may use your User Content to train, develop, and improve its artificial intelligence and machine learning technologies (" AI/ML Models ").”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“AI training is opt-in Contributing to model improvement is off by default. You decide - and can change your mind any time.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“As part of your account settings, Read offers a Customer Experience Program that you may opt-in to. This program allows Meeting Information and connected data (email, messages) to be used for the purpose of improving the features of our Service. You may choose to opt-in or opt-out at any time, via your account settings.”
Apparent contradictionPrivacy Policy ↗retrieved Oct 5, 2026
“Improve (consistent with your account settings) our Services, including using information to train and improve our models within our Services. We rely on our legitimate interest to be able to improve and develop our Services.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Demographics: We also use audio and visual information, as well as other information like language, to infer certain demographic characteristics about users, which we use to improve our models and increase the accuracy of their output.”
Vendor publishedRead AI MCP Adoption Surges In Launch Phase ↗retrieved Oct 5, 2026
“With the OpenAI Connector, no data training by default. Your data remains private. This promise is extended to OpenAI, which will not use Read AI data to train its AI models.”
!Model providers for core processing and the sub-processor list are not publicGap

OpenAI and Anthropic are named only in the context of user-facing ChatGPT/Claude access and the MCP connector. The Privacy Policy discloses that personal information goes to vendors by category, including unnamed 'AI tools', and that Google Workspace data may be transferred to third-party AI tools. Which models or providers perform transcription, summarisation, Read Score inference and Agentic actions by default is not stated. The sub-processor list exists but is behind the Trust Center. subprocessors_and_supply_chain and model_provider_transparency are therefore assessed partial, not not_evidenced: the vendor discloses that a list exists and names two providers, but the request-path providers for core processing are not identified in public pages.

Without the sub-processor list and the model providers in the default processing path, a buyer cannot assess onward-transfer risk, provider-side retention, or whether third-party model terms permit training on inputs.

Question for vendor: Provide the current sub-processor list and identify which AI/model providers process meeting audio, transcripts and summaries by default (outside user-initiated ChatGPT/Claude connectors), the regions where they process it, and the contractual training and retention terms in place with each.

Evidence
Vendor publishedRead AI MCP Adoption Surges In Launch Phase ↗retrieved Oct 5, 2026
“Read AI connects your complete meeting history to AI platforms including ChatGPT , Claude , and Claude Code and other MCP-compatible clients like Microsoft Copilot Studio.”
“Read AI Users Now Have Direct Access to OpenAI's ChatGPT and Anthropic's Claude—For Free Starting today, Read AI is giving free unlimited access to the world's most powerful large language models for paid customers.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Any user data collected via Google Workspace APIs may be transferred to third party AI tools in connection with the Services. We do not, and do not permit third party AI tools to, use user data collected via Google Workspace APIs to develop, improve, or train generalized/non-personalized AI and/or ML models.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Full audit reports, sub-processors, and DPA available at trust.read.ai”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, and consultants who perform services on our behalf, such as companies that assist us with web hosting, data storage, data analytics, payment processing, fraud prevention, customer service, AI tools, and marketing and advertising.”
!No published testing or evaluation for affect scoring, demographic inference or agentic actionsGap

Read AI infers participant sentiment and engagement (Read Score) from facial and verbal cues, infers demographic characteristics, and offers Agentic Features that act without per-action review. None of the collected documents describe accuracy, bias or safety testing for these capabilities; the Terms instead disclaim output accuracy and state the vendor does not guarantee Agentic Features will stay within the authorised scope. testing_and_evaluation is marked not_evidenced rather than not_applicable: these are hosted models making inferences about identifiable people and taking actions on their behalf, so evaluation evidence can exist and other vendors publish it. No domain is marked not_applicable for this scan. governance_and_accountability and change_management are partial: user-side controls for Agentic Features and notice mechanisms for Terms and policy changes are published, but there is no AI governance framework, accountable owner, or model-change notification commitment.

Sentiment, engagement and demographic inference over employees and external participants carries fairness and workplace-monitoring risk, and unsupervised agentic actions carry operational risk; without evaluation evidence the buyer bears that risk under a $100 liability cap and broad disclaimers.

Question for vendor: Share model evaluation documentation: transcription accuracy by language, bias and fairness testing for Read Score and demographic inference, pre-release testing and guardrails for Agentic Features, and how customers are notified of material model or feature changes.

Evidence
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“As used in these Terms, " Agentic Features " means any functionality within the Services that, when enabled by you, permits Read AI's artificial intelligence to make limited decisions and take certain actions on your behalf, including but not limited to scheduling, sending communications, or interacting with Third-Party Services.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“To provide our Read Score feature which involves analyzing facial and verbal elements of all meeting attendees to assess how people are reacting (positively, neutrally or negatively) as well as their level of involvement and interest to provide an overall meeting score. For users in the EU and UK, the Read Score does not include any use of meeting video or facial elements to calculate a score.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Demographics: We also use audio and visual information, as well as other information like language, to infer certain demographic characteristics about users, which we use to improve our models and increase the accuracy of their output.”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“Agentic Features must be affirmatively enabled by you before Read AI's artificial intelligence may take any action on your behalf. Read AI will not initiate any autonomous action through Agentic Features unless and until you activate the applicable Agentic Feature through your account settings or another mechanism made available by Read AI.”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“Read AI will use commercially reasonable efforts to act only within the scope authorized by your configuration and settings; however, Read AI does not guarantee that Agentic Features will operate exclusively within your intended parameters.”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“We may make changes to these Terms from time to time. If we make changes, we will provide you with notice of such changes, such as by sending an email, providing a notice through our Services, or updating the date at the top of these Terms. Unless we say otherwise in our notice, the amended Terms will be effective immediately, and your continued use of our Services after we provide such notice will confirm your acceptance of the changes.”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“Read AI does not represent or warrant that any AI Outputs are accurate, complete, reliable, current, error-free, or fit for any particular purpose. AI Outputs may contain errors, omissions, inaccuracies, or outdated information, and Read AI shall have no obligation to update or correct any AI Outputs.”
!Retention and location: hard cap on audio/video, open-ended for other data, US default with multi-region optionGap

Audio and video (and derived data) are retained no longer than two years; other paid-account data is kept until the customer stops paying or requests deletion, with no stated period for transcripts or summaries. Participants who opt out have meeting data deleted immediately. The Terms place processing in the United States and unspecified other countries; a February 2026 announcement offers multi-region deployments, but eligibility and regions are not described in the collected pages.

Buyers with residency obligations need the default region and the terms of the multi-region option, and need a retention schedule for transcripts and summaries, which are the artefacts most likely to contain confidential content.

Question for vendor: Confirm the retention period for transcripts, summaries and derived analytics for Workspace accounts, the default processing and storage region, which plans can select a multi-region deployment, and which regions are available.

Evidence
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We store your audio and video information, including information derived therefrom, in accordance with our internal policies, but in no case for longer than 2 years. For paid accounts, we will store your data until you (i) stop paying, or (ii) request that we delete some or all of your data.”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“In order for us to provide our Services, you agree that we may process, transfer, and store information about you in the United States and other countries, where you may not have the same rights and protections as you do under local law.”
“Read AI Brings International Data Processing and Storage To Global Customers Multi-region deployments are now available to hundreds of thousands of international companies, setting a new compliance standard for AI assistants and notetakers.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Meeting participants can opt out of Read at any time. The meeting data is immediately and permanently deleted.”
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
“Read AI Users Now Have Direct Access to OpenAI's ChatGPT and Anthropic's Claude—For Free Starting today, Read AI is giving free unlimited access to the world's most powerful large language models for paid customers.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Any user data collected via Google Workspace APIs may be transferred to third party AI tools in connection with the Services. We do not, and do not permit third party AI tools to, use user data collected via Google Workspace APIs to develop, improve, or train generalized/non-personalized AI and/or ML models.”
Vendor publishedRead AI MCP Adoption Surges In Launch Phase ↗retrieved Oct 5, 2026
“With the OpenAI Connector, no data training by default. Your data remains private. This promise is extended to OpenAI, which will not use Read AI data to train its AI models.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Full audit reports, sub-processors, and DPA available at trust.read.ai”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, and consultants who perform services on our behalf, such as companies that assist us with web hosting, data storage, data analytics, payment processing, fraud prevention, customer service, AI tools, and marketing and advertising.”
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
“Read AI Users Now Have Direct Access to OpenAI's ChatGPT and Anthropic's Claude—For Free Starting today, Read AI is giving free unlimited access to the world's most powerful large language models for paid customers.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Any user data collected via Google Workspace APIs may be transferred to third party AI tools in connection with the Services. We do not, and do not permit third party AI tools to, use user data collected via Google Workspace APIs to develop, improve, or train generalized/non-personalized AI and/or ML models.”
Vendor publishedRead AI MCP Adoption Surges In Launch Phase ↗retrieved Oct 5, 2026
“With the OpenAI Connector, no data training by default. Your data remains private. This promise is extended to OpenAI, which will not use Read AI data to train its AI models.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Full audit reports, sub-processors, and DPA available at trust.read.ai”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, and consultants who perform services on our behalf, such as companies that assist us with web hosting, data storage, data analytics, payment processing, fraud prevention, customer service, AI tools, and marketing and advertising.”
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
“Read AI Users Now Have Direct Access to OpenAI's ChatGPT and Anthropic's Claude—For Free Starting today, Read AI is giving free unlimited access to the world's most powerful large language models for paid customers.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Any user data collected via Google Workspace APIs may be transferred to third party AI tools in connection with the Services. We do not, and do not permit third party AI tools to, use user data collected via Google Workspace APIs to develop, improve, or train generalized/non-personalized AI and/or ML models.”
Vendor publishedRead AI MCP Adoption Surges In Launch Phase ↗retrieved Oct 5, 2026
“With the OpenAI Connector, no data training by default. Your data remains private. This promise is extended to OpenAI, which will not use Read AI data to train its AI models.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Full audit reports, sub-processors, and DPA available at trust.read.ai”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, and consultants who perform services on our behalf, such as companies that assist us with web hosting, data storage, data analytics, payment processing, fraud prevention, customer service, AI tools, and marketing and advertising.”
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
“Read AI Users Now Have Direct Access to OpenAI's ChatGPT and Anthropic's Claude—For Free Starting today, Read AI is giving free unlimited access to the world's most powerful large language models for paid customers.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Any user data collected via Google Workspace APIs may be transferred to third party AI tools in connection with the Services. We do not, and do not permit third party AI tools to, use user data collected via Google Workspace APIs to develop, improve, or train generalized/non-personalized AI and/or ML models.”
Vendor publishedRead AI MCP Adoption Surges In Launch Phase ↗retrieved Oct 5, 2026
“With the OpenAI Connector, no data training by default. Your data remains private. This promise is extended to OpenAI, which will not use Read AI data to train its AI models.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Full audit reports, sub-processors, and DPA available at trust.read.ai”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, and consultants who perform services on our behalf, such as companies that assist us with web hosting, data storage, data analytics, payment processing, fraud prevention, customer service, AI tools, and marketing and advertising.”

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score40
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“Agentic Features must be affirmatively enabled by you before Read AI's artificial intelligence may take any action on your behalf. Read AI will not initiate any autonomous action through Agentic Features unless and until you activate the applicable Agentic Feature through your account settings or another mechanism made available by Read AI.”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“Read AI will use commercially reasonable efforts to act only within the scope authorized by your configuration and settings; however, Read AI does not guarantee that Agentic Features will operate exclusively within your intended parameters.”
AI system15% of the score33
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“As used in these Terms, " Agentic Features " means any functionality within the Services that, when enabled by you, permits Read AI's artificial intelligence to make limited decisions and take certain actions on your behalf, including but not limited to scheduling, sending communications, or interacting with Third-Party Services.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“To provide our Read Score feature which involves analyzing facial and verbal elements of all meeting attendees to assess how people are reacting (positively, neutrally or negatively) as well as their level of involvement and interest to provide an overall meeting score. For users in the EU and UK, the Read Score does not include any use of meeting video or facial elements to calculate a score.”
Vendor publishedRead AI MCP Adoption Surges In Launch Phase ↗retrieved Oct 5, 2026
“Read AI connects your complete meeting history to AI platforms including ChatGPT , Claude , and Claude Code and other MCP-compatible clients like Microsoft Copilot Studio.”
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Not Evidenced
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“We may make changes to these Terms from time to time. If we make changes, we will provide you with notice of such changes, such as by sending an email, providing a notice through our Services, or updating the date at the top of these Terms. Unless we say otherwise in our notice, the amended Terms will be effective immediately, and your continued use of our Services after we provide such notice will confirm your acceptance of the changes.”

AI system description: vendor-evidenced, not yet independently corroborated.

Testing & evaluation: not publicly evidenced.

Model10% of the score40
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
“Read AI Users Now Have Direct Access to OpenAI's ChatGPT and Anthropic's Claude—For Free Starting today, Read AI is giving free unlimited access to the world's most powerful large language models for paid customers.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Any user data collected via Google Workspace APIs may be transferred to third party AI tools in connection with the Services. We do not, and do not permit third party AI tools to, use user data collected via Google Workspace APIs to develop, improve, or train generalized/non-personalized AI and/or ML models.”
Customer data15% of the score77
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“When you create a new account, if you consent to connect your Google account to your Read account, we may, either now or in the future, collect your Google user data via Google’s Workspace APIs that we may use for developing, improving, or training personalized AI and/or ML models, including (i) Google account information (email address and name); (ii) Google Calendar data, including event titles, descriptions, dates/times, and guest lists; (iii) Gmail data, including email messages (subject, body, recipients, senders, and other metadata) and settings;”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“Without limiting the foregoing license, you acknowledge that, subject to the terms and limitations described in our Privacy Policy and any applicable opt-in or opt-out mechanisms, Read AI may use your User Content to train, develop, and improve its artificial intelligence and machine learning technologies (" AI/ML Models ").”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“AI training is opt-in Contributing to model improvement is off by default. You decide - and can change your mind any time.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“As part of your account settings, Read offers a Customer Experience Program that you may opt-in to. This program allows Meeting Information and connected data (email, messages) to be used for the purpose of improving the features of our Service. You may choose to opt-in or opt-out at any time, via your account settings.”
Apparent contradictionPrivacy Policy ↗retrieved Oct 5, 2026
“Improve (consistent with your account settings) our Services, including using information to train and improve our models within our Services. We rely on our legitimate interest to be able to improve and develop our Services.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“Demographics: We also use audio and visual information, as well as other information like language, to infer certain demographic characteristics about users, which we use to improve our models and increase the accuracy of their output.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We store your audio and video information, including information derived therefrom, in accordance with our internal policies, but in no case for longer than 2 years. For paid accounts, we will store your data until you (i) stop paying, or (ii) request that we delete some or all of your data.”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“In order for us to provide our Services, you agree that we may process, transfer, and store information about you in the United States and other countries, where you may not have the same rights and protections as you do under local law.”
“Read AI Brings International Data Processing and Storage To Global Customers Multi-region deployments are now available to hundreds of thousands of international companies, setting a new compliance standard for AI assistants and notetakers.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Meeting participants can opt out of Read at any time. The meeting data is immediately and permanently deleted.”

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the score40
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedRead AI MCP Adoption Surges In Launch Phase ↗retrieved Oct 5, 2026
“With the OpenAI Connector, no data training by default. Your data remains private. This promise is extended to OpenAI, which will not use Read AI data to train its AI models.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Full audit reports, sub-processors, and DPA available at trust.read.ai”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, and consultants who perform services on our behalf, such as companies that assist us with web hosting, data storage, data analytics, payment processing, fraud prevention, customer service, AI tools, and marketing and advertising.”
Security foundation15% of the score45
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedread.ai ↗retrieved Oct 5, 2026
“Contact: mailto:[email protected] Contact: https://trust.read.ai Contact: mailto:[email protected] Expires: 2027-08-18T00:00:00.000Z Policy: https://trust.read.ai”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“A third-party auditor has verified that our security controls - access management, encryption, monitoring, and incident response - work as intended.”
Independent assurance evidence10% of the score55
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Read AI is independently audited against SOC 2 Type II standards every year.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“Read AI meets HIPAA's technical safeguard requirements for protected health information. Healthcare and human services teams can request a Business Associates Agreement (BAA) to formalize our shared compliance obligations before getting started.”
Vendor publishedPrivacy Policy ↗retrieved Oct 5, 2026
“As described in our Frameworks certification, Read AI has certified that it adheres to the Frameworks Principles with regard to the processing of personal information received from the EEA, Switzerland, and the UK in reliance on the Frameworks.”

Read from the registry record above — cited, not reproduced.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“To the extent you are an entity or enterprise using our Services, the terms of our Data Processing Addendum will apply.”
Vendor publishedTerms of Service ↗retrieved Oct 5, 2026
“Read AI does not represent or warrant that any AI Outputs are accurate, complete, reliable, current, error-free, or fit for any particular purpose. AI Outputs may contain errors, omissions, inaccuracies, or outdated information, and Read AI shall have no obligation to update or correct any AI Outputs.”
Vendor publishedPrivacy First Meeting Measurement | Read ↗retrieved Oct 5, 2026
“For eligible Workspace customers in the EU and EEA, Read AI acts as a data processor under GDPR Article 28 and offers a Data Processing Agreement. Where applicable, Read relies on recognized safeguards for international data transfers, including the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.”

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Complete the Governance & accountability disclosureOrganisation 40 → 60
+3Publish Testing & evaluation evidenceAI System 33 → 53
+3Complete the Vulnerability & incident handling disclosureSecurity Foundation 45 → 65
+3Verify EU-U.S. Data Privacy Framework scope covers this assessmentIndependent Assurance 55 → 78
+2Have Customer data treatment disclosures independently corroboratedData 77 → 92

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 49 → up to 76 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSRead AI, Inc.Read AI, Inc.Read AI (meeting notes, Ask Read, Digital Twin)Read AI (meeting notes, A…Agentic FeaturesAgentic FeaturesRead AI MCP Connector (ChatGPT, Claude, Copilot Studio)Read AI MCP Connector (Ch…OpenAIOpenAIAnthropicAnthropic
View as list
Read AI, Inc. Uses AI Service OpenAI
Read AI, Inc. Uses AI Service Anthropic

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 5 — registry checks and verification ladders, click to view
SOC 2 Type IIVendor claimed only

Stated as an annual independent audit covering access management, encryption, monitoring and incident response. Auditor, report period and system boundary not stated publicly; report said to be available via trust.read.ai.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

HIPAAVendor claimed only

Self-stated conformance to HIPAA technical safeguard requirements with a BAA available on request; not described as a third-party certification or attestation.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF)Vendor claimed only

Self-certification to the DPF Principles for EEA, UK and Swiss personal data; the Data Privacy Framework list was not checked within this scan.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Oct 5, 2026: Verified on the registry

Sources 12 — click to view
Read AI MCP Adoption Surges In Launch Phase
AI Documentation · Vendor · retrieved Oct 5, 2026
https://read.ai/.well-known/security.txt
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Read AI Trust Center
Subprocessor List · Vendor · retrieved Oct 5, 2026
Privacy First Meeting Measurement | Read
Privacy Notice · Vendor · retrieved Oct 5, 2026
Vanta
Certification Or Compliance Page · Vendor · retrieved Oct 5, 2026
Terms of Service
Terms · Vendor · retrieved Oct 5, 2026
Read AI Trust Center
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Account & Privacy Center | Manage Your Data with Read AI
Privacy Notice · Vendor · retrieved Oct 5, 2026
Vanta
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Privacy Policy
Privacy Notice · Vendor · retrieved Oct 5, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Oct 5, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Read AI at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.

Monitor for changes

Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.