Glean
glean.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No clear commitment that your data will not train their models
See Before you sign, with what to ask for ↓
Scanned Oct 5, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.
What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.
“Glean does not have, derive, or exercise any rights or benefits regarding Customer Personal Data. Glean will not sell any Customer Personal Data, as the term “sell” is defined in the CCPA. In addition, Glean will not collect, share, retain, or use any Customer Personal Data except as necessary to perform the Service for Customer and only within the direct business relationship with Customer.”
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
!Will they train on your data?Ask the vendor
The DPA states Glean derives no rights or benefits from customer personal data, will not sell it, and will not collect, share, retain or use it except as necessary to perform the Service. It does not expressly address model training or fine-tuning.
Requires written confirmation — see Before you sign ↓
“Glean does not have, derive, or exercise any rights or benefits regarding Customer Personal Data. Glean will not sell any Customer Personal Data, as the term “sell” is defined in the CCPA. In addition, Glean will not collect, share, retain, or use any Customer Personal Data except as necessary to perform the Service for Customer and only within the direct business relationship with Customer.”
✓How long do they keep your data?Clear
Under the DPA, Glean mirrors the retention period the customer has set in its own connected applications, except that metadata logs containing personal data are retained for up to 30 days.
“Data importer mirrors the data retention period that data exporter has set as a policy in their respective applications, except for data exporter’s meta-data logs containing any personal data that are retained for up to thirty (30) days.”
“Glean will delete Customer Personal Data following the termination of the Agreement, unless such Customer Personal Data is required to be maintained by Data Protection Laws, in which case it shall be held in accordance with the terms of this DPA.”
✓Who else can access your data?Clear
Glean's public subprocessor list names Anthropic, Baseten, Fireworks.ai, Groq, Modal Labs, OpenAI and Snowflake as LLM providers, all located in the United States.
“Anthropic PBC LLM Provider United States Baseten Labs, Inc. LLM Provider United States Fireworks.ai, Inc. LLM Provider United States Groq, Inc. LLM Provider United States Modal Labs, Inc. LLM Provider United States OpenAI OpCo, LLC LLM Provider United States Snowflake, Inc. LLM Provider United States”
“The Subprocessors used will depend on (a) whether the Data exporter or the Data importer hosts the data, and (b) whether or not the Data exporter uses its own AI large language model.”
“Palo Alto Networks, Inc. AI security provider (Prisma AI Runtime Security) United States”
“Brave Software, Inc. Search United States Deepgram, Inc. Speech-to-text transcription United States** Exa Labs, Inc. Web crawling and rendering United States”
!Where is your data processed?Ask the vendor
AWS, Google and Microsoft are listed as cloud service / LLM providers located in the United States by default, with a footnote that customers may select a different cloud service provider and location.
Confirm in writing: Ask the vendor to state this in writing before signing.
“*Customers have discretion to select a different Cloud Service Provider and location.”
“Glean delivers an open platform with extensible connectors, APIs, and configuration options, including Customer-controlled hosting choices and support for multiple third-party large language models, operated in accordance with Glean’s security, privacy, and compliance commitments.”
“Glean Search Technologies India Private Limited Remote access for support, security and debugging India”
✓What happens in a security incident?Clear
The DPA commits Glean to notify the customer of a personal data breach without undue delay and no later than 72 hours after becoming aware of and investigating it, to identify the cause and to remediate it where within Glean's control.
“Glean shall notify Customer without undue delay, but in no event more than seventy-two (72) hours after becoming aware of and investigating any Personal Data Breach, and Glean will : (i) take reasonable steps to identify the cause of such Personal Data Breach; and (ii) take the steps necessary and reasonable to remediate the cause of such Personal Data Breach to the extent such remediation is within Glean's reasonable control.”
Email to send the vendor6 items to confirm in writing
Hello Glean team, We are assessing Glean as part of our supplier review. Before we proceed, please confirm the following in writing: 1. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan. 2. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose? 3. Please provide the ISO/IEC 27001 and ISO/IEC 42001 certificates (issuer, scope statement, expiry) and the current SOC 2 Type II report under NDA. 4. Which LLM providers and models are used by default for Assistant, Agents and the AI Gateway in our configuration, can we restrict the set, and do all providers operate under zero-data-retention or equivalent terms? 5. Describe your AI evaluation and red-teaming programme, and how customers are notified before default models, model versions or agent capabilities change. 6. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data. A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date. Thank you,
Key findingsclick a row for the evidence
✓Broad certification set including ISO/IEC 42001, but vendor-claimed onlyStrong
Glean publicly claims SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001:2023, HIPAA alignment, TX-RAMP Level 2 and EU-U.S. DPF participation, and its DPA contractually commits to at least annual independent SOC 2-standard audits with the report available on request. None of these is corroborated by an independent source within this scan, and no certificate issuer, scope or validity date is published on the pages collected.
ISO/IEC 42001 is still uncommon among AI vendors and signals a managed AI governance system; the contractual audit commitment means the buyer can obtain the SOC 2 report rather than relying on a badge. Until the certificates are checked against a registry, they remain vendor statements.
Question for vendor: Please provide the ISO/IEC 27001 and ISO/IEC 42001 certificates (issuer, scope statement, expiry) and the current SOC 2 Type II report under NDA.
“Glean is SOC 2 Type II certified, the most comprehensive attestation that our systems are designed and independently audited to keep customers’ sensitive data secure, available, and confidential.”
“Glean is certified to ISO/IEC 27001, the leading global standard for information security management, ensuring robust, independently validated controls for risk assessment, mitigation, and compliance.”
“Glean is certified to ISO/IEC 42001:2023, the leading international standard for AI management systems, demonstrating our commitment to responsible, well‑governed AI with rigorous risk assessment, mitigation, and oversight.”
“HIPAA compliant Customers' sensitive health information is maintained and secured in accordance with the Health Insurance Portability and Accountability Act (HIPAA) of 1996.”
“Enterprise security and compliance ISO 42001 HIPAA TX-RAMP Level 2 SOC 2 Type II ISO 27001 GDPR”
“Glean undertakes to perform regular audits to verify its technical and organizational security measures. Such audits will be conducted: (i) by a qualified independent third party; (ii) at least annually; (iii) in accordance with SOC 2 standards or substantially equivalent standards; and (iv) will result in an audit report (“Report”).”
“Glean has certified to the Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework (DPF) Principles, the UK Extension to the EU–U.S. Data Privacy Framework, and the Swiss–U.S. Data Privacy Framework, and is committed to all relevant framework Principles.”
!No explicit statement on training with customer data in the collected documentsGap
None of the nine documents collected states whether customer content, prompts or outputs are used to train or fine-tune Glean's or third-party models. The DPA's purpose-limitation clause (use only as necessary to perform the Service, no rights or benefits derived) is the closest contractual language but does not name training. The legal page lists an 'AI Addendum' and a 'Limited Retention Addendum' that likely address this but were not collected. Because the central buyer question is unanswered, customer_data_treatment is marked partial despite solid retention and erasure terms; no domain was marked not_evidenced or not_applicable.
A buyer cannot rely on silence. The absence is most likely a collection gap rather than a vendor omission, but it must be closed by reading the AI Addendum before the product is cleared on data training.
Question for vendor: Confirm in writing (ideally by reference to the AI Addendum) whether any customer data, prompts or outputs are used to train, fine-tune or evaluate models by Glean or any LLM provider, and what retention the LLM providers apply to prompts.
“Glean does not have, derive, or exercise any rights or benefits regarding Customer Personal Data. Glean will not sell any Customer Personal Data, as the term “sell” is defined in the CCPA. In addition, Glean will not collect, share, retain, or use any Customer Personal Data except as necessary to perform the Service for Customer and only within the direct business relationship with Customer.”
“Acceptable Use Policy AI Addendum Limited Retention Addendum Optional Offerings Security and Privacy Standard”
“This Privacy Statement (“ Privacy Statement ”) does not apply to your use of our products and services (collectively, “ Solutions ”).”
!Many LLM providers in the request path; model-to-feature routing not disclosedGap
The subprocessor list (updated 28 July 2026) names seven dedicated LLM providers (Anthropic, OpenAI, Baseten, Fireworks.ai, Groq, Modal Labs, Snowflake) plus AWS, Google and Microsoft as cloud/LLM providers, and Palo Alto Networks for AI runtime security. The AI Gateway advertises 40+ models. The DPA says the subprocessor set varies with hosting choice and whether the customer brings its own model, but nothing collected says which providers serve which features, what the default model is, or what data-retention terms each provider applies.
The buyer's data may be sent to any of ten model-hosting organisations depending on configuration. Transparency of names is good; without routing and provider-retention detail the buyer cannot complete a downstream data-flow assessment.
Question for vendor: Which LLM providers and models are used by default for Assistant, Agents and the AI Gateway in our configuration, can we restrict the set, and do all providers operate under zero-data-retention or equivalent terms?
“Access 40+ frontier and open models through one governed layer, improving token efficiency, avoiding provider lock-in, and giving teams faster access to the latest models.”
“Anthropic PBC LLM Provider United States Baseten Labs, Inc. LLM Provider United States Fireworks.ai, Inc. LLM Provider United States Groq, Inc. LLM Provider United States Modal Labs, Inc. LLM Provider United States OpenAI OpCo, LLC LLM Provider United States Snowflake, Inc. LLM Provider United States”
“The Subprocessors used will depend on (a) whether the Data exporter or the Data importer hosts the data, and (b) whether or not the Data exporter uses its own AI large language model.”
“*Customers have discretion to select a different Cloud Service Provider and location.”
“Palo Alto Networks, Inc. AI security provider (Prisma AI Runtime Security) United States”
“Brave Software, Inc. Search United States Deepgram, Inc. Speech-to-text transcription United States** Exa Labs, Inc. Web crawling and rendering United States”
✓Strong contractual data-handling terms in a public DPAStrong
The public DPA (6 March 2026) sets retention to mirror the customer's own application policies with metadata logs capped at 30 days, deletion on termination, 72-hour breach notification, 30-day advance notice of new subprocessors with objection and termination rights, and annual independent audit. Processing defaults to the United States with customer discretion over cloud provider and location, and an Indian affiliate has remote support access.
These are binding terms rather than marketing statements, and they are stronger than many enterprise AI vendors publish. The US default and Indian support access should be confirmed against the buyer's residency requirements.
Question for vendor: Confirm the hosting region available for our tenant and whether remote access by the Indian affiliate can be restricted or logged for our instance.
“Data importer mirrors the data retention period that data exporter has set as a policy in their respective applications, except for data exporter’s meta-data logs containing any personal data that are retained for up to thirty (30) days.”
“Glean will delete Customer Personal Data following the termination of the Agreement, unless such Customer Personal Data is required to be maintained by Data Protection Laws, in which case it shall be held in accordance with the terms of this DPA.”
“Before appointment of any new Subprocessor, Glean shall notify Customer in writing with at least thirty (30) days’ written notice including via the Services or by updating our website.”
“Glean shall notify Customer without undue delay, but in no event more than seventy-two (72) hours after becoming aware of and investigating any Personal Data Breach, and Glean will : (i) take reasonable steps to identify the cause of such Personal Data Breach; and (ii) take the steps necessary and reasonable to remediate the cause of such Personal Data Breach to the extent such remediation is within Glean's reasonable control.”
“*Customers have discretion to select a different Cloud Service Provider and location.”
“Glean Search Technologies India Private Limited Remote access for support, security and debugging India”
“Glean undertakes to perform regular audits to verify its technical and organizational security measures. Such audits will be conducted: (i) by a qualified independent third party; (ii) at least annually; (iii) in accordance with SOC 2 standards or substantially equivalent standards; and (iv) will result in an audit report (“Report”).”
!Testing and change-management disclosure is thinGap
Evidence on testing and evaluation consists of marketing metrics (78% preference versus Claude Cowork, 96.9% prompt-injection detection accuracy) with no published methodology, red-teaming or evaluation programme, so testing_and_evaluation is partial. Change management is evidenced only by the DPA's subprocessor-notice clause; there is no disclosure of how customers are notified of model changes, model version swaps or new AI features (several are marked beta). Both domains are partial rather than not_evidenced because some disclosure exists.
With 40+ swappable models behind the gateway, a model change can alter outputs and risk profile without the buyer knowing. Vendor-run benchmarks do not substitute for an evaluation and red-teaming programme, which an ISO/IEC 42001 certificate would normally imply.
Question for vendor: Describe your AI evaluation and red-teaming programme, and how customers are notified before default models, model versions or agent capabilities change.
“In head-to-head evaluations, Glean was preferred 78% of the time versus Claude Cowork and saved 81% on token costs.”
“Detect prompt injection attacks with 96.9% accuracy Scans unstructured data to separate risk from noise with 95% accuracy”
“Before appointment of any new Subprocessor, Glean shall notify Customer in writing with at least thirty (30) days’ written notice including via the Services or by updating our website.”
“Access 40+ frontier and open models through one governed layer, improving token efficiency, avoiding provider lock-in, and giving teams faster access to the latest models.”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Access 40+ frontier and open models through one governed layer, improving token efficiency, avoiding provider lock-in, and giving teams faster access to the latest models.”
“Anthropic PBC LLM Provider United States Baseten Labs, Inc. LLM Provider United States Fireworks.ai, Inc. LLM Provider United States Groq, Inc. LLM Provider United States Modal Labs, Inc. LLM Provider United States OpenAI OpCo, LLC LLM Provider United States Snowflake, Inc. LLM Provider United States”
“The Subprocessors used will depend on (a) whether the Data exporter or the Data importer hosts the data, and (b) whether or not the Data exporter uses its own AI large language model.”
“Glean delivers an open platform with extensible connectors, APIs, and configuration options, including Customer-controlled hosting choices and support for multiple third-party large language models, operated in accordance with Glean’s security, privacy, and compliance commitments.”
“Palo Alto Networks, Inc. AI security provider (Prisma AI Runtime Security) United States”
“Glean Search Technologies India Private Limited Remote access for support, security and debugging India”
“Brave Software, Inc. Search United States Deepgram, Inc. Speech-to-text transcription United States** Exa Labs, Inc. Web crawling and rendering United States”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score65
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“Always-on auditing. Every control point is logged to an end-to-end audit trail as it happens, with events available to stream into SIEM.”
“A practical framework for assessing agent risk and governing how agents access data and take action. Built in collaboration with Databricks and Palo Alto Networks’ Unit 42.”
“Glean is certified to ISO/IEC 42001:2023, the leading international standard for AI management systems, demonstrating our commitment to responsible, well‑governed AI with rigorous risk assessment, mitigation, and oversight.”
Governance & accountability: vendor-evidenced, not yet independently corroborated.
AI system15% of the score47
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Glean provides an enterprise Work AI Platform that sits horizontally across Customer’s systems and data, connecting to the business applications, content repositories, and data sources that Customer selects. The Service enables Users to find knowledge, generate content, and automate work with AI in an enterprise context, while maintaining the identity, access controls, and sharing configurations of each Connected Application.”
“By reasoning through your request, Assistant creates a multi-step strategy and coordinates sub-agents to work in parallel.”
“Access 40+ frontier and open models through one governed layer, improving token efficiency, avoiding provider lock-in, and giving teams faster access to the latest models.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“In head-to-head evaluations, Glean was preferred 78% of the time versus Claude Cowork and saved 81% on token costs.”
“Detect prompt injection attacks with 96.9% accuracy Scans unstructured data to separate risk from noise with 95% accuracy”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“Before appointment of any new Subprocessor, Glean shall notify Customer in writing with at least thirty (30) days’ written notice including via the Services or by updating our website.”
AI system description: vendor-evidenced, not yet independently corroborated.
Model10% of the score60
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Access 40+ frontier and open models through one governed layer, improving token efficiency, avoiding provider lock-in, and giving teams faster access to the latest models.”
“Anthropic PBC LLM Provider United States Baseten Labs, Inc. LLM Provider United States Fireworks.ai, Inc. LLM Provider United States Groq, Inc. LLM Provider United States Modal Labs, Inc. LLM Provider United States OpenAI OpCo, LLC LLM Provider United States Snowflake, Inc. LLM Provider United States”
“The Subprocessors used will depend on (a) whether the Data exporter or the Data importer hosts the data, and (b) whether or not the Data exporter uses its own AI large language model.”
“Glean delivers an open platform with extensible connectors, APIs, and configuration options, including Customer-controlled hosting choices and support for multiple third-party large language models, operated in accordance with Glean’s security, privacy, and compliance commitments.”
Model provider transparency: vendor-evidenced, not yet independently corroborated.
Customer data15% of the score52
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“Data importer mirrors the data retention period that data exporter has set as a policy in their respective applications, except for data exporter’s meta-data logs containing any personal data that are retained for up to thirty (30) days.”
“Glean will delete Customer Personal Data following the termination of the Agreement, unless such Customer Personal Data is required to be maintained by Data Protection Laws, in which case it shall be held in accordance with the terms of this DPA.”
“Glean does not have, derive, or exercise any rights or benefits regarding Customer Personal Data. Glean will not sell any Customer Personal Data, as the term “sell” is defined in the CCPA. In addition, Glean will not collect, share, retain, or use any Customer Personal Data except as necessary to perform the Service for Customer and only within the direct business relationship with Customer.”
“All customer data is encrypted at rest with FIPS 140-2 validated crypto module utilizing AES 256 bit encryption. All data in transit is encrypted using TLS 1.2+.”
“*Customers have discretion to select a different Cloud Service Provider and location.”
AI supply chain10% of the score60
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Anthropic PBC LLM Provider United States Baseten Labs, Inc. LLM Provider United States Fireworks.ai, Inc. LLM Provider United States Groq, Inc. LLM Provider United States Modal Labs, Inc. LLM Provider United States OpenAI OpCo, LLC LLM Provider United States Snowflake, Inc. LLM Provider United States”
“The Subprocessors used will depend on (a) whether the Data exporter or the Data importer hosts the data, and (b) whether or not the Data exporter uses its own AI large language model.”
“Palo Alto Networks, Inc. AI security provider (Prisma AI Runtime Security) United States”
“Glean Search Technologies India Private Limited Remote access for support, security and debugging India”
“Brave Software, Inc. Search United States Deepgram, Inc. Speech-to-text transcription United States** Exa Labs, Inc. Web crawling and rendering United States”
Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.
Security foundation15% of the score70
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“Glean shall notify Customer without undue delay, but in no event more than seventy-two (72) hours after becoming aware of and investigating any Personal Data Breach, and Glean will : (i) take reasonable steps to identify the cause of such Personal Data Breach; and (ii) take the steps necessary and reasonable to remediate the cause of such Personal Data Breach to the extent such remediation is within Glean's reasonable control.”
“If you believe you have found a security vulnerability in Glean's product offering, please submit it to our bug bounty program .”
“Screen for prompt injection, malicious code, and harmful content while AI operates.”
Vulnerability & incident handling: vendor-evidenced, not yet independently corroborated.
Independent assurance evidence10% of the score55
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“Glean is SOC 2 Type II certified, the most comprehensive attestation that our systems are designed and independently audited to keep customers’ sensitive data secure, available, and confidential.”
“Glean is certified to ISO/IEC 27001, the leading global standard for information security management, ensuring robust, independently validated controls for risk assessment, mitigation, and compliance.”
“Glean is certified to ISO/IEC 42001:2023, the leading international standard for AI management systems, demonstrating our commitment to responsible, well‑governed AI with rigorous risk assessment, mitigation, and oversight.”
“HIPAA compliant Customers' sensitive health information is maintained and secured in accordance with the Health Insurance Portability and Accountability Act (HIPAA) of 1996.”
“Enterprise security and compliance ISO 42001 HIPAA TX-RAMP Level 2 SOC 2 Type II ISO 27001 GDPR”
“Glean undertakes to perform regular audits to verify its technical and organizational security measures. Such audits will be conducted: (i) by a qualified independent third party; (ii) at least annually; (iii) in accordance with SOC 2 standards or substantially equivalent standards; and (iv) will result in an audit report (“Report”).”
“Glean has certified to the Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework (DPF) Principles, the UK Extension to the EU–U.S. Data Privacy Framework, and the Swiss–U.S. Data Privacy Framework, and is committed to all relevant framework Principles.”
Read from the registry record above — cited, not reproduced.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“This Privacy Statement (“ Privacy Statement ”) does not apply to your use of our products and services (collectively, “ Solutions ”).”
“Acceptable Use Policy AI Addendum Limited Retention Addendum Optional Offerings Security and Privacy Standard”
“Data importer mirrors the data retention period that data exporter has set as a policy in their respective applications, except for data exporter’s meta-data logs containing any personal data that are retained for up to thirty (30) days.”
“Before appointment of any new Subprocessor, Glean shall notify Customer in writing with at least thirty (30) days’ written notice including via the Services or by updating our website.”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 59 → up to 82 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 6 — registry checks and verification ladders, click to view
Claimed on the legal page and AI security page; the DPA commits to annual independent SOC 2-standard audits with the report available on request. Auditor and period not stated.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Claimed on the legal page and AI security page; certification body, certificate scope and expiry not stated.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Claimed as ISO/IEC 42001:2023 on the legal page and AI security page; certification body, scope and expiry not stated.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Compliance statement with BAAs offered; HIPAA has no formal certification scheme.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Appears only as a badge on the AI security page; no certification detail.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Self-certification stated in the website privacy statement (which excludes the Solutions); DPF list not checked in this scan.
Checked against Data Privacy Framework (dataprivacyframework.gov), Oct 5, 2026: Verified on the registry
Sources 13 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
Want to go further?
This scan assesses Glean at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.
Scan a specific product →This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
Monitor for changes
Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.
