Glean

glean.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
59 / 100C
Procurement decision
Approve with conditions
1 condition outstanding
  • No clear commitment that your data will not train their models

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification Partial

Scanned Oct 5, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean does not have, derive, or exercise any rights or benefits regarding Customer Personal Data. Glean will not sell any Customer Personal Data, as the term “sell” is defined in the CCPA. In addition, Glean will not collect, share, retain, or use any Customer Personal Data except as necessary to perform the Service for Customer and only within the direct business relationship with Customer.”

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

The DPA states Glean derives no rights or benefits from customer personal data, will not sell it, and will not collect, share, retain or use it except as necessary to perform the Service. It does not expressly address model training or fine-tuning.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean does not have, derive, or exercise any rights or benefits regarding Customer Personal Data. Glean will not sell any Customer Personal Data, as the term “sell” is defined in the CCPA. In addition, Glean will not collect, share, retain, or use any Customer Personal Data except as necessary to perform the Service for Customer and only within the direct business relationship with Customer.”
✓How long do they keep your data?Clear

Under the DPA, Glean mirrors the retention period the customer has set in its own connected applications, except that metadata logs containing personal data are retained for up to 30 days.

Evidence
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Data importer mirrors the data retention period that data exporter has set as a policy in their respective applications, except for data exporter’s meta-data logs containing any personal data that are retained for up to thirty (30) days.”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean will delete Customer Personal Data following the termination of the Agreement, unless such Customer Personal Data is required to be maintained by Data Protection Laws, in which case it shall be held in accordance with the terms of this DPA.”
✓Who else can access your data?Clear

Glean's public subprocessor list names Anthropic, Baseten, Fireworks.ai, Groq, Modal Labs, OpenAI and Snowflake as LLM providers, all located in the United States.

Evidence
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Anthropic PBC LLM Provider United States Baseten Labs, Inc. LLM Provider United States Fireworks.ai, Inc. LLM Provider United States Groq, Inc. LLM Provider United States Modal Labs, Inc. LLM Provider United States OpenAI OpCo, LLC LLM Provider United States Snowflake, Inc. LLM Provider United States”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“The Subprocessors used will depend on (a) whether the Data exporter or the Data importer hosts the data, and (b) whether or not the Data exporter uses its own AI large language model.”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Palo Alto Networks, Inc. AI security provider (Prisma AI Runtime Security) United States”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Brave Software, Inc. Search United States Deepgram, Inc. Speech-to-text transcription United States** Exa Labs, Inc. Web crawling and rendering United States”
!Where is your data processed?Ask the vendor

AWS, Google and Microsoft are listed as cloud service / LLM providers located in the United States by default, with a footnote that customers may select a different cloud service provider and location.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Externally corroboratedSubprocessors | Glean ↗retrieved Oct 5, 2026
“*Customers have discretion to select a different Cloud Service Provider and location.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Glean delivers an open platform with extensible connectors, APIs, and configuration options, including Customer-controlled hosting choices and support for multiple third-party large language models, operated in accordance with Glean’s security, privacy, and compliance commitments.”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Glean Search Technologies India Private Limited Remote access for support, security and debugging India”
✓What happens in a security incident?Clear

The DPA commits Glean to notify the customer of a personal data breach without undue delay and no later than 72 hours after becoming aware of and investigating it, to identify the cause and to remediate it where within Glean's control.

Evidence
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean shall notify Customer without undue delay, but in no event more than seventy-two (72) hours after becoming aware of and investigating any Personal Data Breach, and Glean will : (i) take reasonable steps to identify the cause of such Personal Data Breach; and (ii) take the steps necessary and reasonable to remediate the cause of such Personal Data Breach to the extent such remediation is within Glean's reasonable control.”

Email to send the vendor6 items to confirm in writing

Subject: Supplier assessment: written confirmation requested
Hello Glean team,

We are assessing Glean as part of our supplier review. Before we proceed, please confirm the following in writing:

1. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan.
2. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose?
3. Please provide the ISO/IEC 27001 and ISO/IEC 42001 certificates (issuer, scope statement, expiry) and the current SOC 2 Type II report under NDA.
4. Which LLM providers and models are used by default for Assistant, Agents and the AI Gateway in our configuration, can we restrict the set, and do all providers operate under zero-data-retention or equivalent terms?
5. Describe your AI evaluation and red-teaming programme, and how customers are notified before default models, model versions or agent capabilities change.
6. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date.

Thank you,
Audit evidence: a verified report maps its findings to ISO/IEC 27001 supplier controls, ISO/IEC 42001 third-party controls and APRA CPS 230. See verified reports →

Key findingsclick a row for the evidence

✓Broad certification set including ISO/IEC 42001, but vendor-claimed onlyStrong

Glean publicly claims SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001:2023, HIPAA alignment, TX-RAMP Level 2 and EU-U.S. DPF participation, and its DPA contractually commits to at least annual independent SOC 2-standard audits with the report available on request. None of these is corroborated by an independent source within this scan, and no certificate issuer, scope or validity date is published on the pages collected.

ISO/IEC 42001 is still uncommon among AI vendors and signals a managed AI governance system; the contractual audit commitment means the buyer can obtain the SOC 2 report rather than relying on a badge. Until the certificates are checked against a registry, they remain vendor statements.

Question for vendor: Please provide the ISO/IEC 27001 and ISO/IEC 42001 certificates (issuer, scope statement, expiry) and the current SOC 2 Type II report under NDA.

Evidence
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Glean is SOC 2 Type II certified, the most comprehensive attestation that our systems are designed and independently audited to keep customers’ sensitive data secure, available, and confidential.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Glean is certified to ISO/IEC 27001, the leading global standard for information security management, ensuring robust, independently validated controls for risk assessment, mitigation, and compliance.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Glean is certified to ISO/IEC 42001:2023, the leading international standard for AI management systems, demonstrating our commitment to responsible, well‑governed AI with rigorous risk assessment, mitigation, and oversight.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“HIPAA compliant Customers' sensitive health information is maintained and secured in accordance with the Health Insurance Portability and Accountability Act (HIPAA) of 1996.”
Vendor publishedAI Security: Protecting Enterprise Data with Glean ↗retrieved Oct 5, 2026
“Enterprise security and compliance ISO 42001 HIPAA TX-RAMP Level 2 SOC 2 Type II ISO 27001 GDPR”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean undertakes to perform regular audits to verify its technical and organizational security measures. Such audits will be conducted: (i) by a qualified independent third party; (ii) at least annually; (iii) in accordance with SOC 2 standards or substantially equivalent standards; and (iv) will result in an audit report (“Report”).”
Vendor publishedGlean's Privacy Policy | Glean ↗retrieved Oct 5, 2026
“Glean has certified to the Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework (DPF) Principles, the UK Extension to the EU–U.S. Data Privacy Framework, and the Swiss–U.S. Data Privacy Framework, and is committed to all relevant framework Principles.”
!No explicit statement on training with customer data in the collected documentsGap

None of the nine documents collected states whether customer content, prompts or outputs are used to train or fine-tune Glean's or third-party models. The DPA's purpose-limitation clause (use only as necessary to perform the Service, no rights or benefits derived) is the closest contractual language but does not name training. The legal page lists an 'AI Addendum' and a 'Limited Retention Addendum' that likely address this but were not collected. Because the central buyer question is unanswered, customer_data_treatment is marked partial despite solid retention and erasure terms; no domain was marked not_evidenced or not_applicable.

A buyer cannot rely on silence. The absence is most likely a collection gap rather than a vendor omission, but it must be closed by reading the AI Addendum before the product is cleared on data training.

Question for vendor: Confirm in writing (ideally by reference to the AI Addendum) whether any customer data, prompts or outputs are used to train, fine-tune or evaluate models by Glean or any LLM provider, and what retention the LLM providers apply to prompts.

Evidence
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean does not have, derive, or exercise any rights or benefits regarding Customer Personal Data. Glean will not sell any Customer Personal Data, as the term “sell” is defined in the CCPA. In addition, Glean will not collect, share, retain, or use any Customer Personal Data except as necessary to perform the Service for Customer and only within the direct business relationship with Customer.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Acceptable Use Policy AI Addendum Limited Retention Addendum Optional Offerings Security and Privacy Standard”
Vendor publishedGlean's Privacy Policy | Glean ↗retrieved Oct 5, 2026
“This Privacy Statement (“ Privacy Statement ”) does not apply to your use of our products and services (collectively, “ Solutions ”).”
!Many LLM providers in the request path; model-to-feature routing not disclosedGap

The subprocessor list (updated 28 July 2026) names seven dedicated LLM providers (Anthropic, OpenAI, Baseten, Fireworks.ai, Groq, Modal Labs, Snowflake) plus AWS, Google and Microsoft as cloud/LLM providers, and Palo Alto Networks for AI runtime security. The AI Gateway advertises 40+ models. The DPA says the subprocessor set varies with hosting choice and whether the customer brings its own model, but nothing collected says which providers serve which features, what the default model is, or what data-retention terms each provider applies.

The buyer's data may be sent to any of ten model-hosting organisations depending on configuration. Transparency of names is good; without routing and provider-retention detail the buyer cannot complete a downstream data-flow assessment.

Question for vendor: Which LLM providers and models are used by default for Assistant, Agents and the AI Gateway in our configuration, can we restrict the set, and do all providers operate under zero-data-retention or equivalent terms?

Evidence
Vendor publishedGlean AI Gateway: Enterprise AI Control Plane ↗retrieved Oct 5, 2026
“Access 40+ frontier and open models through one governed layer, improving token efficiency, avoiding provider lock-in, and giving teams faster access to the latest models.”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Anthropic PBC LLM Provider United States Baseten Labs, Inc. LLM Provider United States Fireworks.ai, Inc. LLM Provider United States Groq, Inc. LLM Provider United States Modal Labs, Inc. LLM Provider United States OpenAI OpCo, LLC LLM Provider United States Snowflake, Inc. LLM Provider United States”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“The Subprocessors used will depend on (a) whether the Data exporter or the Data importer hosts the data, and (b) whether or not the Data exporter uses its own AI large language model.”
Externally corroboratedSubprocessors | Glean ↗retrieved Oct 5, 2026
“*Customers have discretion to select a different Cloud Service Provider and location.”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Palo Alto Networks, Inc. AI security provider (Prisma AI Runtime Security) United States”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Brave Software, Inc. Search United States Deepgram, Inc. Speech-to-text transcription United States** Exa Labs, Inc. Web crawling and rendering United States”
✓Strong contractual data-handling terms in a public DPAStrong

The public DPA (6 March 2026) sets retention to mirror the customer's own application policies with metadata logs capped at 30 days, deletion on termination, 72-hour breach notification, 30-day advance notice of new subprocessors with objection and termination rights, and annual independent audit. Processing defaults to the United States with customer discretion over cloud provider and location, and an Indian affiliate has remote support access.

These are binding terms rather than marketing statements, and they are stronger than many enterprise AI vendors publish. The US default and Indian support access should be confirmed against the buyer's residency requirements.

Question for vendor: Confirm the hosting region available for our tenant and whether remote access by the Indian affiliate can be restricted or logged for our instance.

Evidence
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Data importer mirrors the data retention period that data exporter has set as a policy in their respective applications, except for data exporter’s meta-data logs containing any personal data that are retained for up to thirty (30) days.”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean will delete Customer Personal Data following the termination of the Agreement, unless such Customer Personal Data is required to be maintained by Data Protection Laws, in which case it shall be held in accordance with the terms of this DPA.”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Before appointment of any new Subprocessor, Glean shall notify Customer in writing with at least thirty (30) days’ written notice including via the Services or by updating our website.”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean shall notify Customer without undue delay, but in no event more than seventy-two (72) hours after becoming aware of and investigating any Personal Data Breach, and Glean will : (i) take reasonable steps to identify the cause of such Personal Data Breach; and (ii) take the steps necessary and reasonable to remediate the cause of such Personal Data Breach to the extent such remediation is within Glean's reasonable control.”
Externally corroboratedSubprocessors | Glean ↗retrieved Oct 5, 2026
“*Customers have discretion to select a different Cloud Service Provider and location.”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Glean Search Technologies India Private Limited Remote access for support, security and debugging India”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean undertakes to perform regular audits to verify its technical and organizational security measures. Such audits will be conducted: (i) by a qualified independent third party; (ii) at least annually; (iii) in accordance with SOC 2 standards or substantially equivalent standards; and (iv) will result in an audit report (“Report”).”
!Testing and change-management disclosure is thinGap

Evidence on testing and evaluation consists of marketing metrics (78% preference versus Claude Cowork, 96.9% prompt-injection detection accuracy) with no published methodology, red-teaming or evaluation programme, so testing_and_evaluation is partial. Change management is evidenced only by the DPA's subprocessor-notice clause; there is no disclosure of how customers are notified of model changes, model version swaps or new AI features (several are marked beta). Both domains are partial rather than not_evidenced because some disclosure exists.

With 40+ swappable models behind the gateway, a model change can alter outputs and risk profile without the buyer knowing. Vendor-run benchmarks do not substitute for an evaluation and red-teaming programme, which an ISO/IEC 42001 certificate would normally imply.

Question for vendor: Describe your AI evaluation and red-teaming programme, and how customers are notified before default models, model versions or agent capabilities change.

Evidence
Vendor publishedGlean AI Gateway: Enterprise AI Control Plane ↗retrieved Oct 5, 2026
“In head-to-head evaluations, Glean was preferred 78% of the time versus Claude Cowork and saved 81% on token costs.”
Vendor publishedAI Security: Protecting Enterprise Data with Glean ↗retrieved Oct 5, 2026
“Detect prompt injection attacks with 96.9% accuracy Scans unstructured data to separate risk from noise with 95% accuracy”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Before appointment of any new Subprocessor, Glean shall notify Customer in writing with at least thirty (30) days’ written notice including via the Services or by updating our website.”
Vendor publishedGlean AI Gateway: Enterprise AI Control Plane ↗retrieved Oct 5, 2026
“Access 40+ frontier and open models through one governed layer, improving token efficiency, avoiding provider lock-in, and giving teams faster access to the latest models.”
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedGlean AI Gateway: Enterprise AI Control Plane ↗retrieved Oct 5, 2026
“Access 40+ frontier and open models through one governed layer, improving token efficiency, avoiding provider lock-in, and giving teams faster access to the latest models.”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Anthropic PBC LLM Provider United States Baseten Labs, Inc. LLM Provider United States Fireworks.ai, Inc. LLM Provider United States Groq, Inc. LLM Provider United States Modal Labs, Inc. LLM Provider United States OpenAI OpCo, LLC LLM Provider United States Snowflake, Inc. LLM Provider United States”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“The Subprocessors used will depend on (a) whether the Data exporter or the Data importer hosts the data, and (b) whether or not the Data exporter uses its own AI large language model.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Glean delivers an open platform with extensible connectors, APIs, and configuration options, including Customer-controlled hosting choices and support for multiple third-party large language models, operated in accordance with Glean’s security, privacy, and compliance commitments.”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Palo Alto Networks, Inc. AI security provider (Prisma AI Runtime Security) United States”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Glean Search Technologies India Private Limited Remote access for support, security and debugging India”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Brave Software, Inc. Search United States Deepgram, Inc. Speech-to-text transcription United States** Exa Labs, Inc. Web crawling and rendering United States”

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score65
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedAI Security: Protecting Enterprise Data with Glean ↗retrieved Oct 5, 2026
“Always-on auditing. Every control point is logged to an end-to-end audit trail as it happens, with events available to stream into SIEM.”
Vendor publishedAI Security: Protecting Enterprise Data with Glean ↗retrieved Oct 5, 2026
“A practical framework for assessing agent risk and governing how agents access data and take action. Built in collaboration with Databricks and Palo Alto Networks’ Unit 42.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Glean is certified to ISO/IEC 42001:2023, the leading international standard for AI management systems, demonstrating our commitment to responsible, well‑governed AI with rigorous risk assessment, mitigation, and oversight.”

Governance & accountability: vendor-evidenced, not yet independently corroborated.

AI system15% of the score47
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Glean provides an enterprise Work AI Platform that sits horizontally across Customer’s systems and data, connecting to the business applications, content repositories, and data sources that Customer selects. The Service enables Users to find knowledge, generate content, and automate work with AI in an enterprise context, while maintaining the identity, access controls, and sharing configurations of each Connected Application.”
Vendor publishedEnterprise AI Assistant for Work | Glean ↗retrieved Oct 5, 2026
“By reasoning through your request, Assistant creates a multi-step strategy and coordinates sub-agents to work in parallel.”
Vendor publishedGlean AI Gateway: Enterprise AI Control Plane ↗retrieved Oct 5, 2026
“Access 40+ frontier and open models through one governed layer, improving token efficiency, avoiding provider lock-in, and giving teams faster access to the latest models.”
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedGlean AI Gateway: Enterprise AI Control Plane ↗retrieved Oct 5, 2026
“In head-to-head evaluations, Glean was preferred 78% of the time versus Claude Cowork and saved 81% on token costs.”
Vendor publishedAI Security: Protecting Enterprise Data with Glean ↗retrieved Oct 5, 2026
“Detect prompt injection attacks with 96.9% accuracy Scans unstructured data to separate risk from noise with 95% accuracy”
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Before appointment of any new Subprocessor, Glean shall notify Customer in writing with at least thirty (30) days’ written notice including via the Services or by updating our website.”

AI system description: vendor-evidenced, not yet independently corroborated.

Model10% of the score60
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Vendor publishedGlean AI Gateway: Enterprise AI Control Plane ↗retrieved Oct 5, 2026
“Access 40+ frontier and open models through one governed layer, improving token efficiency, avoiding provider lock-in, and giving teams faster access to the latest models.”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Anthropic PBC LLM Provider United States Baseten Labs, Inc. LLM Provider United States Fireworks.ai, Inc. LLM Provider United States Groq, Inc. LLM Provider United States Modal Labs, Inc. LLM Provider United States OpenAI OpCo, LLC LLM Provider United States Snowflake, Inc. LLM Provider United States”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“The Subprocessors used will depend on (a) whether the Data exporter or the Data importer hosts the data, and (b) whether or not the Data exporter uses its own AI large language model.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Glean delivers an open platform with extensible connectors, APIs, and configuration options, including Customer-controlled hosting choices and support for multiple third-party large language models, operated in accordance with Glean’s security, privacy, and compliance commitments.”

Model provider transparency: vendor-evidenced, not yet independently corroborated.

Customer data15% of the score52
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Data importer mirrors the data retention period that data exporter has set as a policy in their respective applications, except for data exporter’s meta-data logs containing any personal data that are retained for up to thirty (30) days.”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean will delete Customer Personal Data following the termination of the Agreement, unless such Customer Personal Data is required to be maintained by Data Protection Laws, in which case it shall be held in accordance with the terms of this DPA.”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean does not have, derive, or exercise any rights or benefits regarding Customer Personal Data. Glean will not sell any Customer Personal Data, as the term “sell” is defined in the CCPA. In addition, Glean will not collect, share, retain, or use any Customer Personal Data except as necessary to perform the Service for Customer and only within the direct business relationship with Customer.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“All customer data is encrypted at rest with FIPS 140-2 validated crypto module utilizing AES 256 bit encryption. All data in transit is encrypted using TLS 1.2+.”
Externally corroboratedSubprocessors | Glean ↗retrieved Oct 5, 2026
“*Customers have discretion to select a different Cloud Service Provider and location.”
AI supply chain10% of the score60
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Anthropic PBC LLM Provider United States Baseten Labs, Inc. LLM Provider United States Fireworks.ai, Inc. LLM Provider United States Groq, Inc. LLM Provider United States Modal Labs, Inc. LLM Provider United States OpenAI OpCo, LLC LLM Provider United States Snowflake, Inc. LLM Provider United States”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“The Subprocessors used will depend on (a) whether the Data exporter or the Data importer hosts the data, and (b) whether or not the Data exporter uses its own AI large language model.”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Palo Alto Networks, Inc. AI security provider (Prisma AI Runtime Security) United States”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Glean Search Technologies India Private Limited Remote access for support, security and debugging India”
Vendor publishedSubprocessors | Glean ↗retrieved Oct 5, 2026
“Brave Software, Inc. Search United States Deepgram, Inc. Speech-to-text transcription United States** Exa Labs, Inc. Web crawling and rendering United States”

Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.

Security foundation15% of the score70
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean shall notify Customer without undue delay, but in no event more than seventy-two (72) hours after becoming aware of and investigating any Personal Data Breach, and Glean will : (i) take reasonable steps to identify the cause of such Personal Data Breach; and (ii) take the steps necessary and reasonable to remediate the cause of such Personal Data Breach to the extent such remediation is within Glean's reasonable control.”
Vendor publishedAI Security: Protecting Enterprise Data with Glean ↗retrieved Oct 5, 2026
“If you believe you have found a security vulnerability in Glean's product offering, please submit it to our bug bounty program .”
Vendor publishedAI Security: Protecting Enterprise Data with Glean ↗retrieved Oct 5, 2026
“Screen for prompt injection, malicious code, and harmful content while AI operates.”

Vulnerability & incident handling: vendor-evidenced, not yet independently corroborated.

Independent assurance evidence10% of the score55
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Glean is SOC 2 Type II certified, the most comprehensive attestation that our systems are designed and independently audited to keep customers’ sensitive data secure, available, and confidential.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Glean is certified to ISO/IEC 27001, the leading global standard for information security management, ensuring robust, independently validated controls for risk assessment, mitigation, and compliance.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Glean is certified to ISO/IEC 42001:2023, the leading international standard for AI management systems, demonstrating our commitment to responsible, well‑governed AI with rigorous risk assessment, mitigation, and oversight.”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“HIPAA compliant Customers' sensitive health information is maintained and secured in accordance with the Health Insurance Portability and Accountability Act (HIPAA) of 1996.”
Vendor publishedAI Security: Protecting Enterprise Data with Glean ↗retrieved Oct 5, 2026
“Enterprise security and compliance ISO 42001 HIPAA TX-RAMP Level 2 SOC 2 Type II ISO 27001 GDPR”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Glean undertakes to perform regular audits to verify its technical and organizational security measures. Such audits will be conducted: (i) by a qualified independent third party; (ii) at least annually; (iii) in accordance with SOC 2 standards or substantially equivalent standards; and (iv) will result in an audit report (“Report”).”
Vendor publishedGlean's Privacy Policy | Glean ↗retrieved Oct 5, 2026
“Glean has certified to the Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework (DPF) Principles, the UK Extension to the EU–U.S. Data Privacy Framework, and the Swiss–U.S. Data Privacy Framework, and is committed to all relevant framework Principles.”

Read from the registry record above — cited, not reproduced.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedGlean's Privacy Policy | Glean ↗retrieved Oct 5, 2026
“This Privacy Statement (“ Privacy Statement ”) does not apply to your use of our products and services (collectively, “ Solutions ”).”
Vendor publishedLegal | Glean ↗retrieved Oct 5, 2026
“Acceptable Use Policy AI Addendum Limited Retention Addendum Optional Offerings Security and Privacy Standard”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Data importer mirrors the data retention period that data exporter has set as a policy in their respective applications, except for data exporter’s meta-data logs containing any personal data that are retained for up to thirty (30) days.”
Vendor publishedassets.glean.com ↗retrieved Oct 5, 2026
“Before appointment of any new Subprocessor, Glean shall notify Customer in writing with at least thirty (30) days’ written notice including via the Services or by updating our website.”

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Complete the Customer data treatment disclosureData 52 → 72
+3Verify EU-U.S. Data Privacy Framework scope covers this assessmentIndependent Assurance 55 → 78
+2Have Governance & accountability disclosures independently corroboratedOrganisation 65 → 80
+2Have Vulnerability & incident handling disclosures independently corroboratedSecurity Foundation 70 → 85
+1Have Legal & contractual transparency disclosures independently corroboratedLegal Contractual 60 → 75

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 59 → up to 82 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSINFRASTRUCTURESUBPROCESSORSGlean Technologies, Inc.Glean Technologies, Inc.Glean AssistantGlean AssistantGlean AI GatewayGlean AI GatewayGlean ProtectGlean ProtectAnthropic PBCAnthropic PBCOpenAI OpCo, LLCOpenAI OpCo, LLCBaseten Labs, Inc.Baseten Labs, Inc.Fireworks.ai, Inc.Fireworks.ai, Inc.Groq, Inc.Groq, Inc.Modal Labs, Inc.Modal Labs, Inc.Snowflake, Inc.Snowflake, Inc.Amazon Web Services, Inc.Amazon Web Services, Inc.Google LLCGoogle LLCMicrosoft CorporationMicrosoft CorporationPalo Alto Networks, Inc. (Prisma AI Runtime Security)Palo Alto Networks, Inc. …Brave Software, Inc.Brave Software, Inc.Deepgram, Inc.Deepgram, Inc.Exa Labs, Inc.Exa Labs, Inc.Glean Search Technologies India Private LimitedGlean Search Technologies…
View as list
Glean Technologies, Inc. Contracted Subprocessor Anthropic PBC
Glean Technologies, Inc. Contracted Subprocessor OpenAI OpCo, LLC
Glean Technologies, Inc. Contracted Subprocessor Baseten Labs, Inc.
Glean Technologies, Inc. Contracted Subprocessor Fireworks.ai, Inc.
Glean Technologies, Inc. Contracted Subprocessor Groq, Inc.
Glean Technologies, Inc. Contracted Subprocessor Modal Labs, Inc.
Glean Technologies, Inc. Contracted Subprocessor Snowflake, Inc.
Glean Technologies, Inc. Uses Infrastructure Amazon Web Services, Inc.
Glean Technologies, Inc. Uses Infrastructure Google LLC
Glean Technologies, Inc. Uses Infrastructure Microsoft Corporation
Glean Technologies, Inc. Contracted Subprocessor Palo Alto Networks, Inc. (Prisma AI Runtime Security)
Glean Technologies, Inc. Contracted Subprocessor Brave Software, Inc.
Glean Technologies, Inc. Contracted Subprocessor Deepgram, Inc.
Glean Technologies, Inc. Contracted Subprocessor Exa Labs, Inc.
Glean Technologies, Inc. Contracted Subprocessor Glean Search Technologies India Private Limited

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 6 — registry checks and verification ladders, click to view
SOC 2 Type IIVendor claimed only

Claimed on the legal page and AI security page; the DPA commits to annual independent SOC 2-standard audits with the report available on request. Auditor and period not stated.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27001Claimed, scope unclear

Claimed on the legal page and AI security page; certification body, certificate scope and expiry not stated.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001Claimed, scope unclear

Claimed as ISO/IEC 42001:2023 on the legal page and AI security page; certification body, scope and expiry not stated.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

HIPAAVendor claimed only

Compliance statement with BAAs offered; HIPAA has no formal certification scheme.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

TX-RAMP Level 2Claimed, scope unclear

Appears only as a badge on the AI security page; no certification detail.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

EU-U.S. Data Privacy FrameworkClaimed & corroborated

Self-certification stated in the website privacy statement (which excludes the Solutions); DPF list not checked in this scan.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Oct 5, 2026: Verified on the registry

Sources 13 — click to view
Glean AI Gateway: Enterprise AI Control Plane
AI Documentation · Vendor · retrieved Oct 5, 2026
AI Security: Protecting Enterprise Data with Glean
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Subprocessors | Glean
Subprocessor List · Vendor · retrieved Oct 5, 2026
Glean's Privacy Policy | Glean
Privacy Notice · Vendor · retrieved Oct 5, 2026
Vanta
Certification Or Compliance Page · Vendor · retrieved Oct 5, 2026
Glean Documentation
Product Documentation · Vendor · retrieved Oct 5, 2026
Legal | Glean
Terms · Vendor · retrieved Oct 5, 2026
Enterprise AI Assistant for Work | Glean
AI Documentation · Vendor · retrieved Oct 5, 2026
Glean Trust Center
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Glean Trust Center
Subprocessor List · Vendor · retrieved Oct 5, 2026
Glean Developer Platform | Glean Developer
Product Documentation · Vendor · retrieved Oct 5, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Oct 5, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Glean at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.

Monitor for changes

Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.