Resource · Security questionnaires

Which certifications AI vendors say they hold

What 120 AI vendors name on their own trust pages, grouped by standard and kept apart by level.

Says, not holds

Every count on this page is a claim a vendor published about itself. Xither has not seen a report, confirmed an auditor, or checked whether a certificate is still in date. A vendor appears in a row because its page names the standard — nothing more.

A count read off trust pages looks like verification and is not one. The difference is the reason this page can be published at all.

Why SOC 2 is two rows

82 vendors name SOC 2 Type II. 58 name SOC 2 without saying which type. Adding those together would publish a Type II claim on behalf of vendors that never made one — a Type II report covers a period of operating effectiveness, a Type I is a single date, and a page saying only “SOC 2” has not told you which.

The sum is wrong twice over: 140 against 102 distinct vendors, because 38 of them name both on the same page. Every family below is arranged the same way and no levels are added up.

What gets named, and how often

SOC 2Type II82
not stated58
GDPRnot stated82
ISO/IEC 27001not stated77
HIPAAnot stated54
ISO/IEC 27701not stated28
ISO/IEC 42001not stated26
SOC 3not stated22
ISO/IEC 27017not stated22
ISO/IEC 27018not stated22
FedRAMPnot stated22
PCI DSSnot stated18
CSA STARnot stated16
Cyber Essentialsnot stated12
SOC 1not stated11
IRAPnot stated9
TX-RAMPnot stated6
HITRUSTnot stated6

Who names what

SOC 2 — Type II · 82

6sense, Ada, Airtable, Algolia, AlphaSense, Alteryx, Anysphere, Appen, Asana, AssemblyAI, Augment Code, Baseten, Beamery, BigPanda, Box, ClickHouse, and 66 more

SOC 2 · 58

Abnormal Security, Ada, Algolia, AlphaSense, Anysphere, Appen, AssemblyAI, Baseten, Beamery, Cognition, Confluent, Copy.ai, Coveo, Demandbase, Domino Data Lab, Eightfold AI, and 42 more

GDPR · 82

6sense, Abnormal Security, Ada, Adobe, Airtable, Algolia, AlphaSense, Alteryx, Appen, Arthur AI, Asana, AssemblyAI, Automation Anywhere, Baseten, Beamery, Box, and 66 more

ISO/IEC 27001 · 77

6sense, Abnormal Security, Airtable, Algolia, AlphaSense, Alteryx, Anysphere, Appen, Asana, AssemblyAI, Automation Anywhere, Baseten, Beamery, Box, ClickHouse, Cognition, and 61 more

HIPAA · 54

Ada, Airtable, Appen, Asana, AssemblyAI, Automation Anywhere, Baseten, Box, ClickHouse, Confluent, Coveo, DataRobot, Domino Data Lab, Elastic, Encord, Fiddler AI, and 38 more

ISO/IEC 27701 · 28

Abnormal Security, Airtable, Asana, Box, ClickHouse, Confluent, Coveo, Dataminr, Eightfold AI, Freshworks, Gong, Harvey, HireVue, Intercom, Monday.com, Moveworks, and 12 more

ISO/IEC 42001 · 26

6sense, Abnormal Security, AlphaSense, Anysphere, Augment Code, Automation Anywhere, CrowdStrike, Darktrace, Eightfold AI, Glean, Gong, Harvey, Hebbia, Intercom, Moveworks, Nebius, and 10 more

SOC 3 · 22

6sense, Ada, Algolia, Asana, Baseten, Box, Confluent, Eightfold AI, Elastic, Freshworks, HubSpot, LogicMonitor, Make, Monday.com, n8n, Nebius, and 6 more

ISO/IEC 27017 · 22

Algolia, Asana, Box, Coveo, Eightfold AI, Elastic, GitLab, Gong, LogicMonitor, Monday.com, MongoDB, Moveworks, Notion, Pega, Phenom, Redis, and 6 more

ISO/IEC 27018 · 22

Asana, Box, Coveo, Darktrace, Elastic, GitLab, Gong, Intercom, LogicMonitor, Monday.com, MongoDB, Moveworks, Nebius, Notion, Pega, Phenom, and 6 more

FedRAMP · 22

Atlassian, Baseten, Box, CrowdStrike, Eightfold AI, Elastic, Freshworks, H2O.ai, HireVue, MongoDB, Moveworks, New Relic, PagerDuty, Pega, Scale AI, SentinelOne, and 6 more

PCI DSS · 18

AssemblyAI, Baseten, Box, ClickHouse, Confluent, Elastic, Gong, LiveKit, MongoDB, OpenAI, PagerDuty, Paperspace, Pega, Redis, Snowflake, Wiz, and 2 more

CSA STAR · 16

Asana, Beamery, Confluent, Elastic, Freshworks, Monday.com, MongoDB, Moogsoft, Moveworks, Nebius, OpenAI, Pega, Redis, Splunk, Workday, Zendesk

What is missing, and what that means

66 of the 186 vendors whose pages we read name no certification we could find. That is a fact about their pages, not about their security. Several publish attestations behind a trust portal that asks for an NDA, and a portal we cannot read is recorded as a page we could not read rather than as an absence.

What to ask for

The report, its period, and its scope. A Type II covering three months is a different assurance from one covering twelve, and a scope that excludes the product you are buying is common enough to check for. Ask when the current report expires and what the vendor does in the gap before the next one — the question a trust page never answers.

A trust page can also change without anyone telling you, which is why where each vendor publishes matters as much as what it says today.

Take it with you

The same tables as a Word document. It is generated when you download it, so it carries the record as it stands that day.

Get the checklist

A Word document, generated from the record when you download it. Every clause carries the page it came from and the date we read it.

How these were counted

Each row is read from a page the vendor publishes. Standards are grouped into families and levels kept separate; nothing is summed across levels and no level is inferred where a page did not state one. A standard our table does not recognize is shown under its own name rather than folded into a neighbor. How the record is kept.

Common questions

Which AI vendors are SOC 2 certified?
The vendors naming SOC 2 on their trust pages are listed here, split by whether they said Type II or left the type unstated. Naming it is not the same as holding a current report, and only the report tells you the period and the scope.
What is the difference between SOC 2 Type I and Type II?
A Type I reports that controls were designed appropriately on one date. A Type II reports that they operated effectively over a period, usually three to twelve months. A page that says only “SOC 2” has not told you which it has.
What is ISO 42001?
The AI management system standard, published in 2023. It is the newest of the standards on this page and the one whose count is worth watching, because a vendor adding it is making a claim specifically about how it manages AI.
Does a certification on a trust page mean the vendor is certified?
It means the vendor says so. Xither has not seen a report, confirmed an auditor, or checked an expiry date. Ask for the report, its period and its scope before relying on any count — including this one.
Why do some AI vendors show no certifications here?
Because nothing on the pages we read names one. Several publish their attestations behind a trust portal that asks for an NDA first, and a portal we cannot read is recorded as a page we could not read rather than as an absence.

Security questionnaires

Answer what a customer's security team asks about your AI stack.

Everything in the resources section

This is not legal advice and it is not an attestation. The pages quoted are published documents read on the dates shown in each vendor’s record; a certification named here has not been verified by Xither. The record is free to read, and corrections are free to request.