# Attested > Which compliance certifications and attestations 64 cloud, data, AI and developer-tool vendors hold (SOC, ISO, FedRAMP, HIPAA, PCI, DPF, CSA STAR, regional programs), each backed by a source link and the date it was captured. Attested holds 807 pieces of evidence and 260 dated changes. Registry evidence comes from the FedRAMP Marketplace data (GitHub, FedRAMP/marketplace-fedramp-gov-data), the CSA STAR Registry and the Data Privacy Framework List; everything else from each vendor's own compliance or trust-center page, recorded with the sentence the vendor published. A run every Wednesday at 10:00 UTC refreshes the registries and a rotating set of vendor pages. Last successful run: 2026-09-24 02:45:53 UTC. Disclaimer: From public trust centers and registries on the date shown. Confirm scope with the vendor. Logos via logo.dev; trademarks belong to their owners. Readers can suggest corrections on any page. ## Pages - [Matrix](https://attested.fru.dev/): every vendor by every certification, filterable (e.g. https://attested.fru.dev/?has=fedramp:high,hipaa) - [Vendors](https://attested.fru.dev/vendors) - [Certifications](https://attested.fru.dev/certifications) - [Changes](https://attested.fru.dev/changes): added, upgraded and lapsed, by date - [Compare](https://attested.fru.dev/compare?v=snowflake,databricks) - [Method](https://attested.fru.dev/method) - [AI21 Labs compliance](https://attested.fru.dev/vendors/ai21-labs): SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, ISO 42001 - [Akamai compliance](https://attested.fru.dev/vendors/akamai): FedRAMP Moderate, Data Privacy Framework - [Alibaba Cloud compliance](https://attested.fru.dev/vendors/alibaba-cloud): CSA STAR Level 2, Data Privacy Framework, SOC 1 Type II, SOC 2 Type II, SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, HIPAA (BAA) - [Anthropic compliance](https://attested.fru.dev/vendors/anthropic): ISO 42001, SOC 2 Type II, SOC 3, ISO 27001, HIPAA (BAA), DoD Impact Level IL5, nist-800-171, section508, cyber-essentials , hecvat - [Asana compliance](https://attested.fru.dev/vendors/asana): FedRAMP Moderate, CSA STAR Level 1, Data Privacy Framework, SOC 2 Type II, SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, HIPAA (BAA) - [Atlassian compliance](https://attested.fru.dev/vendors/atlassian): FedRAMP Moderate, CSA STAR Level 1, Data Privacy Framework, SOC 1, SOC 2, ISO 27001, HIPAA (BAA), GovRAMP (StateRAMP), IRAP, TISAX - [AWS compliance](https://attested.fru.dev/vendors/aws): FedRAMP High, CSA STAR Level 2, Data Privacy Framework, SOC 1, SOC 2, SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701 - [Box compliance](https://attested.fru.dev/vendors/box): FedRAMP High, CSA STAR Level 1, Data Privacy Framework, HIPAA (BAA), PCI DSS, ISMAP, gxp, fips140 , itar - [ClickHouse compliance](https://attested.fru.dev/vendors/clickhouse): Data Privacy Framework, SOC 2 Type II, ISO 27001, HIPAA (BAA), PCI DSS - [Cloudflare compliance](https://attested.fru.dev/vendors/cloudflare): FedRAMP High, CSA STAR Level 1, EU Cloud Code of Conduct, Data Privacy Framework, SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, ISO 27701, HIPAA (BAA) - [Cockroach Labs compliance](https://attested.fru.dev/vendors/cockroach-labs): Data Privacy Framework, SOC 2, ISO 27001, HIPAA (BAA) - [Cohere compliance](https://attested.fru.dev/vendors/cohere): SOC 2 Type II, ISO 27001, ISO 42001, HIPAA (BAA), cyber-essentials - [Confluent compliance](https://attested.fru.dev/vendors/confluent): FedRAMP Moderate, CSA STAR Level 2, Data Privacy Framework, SOC 1 Type II, SOC 2 Type II, SOC 3, ISO 27001, ISO 27701, HITRUST , PCI DSS - [CrowdStrike compliance](https://attested.fru.dev/vendors/crowdstrike): FedRAMP High, CSA STAR Level 2, Data Privacy Framework, SOC 2, ISO 27001, ISO 42001, HIPAA (BAA), PCI DSS, CJIS, DoD Impact Level IL5 - [Databricks compliance](https://attested.fru.dev/vendors/databricks): FedRAMP High, Data Privacy Framework, SOC 1, SOC 2 Type II, SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, HIPAA (BAA) - [Datadog compliance](https://attested.fru.dev/vendors/datadog): FedRAMP High, CSA STAR Level 1, Data Privacy Framework, HIPAA (BAA) - [dbt Labs compliance](https://attested.fru.dev/vendors/dbt-labs): Data Privacy Framework, SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, HIPAA (BAA) - [DigitalOcean compliance](https://attested.fru.dev/vendors/digitalocean): CSA STAR Level 1, Data Privacy Framework, SOC 1 Type II, SOC 2 Type II, SOC 3, ISO 27001, PCI DSS, iso9001, iso22301, apec-cbpr - [Dropbox compliance](https://attested.fru.dev/vendors/dropbox): CSA STAR Level 2, EU Cloud Code of Conduct, Data Privacy Framework, SOC 1, SOC 2, SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701 - [Elastic compliance](https://attested.fru.dev/vendors/elastic): FedRAMP High, CSA STAR Level 2, Data Privacy Framework, SOC 2, SOC 3, ISO 27001, ISO 27017, ISO 27018, HIPAA (BAA), PCI DSS - [Figma compliance](https://attested.fru.dev/vendors/figma): FedRAMP Moderate, CSA STAR Level 1, CSA STAR for AI Level 1, EU Cloud Code of Conduct, Data Privacy Framework, SOC 2 Type II, SOC 3, ISO 27001, ISO 27017, ISO 27018 - [Fivetran compliance](https://attested.fru.dev/vendors/fivetran): CSA STAR Level 1, Data Privacy Framework, SOC 1, SOC 2, ISO 27001, HIPAA (BAA), HITRUST, PCI DSS - [GitHub compliance](https://attested.fru.dev/vendors/github): FedRAMP Low, CSA STAR Level 2, Data Privacy Framework, SOC 1 Type II, SOC 2 Type II, ISO 27001, PCI DSS - [GitLab compliance](https://attested.fru.dev/vendors/gitlab): FedRAMP Moderate, CSA STAR Level 1, Data Privacy Framework, SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, section508 - [Google Cloud compliance](https://attested.fru.dev/vendors/google-cloud): FedRAMP High, CSA STAR Level 2, EU Cloud Code of Conduct, Data Privacy Framework, SOC 1, SOC 2, SOC 3, ISO 27001, ISO 27017, ISO 27018 - [Groq compliance](https://attested.fru.dev/vendors/groq): SOC 2 Type II, HIPAA (BAA) - [HashiCorp compliance](https://attested.fru.dev/vendors/hashicorp): CSA STAR Level 1, Data Privacy Framework, SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, TISAX, fips140 , ens - [Hugging Face compliance](https://attested.fru.dev/vendors/hugging-face): SOC 2 Type II - [IBM compliance](https://attested.fru.dev/vendors/ibm): FedRAMP High, CSA STAR Level 2, EU Cloud Code of Conduct, Data Privacy Framework, SOC 1, SOC 2, SOC 3, ISO 27001, ISO 27017, ISO 27018 - [Informatica compliance](https://attested.fru.dev/vendors/informatica): FedRAMP Moderate, CSA STAR Level 1, Data Privacy Framework - [JFrog compliance](https://attested.fru.dev/vendors/jfrog): CSA STAR Level 1, Data Privacy Framework - [Microsoft compliance](https://attested.fru.dev/vendors/microsoft): FedRAMP High, CSA STAR Level 2, CSA STAR for AI Level 2, ISO 42001, EU Cloud Code of Conduct, Data Privacy Framework, SOC 1, SOC 2, SOC 3, ISO 27001 - [Mistral AI compliance](https://attested.fru.dev/vendors/mistral-ai): SOC 2 Type II, ISO 27001, ISO 27701, HIPAA (BAA) - [MongoDB compliance](https://attested.fru.dev/vendors/mongodb): FedRAMP Moderate, CSA STAR Level 2, Data Privacy Framework, SOC 2, ISO 27001, ISO 27017, ISO 27018, HIPAA (BAA), HITRUST, PCI DSS - [New Relic compliance](https://attested.fru.dev/vendors/new-relic): FedRAMP Moderate, CSA STAR Level 1, Data Privacy Framework, SOC 1, SOC 2, ISO 27001, ISO 42001, HIPAA (BAA), PCI DSS, TISAX - [Notion compliance](https://attested.fru.dev/vendors/notion): Data Privacy Framework, SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, ISO 27701, HIPAA (BAA), BSI C5 - [Okta compliance](https://attested.fru.dev/vendors/okta): FedRAMP High, CSA STAR Level 2, EU Cloud Code of Conduct, Data Privacy Framework - [OpenAI compliance](https://attested.fru.dev/vendors/openai): FedRAMP Moderate, CSA STAR Level 1, SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, HIPAA (BAA), PCI DSS, ferpa - [Oracle compliance](https://attested.fru.dev/vendors/oracle): FedRAMP High, CSA STAR Level 2, CSA STAR for AI Level 2, ISO 42001, EU Cloud Code of Conduct, Data Privacy Framework, SOC 1, SOC 2, SOC 3, ISO 27001 - [PagerDuty compliance](https://attested.fru.dev/vendors/pagerduty): FedRAMP Low, CSA STAR Level 1, Data Privacy Framework, SOC 2 Type II, ISO 27001, PCI DSS - [Palantir compliance](https://attested.fru.dev/vendors/palantir): FedRAMP High, CSA STAR Level 1, SOC 1 Type II, SOC 2 Type II, SOC 3, ISO 27001, ISO 27017, ISO 27018, HIPAA (BAA), CJIS - [Perplexity compliance](https://attested.fru.dev/vendors/perplexity): FedRAMP Low, Data Privacy Framework, SOC 2 Type II, ISO 27001, HIPAA (BAA), PCI DSS - [Pinecone compliance](https://attested.fru.dev/vendors/pinecone): SOC 2 Type II, HIPAA (BAA) - [Postman compliance](https://attested.fru.dev/vendors/postman): CSA STAR Level 1, Data Privacy Framework, SOC 2 Type II, ISO 27001, ISO 42001, HIPAA (BAA), PCI DSS, txramp - [Redis compliance](https://attested.fru.dev/vendors/redis): CSA STAR Level 2 - [Salesforce compliance](https://attested.fru.dev/vendors/salesforce): FedRAMP High, CSA STAR Level 1, CSA STAR for AI Level 1, ISO 42001, EU Cloud Code of Conduct, Data Privacy Framework - [SAP compliance](https://attested.fru.dev/vendors/sap): FedRAMP Moderate, CSA STAR Level 2, EU Cloud Code of Conduct, SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001, PCI DSS - [Scale AI compliance](https://attested.fru.dev/vendors/scale-ai): FedRAMP High, Data Privacy Framework, SOC 2 Type II, ISO 27001, DoD Impact Level IL4 - [ServiceNow compliance](https://attested.fru.dev/vendors/servicenow): FedRAMP High, CSA STAR Level 2, EU Cloud Code of Conduct, Data Privacy Framework, SOC 1 Type II, SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, ISO 27701 - [Slack compliance](https://attested.fru.dev/vendors/slack): FedRAMP High, Data Privacy Framework, SOC 2, SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, HIPAA (BAA) - [Snowflake compliance](https://attested.fru.dev/vendors/snowflake): FedRAMP High, CSA STAR Level 1, Data Privacy Framework, SOC 1 Type II, SOC 2 Type II, ISO 27001, ISO 42001, HIPAA (BAA), HITRUST , PCI DSS - [Snyk compliance](https://attested.fru.dev/vendors/snyk): FedRAMP Moderate, SOC 2 Type II, ISO 27001, ISO 27017, PCI DSS - [Splunk compliance](https://attested.fru.dev/vendors/splunk): FedRAMP High, CSA STAR Level 2, Data Privacy Framework, SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, HIPAA (BAA), PCI DSS - [Stripe compliance](https://attested.fru.dev/vendors/stripe): Data Privacy Framework, SOC 1, SOC 2 Type II, SOC 3, apec-cbpr - [Supabase compliance](https://attested.fru.dev/vendors/supabase): SOC 2 Type II, ISO 27001, HIPAA (BAA) - [Teradata compliance](https://attested.fru.dev/vendors/teradata): Data Privacy Framework - [Together AI compliance](https://attested.fru.dev/vendors/together-ai): SOC 2 Type II, ISO 27001 - [Twilio compliance](https://attested.fru.dev/vendors/twilio): Data Privacy Framework, SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, HIPAA (BAA), PCI DSS - [Vercel compliance](https://attested.fru.dev/vendors/vercel): Data Privacy Framework, SOC 2 Type II, ISO 27001, HIPAA (BAA), PCI DSS, TISAX - [Wiz compliance](https://attested.fru.dev/vendors/wiz): FedRAMP High, CSA STAR Level 1, SOC 2 Type II, SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, HIPAA (BAA), PCI DSS - [Workday compliance](https://attested.fru.dev/vendors/workday): FedRAMP Moderate, CSA STAR Level 1, ISO 42001, EU Cloud Code of Conduct, Data Privacy Framework, SOC 1 Type II, SOC 2 Type II, SOC 3, ISO 27001, ISO 27017 - [xAI compliance](https://attested.fru.dev/vendors/xai): CSA STAR Level 1 - [Zoom compliance](https://attested.fru.dev/vendors/zoom): FedRAMP Moderate, CSA STAR Level 2, Data Privacy Framework - [Zscaler compliance](https://attested.fru.dev/vendors/zscaler): FedRAMP High, CSA STAR Level 2, Data Privacy Framework, fips140 - [SOC 1](https://attested.fru.dev/certifications/soc1): held by 21 tracked vendors - [SOC 2](https://attested.fru.dev/certifications/soc2): held by 52 tracked vendors - [SOC 3](https://attested.fru.dev/certifications/soc3): held by 19 tracked vendors - [ISO/IEC 27001](https://attested.fru.dev/certifications/iso27001): held by 48 tracked vendors - [ISO/IEC 27017](https://attested.fru.dev/certifications/iso27017): held by 27 tracked vendors - [ISO/IEC 27018](https://attested.fru.dev/certifications/iso27018): held by 26 tracked vendors - [ISO/IEC 27701](https://attested.fru.dev/certifications/iso27701): held by 20 tracked vendors - [ISO/IEC 42001](https://attested.fru.dev/certifications/iso42001): held by 19 tracked vendors - [CSA STAR for AI](https://attested.fru.dev/certifications/csa-star-ai): held by 4 tracked vendors - [FedRAMP](https://attested.fru.dev/certifications/fedramp): held by 38 tracked vendors - [DoD Impact Level](https://attested.fru.dev/certifications/dod-il): held by 10 tracked vendors - [GovRAMP (StateRAMP)](https://attested.fru.dev/certifications/stateramp): held by 4 tracked vendors - [CJIS](https://attested.fru.dev/certifications/cjis): held by 5 tracked vendors - [HIPAA (BAA)](https://attested.fru.dev/certifications/hipaa): held by 39 tracked vendors - [HITRUST](https://attested.fru.dev/certifications/hitrust): held by 11 tracked vendors - [PCI DSS](https://attested.fru.dev/certifications/pci): held by 32 tracked vendors - [Data Privacy Framework](https://attested.fru.dev/certifications/dpf): held by 48 tracked vendors - [EU Cloud Code of Conduct](https://attested.fru.dev/certifications/eu-cloud-coc): held by 13 tracked vendors - [CSA STAR](https://attested.fru.dev/certifications/csa-star): held by 41 tracked vendors - [IRAP](https://attested.fru.dev/certifications/irap): held by 17 tracked vendors - [BSI C5](https://attested.fru.dev/certifications/c5): held by 10 tracked vendors - [ISMAP](https://attested.fru.dev/certifications/ismap): held by 13 tracked vendors - [TISAX](https://attested.fru.dev/certifications/tisax): held by 21 tracked vendors ## Data - [Sitemap](https://attested.fru.dev/sitemap.xml) - [RSS of changes](https://attested.fru.dev/rss.xml) - [Full plain-text dump](https://attested.fru.dev/llms-full.txt): one line per piece of evidence - JSON: https://attested.fru.dev/api/matrix (every cell), https://attested.fru.dev/api/evidence?vendor=&cert=, https://attested.fru.dev/api/page?path=/vendors/