Method
Where each square comes from, how it is read, and what it cannot tell you.
FedRAMP Marketplace data
RegistryThe JSON behind marketplace.fedramp.gov and its status changelog: every offering, its impact level, authorization date and history. Authoritative for FedRAMP.
Last read Sep 23, 2026 · Source
CSA STAR Registry
RegistrySTAR Level 1 and 2, STAR for AI, and partner entries for ISO/IEC 42001 and the EU Cloud Code of Conduct, with the date each company was first listed.
Last read Sep 23, 2026 · Source
Data Privacy Framework List
RegistryEach company's EU-US, UK and Swiss certification status, the date it certified and when recertification is due.
Last read Sep 23, 2026 · Source
Vendor compliance pages
Vendor statementEverything else: the vendor's own trust center or compliance page, read as text. The sentence that names the certification is stored with the date it was read.
55 pages read · Source
How to read a square
Held means the registry lists the vendor as authorized or certified, or the vendor's own compliance page names the certification as one it holds. The white dot marks registry evidence. Darker green is a stronger level (FedRAMP High over Moderate, SOC 2 Type II over Type I, STAR Level 2 over Level 1).
In process is FedRAMP In Process or Ready. Lapsed is a withdrawn or expired registry entry, or a vendor page that says it no longer holds it.
A vendor page is matched by the certification's name and kept with the sentence it appeared in. Pages that only name a standard as something customers are responsible for, or as "readiness", are set aside by hand or by a model check; new matches show Unverified until reviewed.
Most trust centers (Vanta, SafeBase and similar) render their lists with JavaScript. Those are read in a browser when the site is refreshed by hand; plain pages are re-read by the weekly run, Wednesday 10:00 UTC, along with every registry.
Scope matters. A certification usually covers named products, regions or a government cloud, not everything a company sells. From public trust centers and registries on the date shown. Confirm scope with the vendor.
Questions
What is Attested?
Attested is a grid of which certifications and attestations data, AI, cloud and developer-tool vendors hold: SOC 1, 2 and 3, ISO 27001, 27017, 27018, 27701 and 42001, HIPAA, HITRUST, PCI DSS, FedRAMP, DoD Impact Levels, GovRAMP, CJIS, the Data Privacy Framework, CSA STAR, IRAP, C5, ISMAP and TISAX. Every cell links to the evidence and the date it was captured.
Where does the data come from?
From public registries where they exist (the FedRAMP Marketplace data, the CSA STAR Registry and the Data Privacy Framework List) and otherwise from each vendor's own compliance or trust-center page. Registry entries are authoritative; vendor-page entries record the sentence the vendor published.
How often is it updated?
A run every Wednesday at 10:00 UTC re-reads the FedRAMP data and status history, the STAR Registry, the DPF List and a rotating set of vendor pages. What changed goes into the change log with its date.
Which AI vendors are FedRAMP authorized?
Filter the grid by FedRAMP: OpenAI (ChatGPT Enterprise and API Platform, FedRAMP 20x Moderate), Perplexity (20x Low), Scale AI and Palantir (High), and Google's Gemini for Government (20x Low) are listed in the FedRAMP Marketplace. Claude reaches federal agencies through AWS GovCloud and Google Cloud authorizations.
Which companies are ISO 42001 certified?
Open the ISO/IEC 42001 page: it lists every tracked vendor that names the AI management system certification on its compliance page or in the CSA STAR Registry, including Microsoft, AWS, Google Cloud, Anthropic, OpenAI, Snowflake and Workday.
Is HIPAA a certification?
No. There is no HIPAA certificate. The HIPAA column records whether a vendor says it supports HIPAA-regulated data and signs a Business Associate Agreement, and for which products; confirm the BAA scope with the vendor.
Does a SOC 2 listing mean I can see the report?
No. SOC 1 and SOC 2 reports are shared under NDA through the vendor's trust center. SOC 3 is the public summary. Attested records that the vendor states it has the report, with a link to where to request it.