Which certifications each vendor publishes

    We record the certification each vendor claims on its own pages and nothing more. A published claim is not a verified certificate, and an absent claim is not evidence a vendor lacks one. Always ask for the certificate itself.

    33 of 39 vendors publish somethingLast checked 25 Sept 2026
    This tracker records only what each vendor has published on its own public pages. It is not an assessment, audit, certification or endorsement. Vendors change their documentation — always verify directly before making a procurement decision.

    What is on the public record

    What certifications does Abridge publish?Ambient scribe
    SummaryChecked 25 Sept 2026
    SOC 2 Type 1, SOC 2 Type 2, HIPAA, CCPA and TX-RAMP listed on trust centre
    “Our products are covered by a SOC 2 Type 2 report, validated by an independent third-party auditor for security and confidentiality.”
    trust.abridge.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Amazon Connect (Amazon Web Services) publish?Contact centre (CCaaS)
    SummaryChecked 25 Sept 2026
    AWS lists Amazon Connect on its Services in Scope by Compliance Program page for IRAP.
    “Amazon Connect”
    aws.amazon.com
    SummaryChecked 28 July 2026
    Amazon Connect listed on the AWS HIPAA Eligible Services Reference. AWS states an AWS business associate agreement must be entered into before using HIPAA Eligible Services with Protected Health Information.
    “without first entering into an AWS business associate agreement”
    aws.amazon.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Anthropic publish?Foundation model
    SummaryChecked 25 Sept 2026
    ISO/IEC 42001:2023 accredited certification (AI management system), announced Jan 2025
    “Anthropic has achieved accredited certification under the new ISO/IEC 42001:2023 standard for our AI management system”
    www.anthropic.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does AutoMed Systems publish?Platform / infrastructure
    SummaryChecked 25 Sept 2026
    Australian Privacy Principles / Privacy Act 1988 (Cth) adopted
    “We have adopted the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth)”
    automedsystems.com.au

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Cisco Webex Contact Center publish?Contact centre (CCaaS)
    SummaryChecked 25 Sept 2026
    Webex stated as ISO/IEC 27001:2013 certified. The same page addresses GDPR and states Webex can be used in a healthcare environment consistent with customer needs for HIPAA compliance. The page covers Webex generally and does not separately delineate Webex Contact Center.
    “Webex is ISO/IEC 27001:2013 certified.”
    help.webex.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Cognigy (NiCE Cognigy) publish?Voice agent
    SummaryChecked 25 Sept 2026
    Vendor announced completion of a SOC 2 Type II audit performed by KirkpatrickPrice (announcement dated October 2020).
    “today announced that it has completed its SOC 2 Type II audit, performed by KirkpatrickPrice.”
    www.cognigy.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Corti publish?Ambient scribe
    SummaryChecked 25 Sept 2026
    Safety page states Corti's security meets or exceeds market and regulatory requirements, including compliance with several strict frameworks, and displays framework logos (images without text labels) for ISO 27001, ISO 27017, ISO 27018, ISO 42001, ISO 13485, ISO 14971, ISO 62366, SOC 2, HIPAA, GDPR, CE, NHS DSPT, NHS DTAC, NHS DCB0129, Cyber Essentials Plus, EU AI Act, NIS2, DORA, ISAE 3000, BSI C5, US FedRAMP and EU-U.S. Privacy Shield.
    “Corti ensures that its security meets or exceeds market and regulatory requirements, including compliance with several strict frameworks.”
    corti.ai

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Coviu publish?Platform / infrastructure
    SummaryChecked 25 Sept 2026
    Business Associate Agreements available to eligible customers (HIPAA)
    “Business Associate Agreements (BAAs) are available to eligible customers.”
    www.coviu.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Curious Thing publish?Voice agent
    SummaryChecked 25 Sept 2026
    Vendor states ISO 27001 and SOC 2 certification and GDPR and HIPAA compliance. No certificate numbers or audit dates given.
    “Stay secure with ISO 27001 and SOC 2 certification and GDPR and HIPAA compliant.”
    curiousthing.io

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Decagon publish?Voice agent
    SummaryChecked 28 July 2026
    Vendor states SOC 2 Type II compliance and HIPAA options. Security page additionally displays compliance badges (GDPR, CCPA, EU AI Act, HIPAA, SOC 2, ISO, PCI) as images without accompanying text.
    “Built with security at its core, the platform includes SOC 2 Type II compliance, HIPAA options, and strict guardrails for sensitive actions like refunds.”
    decagon.ai

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Five9 publish?Contact centre (CCaaS)
    SummaryChecked 25 Sept 2026
    Trust page states '88 Certifications' as a metric; individual certifications are not itemised on the public page
    “88 Certifications”
    www.five9.com
    SummaryChecked 25 Sept 2026
    Five9 states it acts as a HIPAA Business Associate and has implemented administrative, physical and technical safeguards for protected health information.
    “As a Business Associate, Five9 has designed and implemented appropriate administrative, physical, and technical safeguards for protected health information.”
    www.five9.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Genesys publish?Contact centre (CCaaS)
    SummaryChecked 25 Sept 2026
    Listed under Authorizations: IRAP Protected (also FedRAMP, GovRAMP, TX-RAMP, DoD Impact Level (IL) 2, ACN, DESC). HIPAA listed under Laws/Frameworks.
    “IRAP Protected”
    www.genesys.com
    SummaryChecked 25 Sept 2026
    Genesys Cloud security policy page references compliance with ISO 27001, SOC 2 and GDPR; also EU-U.S. Data Privacy Framework certification in privacy policy
    “compliance with standards like ISO 27001, SOC 2, and GDPR”
    help.genesys.cloud

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Google (Gemini / Cloud AI) publish?Foundation model
    SummaryChecked 25 Sept 2026
    Google Cloud compliance offerings incl. ISO/IEC 27001, 27017, 27018, 27701, 42001, SOC 1/2/3, PCI DSS
    “ISO/IEC 27001 | ISO/IEC 27017 | ISO/IEC 27018 | ISO/IEC 27701 | ISO/IEC 42001 | PCI 3DS Core Security Standard | PCI DSS | PCI PIN Security | SOC 1 | SOC 2 | SOC 3”
    cloud.google.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does HealthEngine publish?Voice agent
    SummaryChecked 25 Sept 2026
    Vendor states it earned ISO 27001 certification for Information Security Management Systems in October 2022
    “Healthengine earned ISO 27001 Certification for Information Security Management Systems in October 2022.”
    privacy.healthengine.com.au

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Heidi Health publish?Ambient scribe
    SummaryChecked 25 Sept 2026
    ISO 27001, ISO 42001, SOC 2 stated as credentials; regional regulatory requirements stated as HIPAA, GDPR, PIPEDA and APP.
    “Our credentials include ISO 27001, ISO 42001, and SOC2 compliance, and we meet regional regulatory requirements including HIPAA, GDPR, PIPEDA, and APP.”
    support.heidihealth.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does HotDoc publish?Platform / infrastructure
    SummaryChecked 25 Sept 2026
    SOC 2 Type II accreditation; compliance with Australian Privacy Principles and Privacy Act stated
    “SOC 2 Type II accreditation”
    practices.hotdoc.com.au

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does i-scribe by Akuru (Akuru Clinical Intelligence) publish?Ambient scribe
    SummaryChecked 25 Sept 2026
    Vendor states ISO/IEC 27001:2022 certification, certificate number 1446-I-1, issued 24 April 2026, expiring 23 April 2029, audited by Global Compliance Certification Pty Ltd (GCC). No SOC 2 or IRAP statement found on vendor-published pages.
    “ISO/IEC 27001:2022 certified — Certificate number 1446-I-1, issued 24 April 2026, expires 23 April 2029. Audited by Global Compliance Certification Pty Ltd (GCC)”
    www.i-scribe.com.au

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does IntelliTek Health publish?Platform / infrastructure
    SummaryChecked 25 Sept 2026
    Homepage states it is HIPAA-compliant; no linked privacy policy, security page or trust centre found on the pages checked
    “HIPAA-compliant and secure with robust data protection”
    intellitekhealth.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Lyngo AI publish?Voice agent
    SummaryChecked 25 Sept 2026
    Privacy policy says it takes into account the requirements of the Privacy Act 1988 (Cth) and the Australian Privacy Principles, as well as the New Zealand Privacy Act 2020 and the Information Privacy Principles. No ISO 27001, SOC 2, IRAP or HIPAA certification is stated on the pages checked.
    “This Privacy Policy takes into account the requirements of the Privacy Act 1988 (Cth) and the Australian Privacy Principles, as well as the New Zealand Privacy Act 2020 and the Information Privacy Principles.”
    lyngo.notion.site

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Lyrebird Health publish?Ambient scribe
    SummaryChecked 25 Sept 2026
    Alignment with APP, HIPAA and GDPR stated on compliance page; encryption in transit and at rest
    “Aligned with APP, HIPAA, and GDPR.”
    www.lyrebirdhealth.com
    SummaryChecked 25 Sept 2026
    ISO 27001 certification announced by the vendor on 6 July 2026. Vendor states alignment with APP, HIPAA and GDPR. No SOC 2 or IRAP statement found on vendor-published pages.
    “Lyrebird Health is ISO 27001 Certified Clinical AI Platform”
    www.lyrebirdhealth.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Medow Health AI publish?Ambient scribe
    SummaryChecked 25 Sept 2026
    ISO 27001 certified; compliance stated with Privacy Act 1988/APPs (AU), Privacy Act 2020/HIPC (NZ) and PDPA (Singapore); AES-256 encryption
    “ISO 27001 Certified”
    medowhealth.ai

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Microsoft Azure AI publish?Platform / infrastructure
    SummaryChecked 25 Sept 2026
    ISO/IEC 27001 and HITRUST CSF: BAA-covered Microsoft services are audited by accredited independent auditors for these certifications.
    “undergo audits conducted by accredited independent auditors for the Microsoft ISO/IEC 27001 certification and the HITRUST Common Security Framework (CSF) certification”
    learn.microsoft.com
    SummaryChecked 25 Sept 2026
    IRAP: Microsoft states ACSC certification of Azure and Office 365 at the PROTECTED classification (April 2018), with the September 2019 assessment scope covering 113 services at PROTECTED, and further incremental Azure/Dynamics and Office 365 assessments completed December 2020.
    “In April 2018, the ACSC announced the certification of Azure and Office 365 at the PROTECTED classification.”
    learn.microsoft.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Microsoft Dragon Copilot publish?Ambient scribe
    SummaryChecked 25 Sept 2026
    Azure-platform compliance cited in Dragon Copilot security white paper: HITRUST CSF, HIPAA, ISO 27001/27017/27018, FedRAMP, SOC 1/2/3, GDPR, C5 (Germany), HDS (France), revFADP (Switzerland), Cyber Essentials Plus (UK)
    “Microsoft Azure supports compliance efforts related to more than 65 national, regional, and industry-specific requirements governing the collection and use of individuals' data”
    learn.microsoft.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Nabla publish?Ambient scribe
    SummaryChecked 25 Sept 2026
    Vendor states it follows HIPAA, GDPR, SOC 2, ISO 27001 and NIST cybersecurity standards for security and privacy
    “Nabla follows HIPAA, GDPR, SOC2, ISO27001 and NIST Cybersecurity standards for security and privacy.”
    trust.nabla.com
    SummaryChecked 25 Sept 2026
    HIPAA and GDPR compliance and ISO 27001 / SOC 2 Type II certification stated on the EHR integration page.
    “HIPAA and GDPR Compliant. Certified for ISO 27001 and SOC 2 Type II.”
    nabla.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does OpenAI publish?Foundation model
    SummaryChecked 25 Sept 2026
    SOC 2 Type 2 report; ISO 27001, 27017, 27018 and 27701 certified (per OpenAI Trust Portal)
    “Our products are also ISO 27001, 27017, 27018, and 27701 certified.”
    trust.openai.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does PatientNotes publish?Ambient scribe
    SummaryChecked 25 Sept 2026
    HIPAA compliance stated (BAAs signed with paid customers); compliance with Australian Privacy Principles APP 1-13 stated; AES-256 at rest, TLS 1.3 in transit
    “Compliant with Australian Privacy Principles (APP 1-13)”
    www.patientnotes.ai

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does PolyAI publish?Voice agent
    SummaryChecked 25 Sept 2026
    Vendor states it is certified for ISO/IEC 27001, the international standard for information security management systems.
    “We are certified for ISO/IEC 27001, the international standard for information security management systems (ISMS).”
    docs.poly.ai

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Sierra publish?Voice agent
    SummaryChecked 25 Sept 2026
    Vendor states it is committed to maintaining compliance standards including SOC 2, HIPAA, GDPR, PCI, FedRAMP High, CCPA, CSA STAR, ISO 27001 and ISO 42001.
    “Sierra is committed to maintaining the highest compliance standards for our customers, including SOC 2, HIPAA, GDPR, PCI, FedRAMP High, CCPA, CSA STAR, ISO 27001, and ISO 42001.”
    sierra.ai

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Sophiie AI publish?Voice agent
    SummaryChecked 28 July 2026
    Privacy policy states the company maintains alignment with ISO 27001 compliance standards. No certification body, audit report or scope is stated.
    “We use multi-factor authentication, advanced threat detection systems, and maintain alignment with ISO 27001 compliance standards.”
    www.sophiie.ai

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Suki publish?Ambient scribe
    SummaryChecked 25 Sept 2026
    SOC 2 Type 2 certified and HIPAA compliant (stated on website)
    “Our platform not only boasts a robust security posture, but is also infinitely scalable, SOC2 Type 2 certified, and HIPAA compliant to support the largest organizations in the industry.”
    www.suki.ai

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Tortus publish?Ambient scribe
    SummaryChecked 25 Sept 2026
    ISO 13485; UKCA Class IIa Medical Device; NHS DTAC; ISO 27001 ISMS also referenced in privacy policy
    “ISO 13485 · UKCA Class IIa Medical Device · NHS DTAC compliant”
    tortus.ai

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does VoiceStack publish?Voice agent
    SummaryChecked 12 Aug 2026
    Website states certification against Australian Privacy Principles, HIPAA standards, SOC 2, PCI and ISO 27001
    “Australian Privacy Principles, HIPAA standards, SOC 2, PCI, and ISO 27001: certified. We meet the highest security standards globally.”
    voicestack.com

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    What certifications does Voxworks publish?Voice agent
    SummaryChecked 25 Sept 2026
    Security documentation states the company aligns its security practices with ISO 27001; no certification, certificate number or audit body is stated in that documentation.
    “Voxworks also aligns its security practices with ISO 27001, the international standard for information security management systems.”
    docs.voxworks.ai

    Answered from what the vendor publishes on its own public pages, or from an official register where noted, as at the check date shown. Not an assessment, audit, certification or endorsement.

    Not found on public pages

    We could not find this on the vendor's public pages as at the check date. This is not a statement that the vendor lacks the capability or has not disclosed it elsewhere.

    Right of reply

    Something wrong or out of date?

    Are we missing something, or has this changed? Vendors and their representatives can submit a correction, and we note each change and credit the source. We review every correction request and update the entry when the source supports it.

    Submit a correction