Trust, risk & security
Data Security & Compliance
Publicly documented security certifications across major AI providers.
مقتبسمحدث 2026-07-08
Certification coverage is uneven across the six providers tracked. Anthropic, OpenAI, Google, and Microsoft each publicly document all four benchmarks checked: SOC 2 Type II, ISO 27001, a GDPR DPA, and a HIPAA BAA, per their trust pages. Mistral AI documents three of four, with no public HIPAA BAA. Perplexity Enterprise documents only two, SOC 2 Type II and HIPAA BAA, with no confirmed ISO 27001 or GDPR DPA. A missing attestation isn't proof of a gap, but it means asking the vendor rather than assuming from a trust page.
البيانات
| Provider | SOC 2 Type II | ISO 27001 | GDPR DPA | HIPAA BAA | Source |
|---|---|---|---|---|---|
| Anthropic (Claude) | Yes | Yes | Yes | Yes | trust.anthropic.com |
| OpenAI (API & Enterprise) | Yes | Yes | Yes | Yes | trust.openai.com |
| Google (Vertex AI / Gemini Enterprise) | Yes | Yes | Yes | Yes | cloud.google.com/vertex-ai/docs/general/vertexai-compliance |
| Microsoft (Azure OpenAI) | Yes | Yes | Yes | Yes | learn.microsoft.com/azure/compliance |
| Mistral AI | Yes | Yes | Yes | - | trust.mistral.ai |
| Perplexity (Enterprise) | Yes | - | - | Yes | perplexity.ai/enterprise/security |
بيانات مقتبسة - توقعات سوق طرف ثالث أو حقائق موثقة علنًا عن البائعين، مستقاة من الموفرين الأساسيين.
أبحاث ذات صلة
- Client Trust & SatisfactionTrust, satisfaction and reuse rates for AI across legal work products.
- Multi-Model Strategy in LegalHow many AI models firms run, and the criteria they weigh when choosing.
- Risk & Hallucination RatesEstimated error rates across legal tasks, highest for citation and jurisdiction work.