Trust, risk & security
Data Security & Compliance
Publicly documented security certifications across major AI providers.
Certification coverage is uneven across the six providers tracked. Anthropic, OpenAI, Google, and Microsoft each publicly document all four benchmarks checked: SOC 2 Type II, ISO 27001, a GDPR DPA, and a HIPAA BAA, per their trust pages. Mistral AI documents three of four, with no public HIPAA BAA. Perplexity Enterprise documents only two, SOC 2 Type II and HIPAA BAA, with no confirmed ISO 27001 or GDPR DPA. A missing attestation isn't proof of a gap, but it means asking the vendor rather than assuming from a trust page.
Os dados
| Provider | SOC 2 Type II | ISO 27001 | GDPR DPA | HIPAA BAA | Source |
|---|---|---|---|---|---|
| Anthropic (Claude) | Yes | Yes | Yes | Yes | trust.anthropic.com |
| OpenAI (API & Enterprise) | Yes | Yes | Yes | Yes | trust.openai.com |
| Google (Vertex AI / Gemini Enterprise) | Yes | Yes | Yes | Yes | cloud.google.com/vertex-ai/docs/general/vertexai-compliance |
| Microsoft (Azure OpenAI) | Yes | Yes | Yes | Yes | learn.microsoft.com/azure/compliance |
| Mistral AI | Yes | Yes | Yes | - | trust.mistral.ai |
| Perplexity (Enterprise) | Yes | - | - | Yes | perplexity.ai/enterprise/security |
Dados citados - previsões de mercado de terceiros ou fatos de fornecedores documentados publicamente, obtidos dos fornecedores subjacentes.
Pesquisa relacionada
- Client Trust & SatisfactionTrust, satisfaction and reuse rates for AI across legal work products.
- Multi-Model Strategy in LegalHow many AI models firms run, and the criteria they weigh when choosing.
- Risk & Hallucination RatesEstimated error rates across legal tasks, highest for citation and jurisdiction work.