23andMe · Trust Center

23Andme Trust Center

Trust center

23andMe maintains a public trust center documenting HIPAA Compliance, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27018, Genetic Information Nondiscrimination Act (GINA), General Data Protection Regulation (GDPR), State Consumer Privacy & Health Privacy Laws (U.S.), FDA Authorization, and Common Rule compliance.

CompanyHealth TechGeneticsGenomicsDNA TestingAncestryConsumer HealthBioinformaticsPrecision MedicinePharmacogenomicsTelehealthHealth Research
Trust center: https://www.23andme.org/trust-center/

Certifications & Compliance

HIPAA ComplianceISO/IEC 27001ISO/IEC 27701ISO/IEC 27018Genetic Information Nondiscrimination Act (GINA)General Data Protection Regulation (GDPR)State Consumer Privacy & Health Privacy Laws (U.S.)FDA AuthorizationCommon Rule

Source

Trust Center

23andme-trust-center.yml Raw ↑
generated: '2026-08-15'
method: searched
probe: true
source: https://www.23andme.org/trust-center/
url: https://www.23andme.org/trust-center/
note: >-
  Upgraded on 2026-08-15 from the live first-party Trust Center. The prior record
  pointed at trust.23andme.com, which now 301s to trust.23andme.org and answers a
  Cloudflare managed challenge (403) to anonymous requests. The certification list
  below was read verbatim from the "Compliance — Certifications, Regulations and
  Standards" section of the canonical Trust Center page.
certifications:
- HIPAA Compliance
- ISO/IEC 27001
- ISO/IEC 27701
- ISO/IEC 27018
- Genetic Information Nondiscrimination Act (GINA)
- General Data Protection Regulation (GDPR)
- State Consumer Privacy & Health Privacy Laws (U.S.)
- FDA Authorization
- Common Rule
lab_accreditations:
- CLIA-certified U.S. laboratories (genotyping and exome sequencing)
- CAP-accredited (Total Health exome processing)
audit:
  scheme: ISO/IEC 27001 / 27701 / 27018
  systems:
  - Information Security Management System (ISMS)
  - Privacy Information Management System (PIMS)
  cadence: annual
  auditor: accredited third party
  quote: >-
    "23andMe's ISMS and PIMS are audited by an accredited third party on an annual
    basis."
  penetration_testing: >-
    "we hire outside experts to perform extensive annual penetration tests on our
    systems."
superseded:
  previous_url: https://trust.23andme.com/
  previous_status: 301
  redirects_to: https://trust.23andme.org/
  redirect_status: 403
  removed_claim: PCI DSS
  removed_claim_note: >-
    A prior pass recorded PCI DSS from the legacy trust portal. It is NOT among the
    nine certifications named on the current first-party Trust Center and could not be
    re-verified on 2026-08-15, so it has been moved to conformance/ as `unknown`
    rather than carried forward.
evidence:
- source: https://www.23andme.org/trust-center/
  status: 200
  keywords:
  - hipaa compliance
  - iso/iec 27001
  - iso/iec 27701
  - iso/iec 27018
  - fda authorization
  - common rule
- source: https://www.23andme.org/security/
  status: 200
  keywords:
  - certified under the global iso/iec 27001, 27701, and 27018 standards
  - information security management system
  - privacy information management system

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/23andme-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.