Ada · Trust Center

Ada Trust Center

Trust center

Ada maintains a public trust center documenting SOC 2 Type 2, SOC 3, PCI DSS (Attestation of Compliance), HIPAA, GDPR, CCPA, CPRA, PIPEDA, and VPAT 2024 (WCAG 2.1 AA) compliance.

Artificial IntelligenceCustomer ServiceChatbotsAutomationConversational AIHelp DeskCRMIntegrationKnowledge-ManagementData Export
Trust center: https://security.ada.cx/

Certifications & Compliance

SOC 2 Type 2SOC 3PCI DSS (Attestation of Compliance)HIPAAGDPRCCPACPRAPIPEDAVPAT 2024 (WCAG 2.1 AA)

Source

Trust Center

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://security.ada.cx/
url: https://security.ada.cx/
vendor: SafeBase (by Drata)
access:
  public: partial
  note: >-
    Certification names, validity windows and security ratings are public. The underlying reports
    (SOC 2 Type 2, SOC 3, PCI AoC, VPAT) sit behind a "Request Access" gate, and full access
    requires naming a valid Ada point of contact.
framework: Center for Internet Security Cybersecurity Framework v8.0 (CIS 8.0)
certifications:
- SOC 2 Type 2
- SOC 3
- PCI DSS (Attestation of Compliance)
- HIPAA
- GDPR
- CCPA
- CPRA
- PIPEDA
- VPAT 2024 (WCAG 2.1 AA)
certification_detail:
- name: SOC 2 Type 2
  period: 2023-10-01 to 2024-09-30
  gated: true
- name: SOC 3
  period: 2023-10-01 to 2024-09-30
  gated: true
- name: PCI DSS
  form: Attestation of Compliance
  gated: true
- name: VPAT
  version: 2024, WCAG 2.1 AA
  gated: true
privacy_regimes:
- GDPR
- CCPA
- CPRA
- PIPEDA
- HIPAA
security_ratings:
- provider: SecurityScorecard
  grade: A
  domains:
  - ada.cx
  - ada.support
- provider: Qualys SSL Labs
  grade: A
  domains:
  - ada.cx
  - ada.support
- provider: UpGuard
  score: 850
  domains:
  - ada.cx
not_observed:
- ISO 27001
- ISO 27017
- ISO 27018
- FedRAMP
- CSA STAR
- FIPS 140
evidence:
- source: https://security.ada.cx/
  fetched: '2026-08-14'
  http_status: 200
  keywords:
  - soc 2 type 2
  - soc 3
  - pci dss
  - hipaa
  - gdpr
  - ccpa
  - cpra
  - pipeda
  - vpat
  - trust center
  note: >-
    The origin bot-challenges plain curl (403); the page was read with a rendering fetch. The
    /.well-known/openid-configuration and /.well-known/oauth-authorization-server documents this
    host serves declare issuer https://app.safebase.io/api/mcp — they belong to the SafeBase
    platform, not to Ada, and are recorded as such in well-known/ada-well-known.yml.
supersedes:
  generated: '2026-07-11'
  certifications:
  - SOC 2
  - HIPAA
  - GDPR
  note: >-
    The 2026-07-11 keyword probe found three certifications. This pass read the rendered trust
    centre and found nine, plus the CIS 8.0 framework, the SOC report windows and three
    third-party security ratings.