Cresta · Trust Center

Cresta Trust Center

Trust center

Cresta maintains a public trust center documenting ISO/IEC 42001, SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, GDPR, TISAX, and CCPA compliance.

AIArtificial IntelligenceContact CenterContact Center AICCaaSCustomer ExperienceConversational AIVoice AIAgent AssistConversation IntelligenceKnowledge AgentQuality ManagementReal-Time CoachingAfter-Call AutomationEnterprise AIMCPCustomer Experience AIAI AgentsgRPCSpeech AnalyticsEnterprise Software
Trust center: https://trust.cresta.com/

Certifications & Compliance

ISO/IEC 42001SOC 2 Type IIISO 27001PCI DSSHIPAAGDPRTISAXCCPA

Source

Trust Center

cresta-trust-center.yml Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://trust.cresta.com/
url: https://trust.cresta.com/
trust_page: https://cresta.com/trust
platform: SafeBase
certifications:
- ISO/IEC 42001
- SOC 2 Type II
- ISO 27001
- PCI DSS
- HIPAA
- GDPR
- TISAX
- CCPA
evidence:
- source: https://trust.cresta.com/
  keywords:
  - soc 2
  - iso/iec 27001
  - pci dss
  - hipaa
  - trust center
  - gdpr
- source: https://cresta.com/llm-info
  fetched: '2026-08-14'
  http_status: 200
  claims: >-
    "Cresta is the first Customer Experience AI provider to achieve ISO/IEC
    42001 certification — the international standard for responsible AI
    management systems. Additional certifications and frameworks include SOC 2
    Type II, HIPAA, GDPR, TISAX, CCPA, and PCI-DSS alignment."
- source: https://cresta.com/blog/cresta-achieves-tisax-compliance
  claims: TISAX compliance announcement.
- source: https://cresta.com/.well-known/security.txt
  claims: 'Policy: https://cresta.com/trust'
notes:
- >-
  Upgraded 2026-08-14 from Cresta's own first-party AI-facing page: added
  ISO/IEC 42001, TISAX and CCPA, and split SOC 2 into SOC 2 Type II. PCI DSS is
  stated by Cresta as *alignment*, not certification — retained in the list but
  qualified in conformance/cresta-conformance.yml. If 0-working/
  probe-security-programs.py is re-run it will flatten this list back to the
  five keywords it can pattern-match on the SafeBase page; re-apply this file
  rather than accept the regression.
- >-
  trust.cresta.com is a CNAMEd SafeBase tenant. Its /.well-known/
  openid-configuration and oauth-authorization-server documents carry
  "issuer": "https://app.safebase.io/api/mcp" and belong to SafeBase, not to
  Cresta. See well-known/cresta-well-known.yml.