Datavant · Trust Center
Datavant Trust Center
Trust center
Datavant maintains a public trust center documenting FedRAMP Moderate, SOC 2 Type 2, HIPAA, and FIPS 140-2 compliance.
HealthcareUnited StatesInteroperabilityHealth DataDe-IdentificationTokenizationReal-World DataRecord RetrievalData ConnectivityLife SciencesHIPAAMedical RecordsRelease of InformationPrivacyOAuth 2.0Health Information Exchange
Trust center: https://trust.datavant.com/
Certifications & Compliance
FedRAMP ModerateSOC 2 Type 2HIPAAFIPS 140-2
Source
Trust Center
generated: '2026-08-14'
method: searched
probe: true
url: https://trust.datavant.com/
platform: TrustShare (TrustCloud / Kintent)
note: >-
trust.datavant.com resolves and returns HTTP 200, but the page is a client-rendered
single-page app: the HTML shell contains only a loader, and every content path
(/home, /api/v1/company, /trustshare/program-content/*) returns the same shell. The
underlying TrustShare content API (backend.trustcloud.ai) answers 401 Unauthorized
without a token, so the certification list, policy documents and subprocessor register
cannot be read anonymously - most TrustShare tenants gate document download behind an
NDA click-through. The certifications recorded below are therefore taken from Datavant's
OWN first-party public statements rather than from the trust center itself, and each one
carries the URL it was read from. This is a real trust center whose contents are not
machine-readable.
certifications:
- name: FedRAMP Moderate
status: authorized
type: Agency ATO
sponsor: National Center for Advancing Translational Sciences (NCATS), National Institutes of Health
date: '2022-12'
detail: 326 controls in place at FedRAMP Moderate.
source: https://www.datavant.com/hipaa-privacy/how-our-security-and-compliance-teams-approached-datavants-fedramp-authorization
- name: SOC 2 Type 2
status: attested
detail: >-
Named by Datavant as a pre-existing program at the time of the FedRAMP effort
("we went from having programs like SOC 2 - Type 2, where we had 50 security
controls in place, to FedRAMP Moderate").
source: https://www.datavant.com/hipaa-privacy/how-our-security-and-compliance-teams-approached-datavants-fedramp-authorization
- name: HIPAA
status: program
detail: >-
HIPAA Expert Determination de-identification is a productised Datavant capability
(Datavant Connect - Privacy), and Datavant maintains a HIPAA privacy content hub.
source: https://www.datavant.com/hipaa-privacy
- name: FIPS 140-2
status: referenced
detail: Cited as a cryptographic-module requirement met as part of the FedRAMP authorization.
source: https://www.datavant.com/hipaa-privacy/how-our-security-and-compliance-teams-approached-datavants-fedramp-authorization
security_investment:
amount_usd_per_year: 40000000
quote: '"invest more than $40 million annually in security and compliance infrastructure"'
source: https://www.datavant.com/about/privacy-compliance
related_pages:
- url: https://www.datavant.com/about/privacy-compliance
title: Privacy and Compliance
http_status: 200
- url: https://www.datavant.com/hipaa-privacy
title: HIPAA Privacy hub
http_status: 200
- url: https://www.datavant.com/report-vulnerabilities
title: Report Software Vulnerabilities
http_status: 200
- url: https://www.datavant.com/international-privacy
title: International Privacy
http_status: 200
evidence:
- source: https://trust.datavant.com/
http_status: 200
kind: trust-center
keywords: [trustshare, trust center]
note: JS-rendered shell; no certification text present in the served HTML.
fetched: '2026-08-14'
- source: https://backend.trustcloud.ai/trustshare/program-content/datavant
http_status: 401
kind: trust-center-api
note: '{"error":"Unauthorized","debug":"Missing authorization token."}'
fetched: '2026-08-14'
- source: https://www.datavant.com/hipaa-privacy/how-our-security-and-compliance-teams-approached-datavants-fedramp-authorization
http_status: 200
kind: first-party-blog
keywords: [fedramp moderate, agency ato, soc 2 type 2, fips 140-2]
fetched: '2026-08-14'