generated: '2026-09-06'
method: searched
probe: true
url: https://trust.dremio.com/
http_status: 200
verified: '2026-09-06'
title: Dremio Corporation Trust Center
certifications:
- SOC 2 Type 2
- ISO/IEC 27001:2022
- HIPAA
evidence:
- source: https://trust.dremio.com/
status: 200
kind: trust center
note: >-
Live and titled "Dremio Corporation Trust Center". The page is JS-rendered — the served HTML
is a ~6KB shell carrying only the title — so the certification list below was read from
Dremio's public security page rather than scraped from the trust center itself. The automated
keyword probe (probe-security-programs.py) recorded trust=none for exactly that reason; this
file is the searched correction.
- source: https://www.dremio.com/platform/security/
status: 200
kind: security page
keywords:
- SOC 2 Type 2
- ISO/IEC 27001:2022
- HIPAA
- responsible disclosure
detail:
soc2: >-
Dremio maintains compliance with AICPA SOC 2 Trust Services Criteria and makes the SOC 2
Type 2 report available on request through an account or sales representative.
iso27001: >-
Dremio operates an ISMS conforming to ISO/IEC 27001:2022; the certificate is available on
request through an account or sales representative.
hipaa: >-
Dremio describes itself as HIPAA-ready, enabling covered entities and business associates to
analyze PHI on the platform. This is a readiness statement, not a certification.
security_assurance: >-
SAST and third-party dependency scanning on every build, periodic automated scans on daily
builds, and vulnerability scanning of containers and images.
security_bulletins: >-
Security notifications are published under a Security Bulletins section, with security fixes
and supply-chain/vendor/dependency responses listed in the release notes.
gap: >-
Nothing is self-serve. Both the SOC 2 report and the ISO 27001 certificate require contacting
sales, so a buyer cannot verify either without entering a sales conversation.
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.