Liberate Innovations · Trust Center

Liberate Innovations Trust Center

Trust center

Liberate publishes a dedicated security page naming its compliance certifications and links out to a hosted Vanta trust center. Because Liberate sells into insurance carriers and agencies and handles claims data over voice, its published posture leans on HIPAA, SOC 2, and PCI DSS.

Liberate Innovations maintains a public trust center documenting SOC 2, HIPAA, PCI DSS, GDPR, CCPA, ISO 27001, and FedRAMP compliance.

CompanyInsuranceInsurTechArtificial IntelligenceVoice AIConversational AIWorkflow OrchestrationClaims AutomationIntegrationContact Center
Trust center:

Certifications & Compliance

SOC 2HIPAAPCI DSSGDPRCCPAISO 27001FedRAMP

Source

Trust Center

Raw ↑
generated: '2026-07-19'
method: searched
source: https://www.liberateinc.com/security
name: Liberate trust center
description: >-
  Liberate publishes a dedicated security page naming its compliance certifications and links out to
  a hosted Vanta trust center. Because Liberate sells into insurance carriers and agencies and
  handles claims data over voice, its published posture leans on HIPAA, SOC 2, and PCI DSS.

trust_center:
  published: true
  url: https://app.vanta.com/liberateinc.com/trust/a3f4px3jh3gd2prixhl6
  platform: Vanta
  status: 200
  public_access: true
  note: >-
    The Vanta-hosted trust center renders client-side, so the certification list below was read from
    Liberate's own security page rather than scraped from the trust center document. Report
    downloads on Vanta trust centers are typically gated behind an NDA request.

security_page:
  url: https://www.liberateinc.com/security
  status: 200

certifications:
  - name: SOC 2
    claimed: true
    type: not specified (Type I vs Type II not stated publicly)
    evidence: >-
      "Liberate provides enterprise-grade security with certifications in HIPAA, SOC 2, PCI, and
      GDPR" and "Our SOC2 certification verifies our strong security measures."
  - name: HIPAA
    claimed: true
    evidence: Named in the certifications list on the security page.
  - name: PCI DSS
    claimed: true
    evidence: "SOC2, CCPA, HIPAA, and PCI DSS certifications give you peace of mind."
  - name: GDPR
    claimed: true
    type: regulatory compliance (not a certification)
    evidence: Named in the certifications list on the security page.
  - name: CCPA
    claimed: true
    type: regulatory compliance (not a certification)
    evidence: >-
      Named in the certifications list; a dedicated CCPA notice is published at
      https://signup.liberateinc.com/ccpa
  - name: ISO 27001
    claimed: false
  - name: FedRAMP
    claimed: false

controls_published:
  - name: Role and attribute-based access control
    detail: >-
      Role-based access controls restrict data access to authorized users; role and attribute-based
      permissions allow customization within a single role.
  - name: Project-based permissions
    detail: Teams can be granted access to specific information within a shared project.
  - name: Encryption in transit and at rest
    detail: >-
      All data, including third-party sourced data, is encrypted. Integration credentials are
      encrypted both in transit and at rest.
  - name: Single-tenant data isolation
    detail: >-
      "Unlike typical multi-tenant systems, Liberate never mixes your data with that of other
      customers." Each organization is given its own instance.
  - name: Audit logging
    detail: >-
      Amazon CloudTrail logs and tracks account activity across the AWS infrastructure, providing
      change attribution and the ability to revert to previous versions.
  - name: Penetration testing
    detail: Liberate states it regularly conducts penetration tests.
  - name: Single sign-on
    detail: SAML SSO brokered through Amazon Cognito. See authentication/liberate-innovations-authentication.yml.
  - name: Backups
    detail: Named among data security practices on the security FAQ.

infrastructure:
  cloud: AWS
  region_evidence: >-
    us-west-2 appears in the documented Cognito ACS URL format
    (https://<tenant>.auth.us-west-2.amazoncognito.com/saml2/idpresponse).
  evidence_url: https://docs.liberateinc.com/docs/google-workspace

privacy:
  privacy_policy: https://www.liberateinc.com/legal/privacy-policy
  privacy_policy_effective: '2024-10-15'
  terms_of_service: https://www.liberateinc.com/legal/terms-of-service
  ccpa_notice: https://signup.liberateinc.com/ccpa
  legal_entity: Liberate Innovations, Inc.