Oracle Cloud Infrastructure · Trust Center

Oracle Cloud Trust Center

Trust center

Oracle Cloud Infrastructure maintains a public trust center documenting SOC 1, SOC 2, SOC 3, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, PCI DSS, HIPAA, HITRUST, FedRAMP, DoD Impact Levels, CJIS, ITAR, IRAP, C5, ENS, HDS, G-Cloud / Cyber Essentials, ISMAP, K-ISMS, MTCS, TISAX, CSA STAR, CSA AI STAR, GDPR, and NIST compliance.

Cloud ComputingEnterprise CloudInfrastructure-as-a-ServiceOraclePlatform-as-a-ServiceComputeObject StorageIdentity and Access ManagementDatabaseKubernetesServerlessMonitoringEvent-Driven
Trust center: https://www.oracle.com/corporate/cloud-compliance/

Certifications & Compliance

SOC 1SOC 2SOC 3ISO/IEC 27001ISO/IEC 27017ISO/IEC 27018ISO/IEC 27701PCI DSSHIPAAHITRUSTFedRAMPDoD Impact LevelsCJISITARIRAPC5ENSHDSG-Cloud / Cyber EssentialsISMAPK-ISMSMTCSTISAXCSA STARCSA AI STARGDPRNIST

Source

Trust Center

Raw ↑
generated: '2026-08-29'
method: searched
source: >-
  https://www.oracle.com/corporate/cloud-compliance/ (reached via a 301 from
  https://www.oracle.com/cloud/compliance/), plus
  https://www.oracle.com/corporate/security-practices/
provider: Oracle Cloud Infrastructure
providerId: oracle-cloud
trust_center_published: true
url: https://www.oracle.com/corporate/cloud-compliance/
alternate_urls:
  - https://www.oracle.com/cloud/compliance/
  - https://www.oracle.com/corporate/security-practices/
probed: '2026-08-29'
http_status: 200
model: >-
  Oracle publishes "attestations" — third-party certifications and audit reports — grouped by line
  of business (Oracle Cloud Infrastructure, Oracle Applications, NetSuite, Oracle Industries,
  Oracle Health) and by framework. Attestation reports are obtained through an Oracle sales
  representative; they are not self-service downloads, and Oracle notes each attestation "may also
  be specific to a certain data center or geographic region."
certifications:
  - {name: SOC 1, scope: attestation}
  - {name: SOC 2, scope: attestation}
  - {name: SOC 3, scope: attestation}
  - {name: ISO/IEC 27001, scope: certification}
  - {name: ISO/IEC 27017, scope: certification}
  - {name: ISO/IEC 27018, scope: certification}
  - {name: ISO/IEC 27701, scope: certification}
  - {name: PCI DSS, scope: attestation}
  - {name: HIPAA, scope: attestation}
  - {name: HITRUST, scope: certification}
  - {name: FedRAMP, scope: authorization, region: United States}
  - {name: DoD Impact Levels, scope: authorization, region: United States}
  - {name: CJIS, scope: attestation, region: United States}
  - {name: ITAR, scope: attestation, region: United States}
  - {name: IRAP, scope: assessment, region: Australia}
  - {name: C5, scope: attestation, region: Germany}
  - {name: ENS, scope: certification, region: Spain}
  - {name: HDS, scope: certification, region: France}
  - {name: G-Cloud / Cyber Essentials, scope: certification, region: United Kingdom}
  - {name: ISMAP, scope: registration, region: Japan}
  - {name: K-ISMS, scope: certification, region: Korea}
  - {name: MTCS, scope: certification, region: Singapore}
  - {name: TISAX, scope: assessment, region: Europe (automotive)}
  - {name: CSA STAR, scope: registry}
  - {name: CSA AI STAR, scope: registry, note: 'Cloud Security Alliance assurance framework extended to AI systems.'}
  - {name: GDPR, scope: regulatory alignment, region: European Union}
  - {name: NIST, scope: framework alignment}
shared_responsibility:
  documented: true
  statement: >-
    Oracle publishes a shared management model on the same page: responsibility for security and
    privacy is split between Oracle and the customer, and the split varies by service model
    (IaaS/PaaS/SaaS).
subprocessors_page: null
status_page: https://ocistatus.oraclecloud.com/
note: >-
  Framework names were read from the live page body on 2026-08-29. Per-framework scope beyond what
  the page states (which services, which regions, current report dates) was not fetched and is not
  asserted here.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/oracle-cloud-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.