Symbl.ai · Trust Center

Symblai Trust Center

Trust center

Symbl.ai maintains a public trust center documenting SOC 2 Type II, HIPAA, PCI DSS, GDPR, and CSA CAIQ compliance.

CompanyConversation IntelligenceSpeech to TextVoice AIArtificial IntelligenceMachine LearningReal TimeSDKs
Trust center:

Certifications & Compliance

SOC 2 Type IIHIPAAPCI DSSGDPRCSA CAIQ

Source

Trust Center

symblai-trust-center.yml Raw ↑
generated: '2026-08-14'
method: searched
source: https://symbl.ai/platform/security/overview/
docs: https://symbl.ai/platform/security/overview/
notes: >-
  Symbl.ai publishes a public "Security, Privacy and Compliance" page naming five specific
  attestations/programs. It is a marketing-hosted security overview, not a hosted trust portal:
  there is no evidence room, no self-service report download, no subprocessor list and no
  document request flow, and trust.symbl.ai does not resolve. Certification names and the
  encryption claims below are quoted from the page; API Evangelist has NOT verified any
  attestation with the auditor or the certifying body.
type: security-overview-page
hosted_portal: false
portal_probes:
- url: https://trust.symbl.ai/
  result: NXDOMAIN
- url: https://symbl.ai/platform/security/overview/
  http_status: 200
certifications:
- name: SOC 2 Type II
  claimed: true
  scope: Product, infrastructure and policies, assessed by an independent third-party auditor.
  report_available: false
  report_note: No self-service report download or NDA request flow is published.
- name: HIPAA
  claimed: true
  scope: >-
    Offers HIPAA Business Associate Agreements to healthcare customers, and signs Business
    Associate Contracts as required.
  report_available: false
- name: PCI DSS
  claimed: true
  scope: Compliant with the Payment Card Industry Data Security Standard.
  report_available: false
- name: GDPR
  claimed: true
  scope: >-
    New vendors, assets and personal-data processing activities are subject to privacy,
    security and compliance review; documented process for personal-data transfers out of the
    EU/UK.
  report_available: false
- name: CSA CAIQ
  claimed: true
  scope: >-
    Completed the Cloud Security Alliance Consensus Assessments Initiative Questionnaire
    security assessment.
  report_available: false
  registry_verified: false
  registry_note: Not verified against the CSA STAR registry by API Evangelist.
security_program:
  data_security:
    tls_minimum_claimed: TLS 1.2
    in_transit: RSA 2048-bit keys; connections secured with 2048-bit encryption.
    at_rest: AES-256.
  product_security: >-
    States a secure-by-design developer process covering development, deployment and post-
    deployment, with a software delivery and change-management model.
  risk_management: >-
    States a flexible risk-management framework for identification, assessment, treatment and
    reporting of security risks, plus identity and access management controls.
privacy_policy: https://symbl.ai/privacy-policy/
terms_of_service: https://symbl.ai/termsofservice/
subprocessors_published: false
caveat: >-
  These claims describe a platform whose API, console and documentation hosts no longer resolve
  (see lifecycle/symblai-lifecycle.yml). The page is live and current-facing as published;
  whether the attestations remain in force under Invoca ownership is not stated anywhere public.
x-evidence:
  fetched: '2026-08-14'
  url: https://symbl.ai/platform/security/overview/
  http_status: 200
  content_type: text/html; charset=UTF-8