Symbl.ai · Trust Center
Symblai Trust Center
Trust center
Symbl.ai maintains a public trust center documenting SOC 2 Type II, HIPAA, PCI DSS, GDPR, and CSA CAIQ compliance.
CompanyConversation IntelligenceSpeech to TextVoice AIArtificial IntelligenceMachine LearningReal TimeSDKs
Certifications & Compliance
SOC 2 Type IIHIPAAPCI DSSGDPRCSA CAIQ
Source
Trust Center
generated: '2026-08-14'
method: searched
source: https://symbl.ai/platform/security/overview/
docs: https://symbl.ai/platform/security/overview/
notes: >-
Symbl.ai publishes a public "Security, Privacy and Compliance" page naming five specific
attestations/programs. It is a marketing-hosted security overview, not a hosted trust portal:
there is no evidence room, no self-service report download, no subprocessor list and no
document request flow, and trust.symbl.ai does not resolve. Certification names and the
encryption claims below are quoted from the page; API Evangelist has NOT verified any
attestation with the auditor or the certifying body.
type: security-overview-page
hosted_portal: false
portal_probes:
- url: https://trust.symbl.ai/
result: NXDOMAIN
- url: https://symbl.ai/platform/security/overview/
http_status: 200
certifications:
- name: SOC 2 Type II
claimed: true
scope: Product, infrastructure and policies, assessed by an independent third-party auditor.
report_available: false
report_note: No self-service report download or NDA request flow is published.
- name: HIPAA
claimed: true
scope: >-
Offers HIPAA Business Associate Agreements to healthcare customers, and signs Business
Associate Contracts as required.
report_available: false
- name: PCI DSS
claimed: true
scope: Compliant with the Payment Card Industry Data Security Standard.
report_available: false
- name: GDPR
claimed: true
scope: >-
New vendors, assets and personal-data processing activities are subject to privacy,
security and compliance review; documented process for personal-data transfers out of the
EU/UK.
report_available: false
- name: CSA CAIQ
claimed: true
scope: >-
Completed the Cloud Security Alliance Consensus Assessments Initiative Questionnaire
security assessment.
report_available: false
registry_verified: false
registry_note: Not verified against the CSA STAR registry by API Evangelist.
security_program:
data_security:
tls_minimum_claimed: TLS 1.2
in_transit: RSA 2048-bit keys; connections secured with 2048-bit encryption.
at_rest: AES-256.
product_security: >-
States a secure-by-design developer process covering development, deployment and post-
deployment, with a software delivery and change-management model.
risk_management: >-
States a flexible risk-management framework for identification, assessment, treatment and
reporting of security risks, plus identity and access management controls.
privacy_policy: https://symbl.ai/privacy-policy/
terms_of_service: https://symbl.ai/termsofservice/
subprocessors_published: false
caveat: >-
These claims describe a platform whose API, console and documentation hosts no longer resolve
(see lifecycle/symblai-lifecycle.yml). The page is live and current-facing as published;
whether the attestations remain in force under Invoca ownership is not stated anywhere public.
x-evidence:
fetched: '2026-08-14'
url: https://symbl.ai/platform/security/overview/
http_status: 200
content_type: text/html; charset=UTF-8