Tray.ai publishes a Conveyor-hosted trust center at https://trust.tray.ai/ carrying 19 documents, 78 knowledge-base FAQs and 8 certification badges, with a gated access request for the audit reports themselves. The certification list below is Tray's OWN vendor record on that page (certifications: soc1-type-2, soc2-type-2, hipaa, gdpr, ccpa, eu-us-data-privacy, swiss-us-dpf, uk-extension-to-eu-us-dpf), read on 2026-09-02.
Tray.ai maintains a public trust center documenting SOC 1 Type 2, SOC 2 Type 2, HIPAA, GDPR, CCPA, EU-US Data Privacy Framework, Swiss-US Data Privacy Framework, and UK Extension to the EU-US Data Privacy Framework compliance.
generated: '2026-09-02'
method: searched
probe: true
source: https://trust.tray.ai/
url: https://trust.tray.ai/
provider: Tray.ai
providerId: tray-ai
platform: Conveyor
description: >-
Tray.ai publishes a Conveyor-hosted trust center at https://trust.tray.ai/ carrying 19
documents, 78 knowledge-base FAQs and 8 certification badges, with a gated access request for
the audit reports themselves. The certification list below is Tray's OWN vendor record on that
page (certifications: soc1-type-2, soc2-type-2, hipaa, gdpr, ccpa, eu-us-data-privacy,
swiss-us-dpf, uk-extension-to-eu-us-dpf), read on 2026-09-02.
certifications:
- SOC 1 Type 2
- SOC 2 Type 2
- HIPAA
- GDPR
- CCPA
- EU-US Data Privacy Framework
- Swiss-US Data Privacy Framework
- UK Extension to the EU-US Data Privacy Framework
auditor: Schellman & Company, LLC
audit_notes:
- date: '2025-10-02'
title: Tray.ai Achieves SOC 1 Type 2
detail: >-
Examination period 2024-08-01 to 2025-07-31, conducted by Schellman & Company, LLC,
complementing the existing SOC 2 Type 2.
data_residency:
regions: [US, EU, APAC]
source: https://tray.ai/trust
legal:
dpa: https://tray.ai/legal/dpa/
sub_processors: https://tray.ai/legal/sub-processors/
msa: https://tray.ai/legal/msa/
support_terms: https://tray.ai/legal/sla/
privacy_policy: https://tray.ai/legal/privacy-policy/
cookie_policy: https://tray.ai/legal/cookie-policy/
report_vulnerability: https://hackerone.com/a15ee773-fdbf-4a7b-9942-43bec427b5ea/embedded_submissions/new
correction:
date: '2026-09-02'
was: [SOC 2, ISO 27001, ISO 27017, ISO 27018, HIPAA, FedRAMP, GDPR]
now: [SOC 1 Type 2, SOC 2 Type 2, HIPAA, GDPR, CCPA, EU-US DPF, Swiss-US DPF, UK-US DPF]
reason: >-
The 2026-07-11 version of this artifact was written by a keyword scan of the trust center HTML
and credited Tray with ISO 27001, ISO 27017, ISO 27018 and FedRAMP. Those strings are on the
page, but they belong to Conveyor's SUBPROCESSOR vendor records embedded in the same document —
AWS ("soc2-type-2","iso-27001","gdpr","pci","iso-27017","iso-27018","soc1-type-2","soc3","csa",
"fedramp") and Datadog ("...","fedramp-li-saas"). Tray's own vendor record on the same page
lists none of them. Misattributing a subprocessor's certifications to the provider is the same
failure class as reading a spec by its fetch URL; corrected here against Tray's own record.
evidence:
- url: https://trust.tray.ai/
status: 200
finding: >-
Tray.ai vendor record — "website":"https://tray.ai", "certifications":["soc1-type-2",
"soc2-type-2","hipaa","gdpr","ccpa","eu-us-data-privacy","swiss-us-dpf",
"uk-extension-to-eu-us-dpf"]. Badge strip renders the same eight.
- url: https://tray.ai/trust
status: 200
finding: >-
"Tray meets global compliance standards including GDPR, CCPA, and HIPAA. Customers can host
data in the US, EU, or APAC. We provide signed DPAs and transparent vendor lists."
- url: https://tray.ai/legal/sub-processors/
status: 200
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.