AI vendors with CSA STAR certification

AI vendors listed in the Cloud Security Alliance STAR Registry, a free public registry of cloud-vendor security attestations based on the Cloud Controls Matrix.

The Cloud Security Alliance (CSA) STAR Registry is a public registry of cloud-vendor security assessments based on the CSA Cloud Controls Matrix (CCM). Three levels: Level 1 Self-Assessment (publicly self-attested CAIQ questionnaire), Level 2 Third-Party Assessment (independent audit, equivalent to SOC 2 or ISO 27001), and Level 3 Continuous Auditing (in development). STAR is widely respected in cloud security circles and complements rather than replaces SOC 2 / ISO 27001.

Vendors with CSA STAR

Amazon (AWS)
HQ: United States
Cloud infrastructure leader that develops proprietary Titan models and custom Trainium/Inferentia chips while offering multi-model access th…
Score 12.34 · low
Salesforce
HQ: United States
Enterprise CRM leader that combines proprietary AI models (Einstein, CodeGen, xGen) with OpenAI integration for Einstein GPT, embedding AI a…
Score 12.74 · low
IBM
HQ: United States
Enterprise technology company offering the watsonx AI platform with proprietary Granite foundation models. Combines own model development wi…
Score 14.11 · low
Microsoft
HQ: United States
Global technology conglomerate that both develops proprietary AI models (Phi series) and deeply integrates OpenAI models across its Copilot …
Score 14.68 · low
SAP
HQ: Germany
Global enterprise software company integrating AI through its Joule AI assistant across ERP, supply chain, and business applications. Combin…
Score 16.63 · low
Google DeepMind
HQ: United States
Google's unified AI research lab combining DeepMind and Google Brain, building the Gemini model family integrated across Google products and…
Score 18.85 · low
Oracle
HQ: United States
Enterprise cloud and database company offering OCI AI Services with both proprietary AI capabilities and third-party model hosting. Provides…
Score 19.89 · low
Palo Alto Networks
HQ: United States
Leading cybersecurity company integrating AI across its security platform through Cortex XSIAM (AI-driven security operations), Prisma Cloud…
Score 19.89 · low
Snowflake
HQ: United States
Cloud data platform with Cortex AI, providing LLM-powered SQL functions, document processing, and AI assistants that operate directly on dat…
Score 24.36 · moderate
ServiceNow
HQ: United States
Enterprise workflow automation platform integrating AI through Now Assist, which combines ServiceNow's proprietary Now LLM models with OpenA…
Score 24.4 · moderate
Databricks
HQ: United States
Unified data analytics and AI platform combining data lakehouse, ML ops, and generative AI capabilities. Offers Foundation Model APIs that i…
Score 25.4 · moderate
Naver
HQ: South Korea
South Korea's largest internet company and search engine operator, developing HyperCLOVA X large language models optimized for Korean and As…
Score 31.18 · moderate
HubSpot
HQ: United States
CRM platform with AI features across marketing, sales, and service hubs. Breeze AI provides content generation, lead scoring, chatbot capabi…
Score 33.63 · moderate
Alibaba Cloud
HQ: China
Cloud computing division of Alibaba Group, developing the Qwen model family. One of China's leading cloud and AI providers with significant …
Score 42.24 · elevated

Buyer checklist

Compliance is necessary, not sufficient. Holding CSA STAR is a meaningful baseline, but no certification covers AI-specific risk end-to-end. Layer this on top of vendor-specific diligence — sub-processor disclosure, training-data policy, model card transparency, dependency-chain mapping.