AI vendors with ISO 27001 certification
AI vendors certified to ISO/IEC 27001, the international standard for information security management systems.
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). Unlike SOC 2 (which is a U.S.-centric attestation report), ISO 27001 is a certification awarded by an accredited certification body. EU and APAC buyers often weight ISO 27001 more heavily than SOC 2, and many enterprise procurement teams will accept either. The vendors below hold a current ISO 27001 certification.
Vendors with ISO 27001
Anthropic
Score 11.44 · low
Amazon (AWS)
Score 12.34 · low
Salesforce
Score 12.74 · low
Adobe
Score 13.74 · low
Cohere
Score 13.79 · low
IBM
Score 14.11 · low
Microsoft
Score 14.68 · low
SAP
Score 16.63 · low
OpenAI
Score 18.36 · low
Google DeepMind
Score 18.85 · low
Oracle
Score 19.89 · low
Palo Alto Networks
Score 19.89 · low
Nuance (Microsoft)
Score 20.86 · moderate
Writer
Score 20.93 · moderate
AI21 Labs
Score 22.34 · moderate
Workday
Score 22.45 · moderate
Mosaic (Databricks)
Score 22.6 · moderate
Nvidia
Score 22.63 · moderate
SentinelOne
Score 22.96 · moderate
Scale AI
Score 23.3 · moderate
Aleph Alpha
Score 24.29 · moderate
Snowflake
Score 24.36 · moderate
ServiceNow
Score 24.4 · moderate
Datadog
Score 24.41 · moderate
SambaNova
Score 24.5 · moderate
PolyAI
Score 24.72 · moderate
Palantir
Score 25.09 · moderate
Databricks
Score 25.4 · moderate
Cloudflare
Score 25.89 · moderate
Slack
Score 26.47 · moderate
GitHub Copilot
Score 27.12 · moderate
Vanta
Score 27.24 · moderate
Zoom
Score 27.35 · moderate
Atlassian
Score 28.51 · moderate
Preferred Networks
Score 29.03 · moderate
Synthesia
Score 29.28 · moderate
Kensho (S&P Global)
Score 29.4 · moderate
Casetext
Score 29.77 · moderate
CoreWeave
Score 29.93 · moderate
Stripe
Score 29.97 · moderate
Harvey
Score 30.27 · moderate
LexisNexis
Score 30.29 · moderate
Grammarly
Score 30.74 · moderate
Moveworks
Score 30.84 · moderate
Sakana AI
Score 30.94 · moderate
Zendesk
Score 30.94 · moderate
Galileo
Score 30.97 · moderate
Bloomberg
Score 31.1 · moderate
Naver
Score 31.18 · moderate
Intercom
Score 31.36 · moderate
Buyer checklist
- Verify the certificate number with the issuing certification body.
- Confirm the scope of the certification covers the product you intend to use.
- Check the certification expiration date and surveillance audit schedule.
- Ask whether ISO 27017 (cloud security) and ISO 27018 (cloud privacy) are also certified.
- For AI-specific use cases, ask about ISO 42001 (AI management system) — the newer standard.
Compliance is necessary, not sufficient. Holding ISO 27001 is a meaningful baseline, but no certification covers AI-specific risk end-to-end. Layer this on top of vendor-specific diligence — sub-processor disclosure, training-data policy, model card transparency, dependency-chain mapping.