Sierra AI Vendor Risk Profile
Enterprise AI agent platform for customer experience, founded 2023 by Bret Taylor (ex-Salesforce co-CEO, OpenAI board chair) and Clay Bavor (ex-Google). Builds always-on conversational agents for support, sales, and operations. $100M ARR reached in under 2 years; customers include Cigna, Blue Cross Blue Shield, Prudential, and one-third of the world's largest banks.
Risk overview
Risk score: 38/100
Risk tier: Moderate
Safety rating: 62/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: May 15, 2026 Fresh
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 64/100 |
| IP Exposure | 16/100 |
| Jurisdiction | 13/100 |
| Security | 34/100 |
| Regulatory Compliance | 50/100 |
| Transparency | 60/100 |
| Business Stability | 23/100 |
| Dependency Chain | 38/100 |
| Agent Governance | Not assessed |
Analyst summary
Rating: Recommended
Sierra became one of the fastest-growing enterprise AI companies in history: $100M ARR in under two years, ~$150M ARR by January 2026, and a $950M raise at $15B+ valuation in May 2026. The customer roster — Cigna, Blue Cross Blue Shield, Prudential, Rocket Mortgage, one-third of the world's largest banks — speaks to the compliance maturity (SOC 2 Type II, ISO 27001, HIPAA, GDPR, BAA available). The model-routing layer atop OpenAI and Anthropic creates an upstream dependency that buyers should map explicitly.
Bottom line: Currently the most enterprise-credentialed AI customer-experience agent vendor. The compliance posture, customer roster, and capital position make Sierra a defensible default pick for regulated enterprise CX deployments — provided you treat the upstream-model routing layer as an explicit dependency in your own risk register.
Strengths
- SOC 2 Type II, ISO 27001, HIPAA, GDPR, CCPA compliant — mature for a 2023-founded vendor
- HIPAA BAA available; healthcare customers include Cigna and Blue Cross Blue Shield
- Public subprocessor list and DPA available
- Customer-controlled data retention and explicit "no training on customer conversations" guarantee
- Red-teaming program in place; safety testing disclosed
- $1.5B+ raised — long enterprise runway and category-leader market position
Concerns
- Operates atop OpenAI and Anthropic foundation models — upstream dependency carries through provider risk
- Founder Bret Taylor chairs the OpenAI board — review model-routing decisions for any structural bias
- No FedRAMP authorization — not currently appropriate for US federal workloads
- ISO 42001 not pursued
- Limited open-source contributions and no public model cards
- US CLOUD Act exposure on US-resident customer conversations
Best for
- Enterprises deploying customer-facing AI agents at scale in support, sales, or operations
- Regulated industries (healthcare, financial services, insurance) needing AI agents with BAA and SOC 2 Type II
- Buyers who want the integration depth of a well-funded, well-staffed agent platform rather than building in-house
Avoid if
- Your procurement requires FedRAMP authorization
- You cannot accept the upstream foundation-model dependency on OpenAI / Anthropic
- You require formal ISO 42001 AI-management-system certification today
Citations
- Security Compliance — Soc2 Type2
- Vendors — Description
- Vendors — Last Valuation Usd
- Vendors — Funding Total Usd
- Vendors — Employee Count Range
- Ip Profile — Training Data Provenance
- Jurisdiction Profile — Geopolitical Risk Notes