You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
'Vellum is an enterprise AI development platform for building, evaluating, and deploying LLM prompts, workflows, and agents.',
19
19
standoutFeatures: [
20
20
{
21
-
title: 'HIPAA compliance',
21
+
title: 'HIPAA compliance with a signable BAA',
22
22
description:
23
-
'Vellum is HIPAA compliant, as documented by Vellum and corroborated by a third-party Drata case study. Sim does not currently offer HIPAA compliance (both platforms hold SOC 2 Type 2).',
24
-
shortDescription: 'HIPAA compliant; Sim does not offer HIPAA.',
23
+
'Vellum is HIPAA compliant and enterprise customers can sign a Business Associate Agreement for handling protected health information, corroborated by a third-party Drata case study. Sim does not currently offer HIPAA compliance (both platforms hold SOC 2 Type 2).',
24
+
shortDescription: 'HIPAA compliant with a signable BAA; Sim does not offer HIPAA.',
'SOC 2 Type 2 and HIPAA compliant; a Drata case study also notes SOC 2 Type 1; no other certifications (ISO 27001, GDPR-specific attestation, PCI, FedRAMP) confirmed',
807
+
'SOC 2 Type 2 and HIPAA compliant, with a BAA available for enterprise customers; a Drata case study also notes SOC 2 Type 1; no other certifications (ISO 27001, GDPR-specific attestation, PCI, FedRAMP) confirmed',
808
808
detail:
809
-
"Vellum's docs state it is SOC 2 Type 2 and HIPAA compliant. A third-party Drata case study also notes its SOC 2 Type 1 and Type 2 attestations. Neither cited source states that Vellum offers a Business Associate Agreement. No mention of ISO 27001, a GDPR-specific attestation, PCI, or FedRAMP certification was found.",
810
-
shortValue: 'SOC 2 Type 2, HIPAA; no other certs confirmed',
809
+
"Vellum's docs state it is HIPAA compliant and that enterprise customers can sign a Business Associate Agreement (BAA). A third-party Drata case study also notes its SOC 2 Type 1 and Type 2 attestations. No mention of ISO 27001, a GDPR-specific attestation, PCI, or FedRAMP certification was found.",
810
+
shortValue: 'SOC 2 Type 2, HIPAA + BAA; no other certs confirmed',
0 commit comments