Skip to content

Commit c2c11b2

Browse files
committed
fix(comparisons): preserve SOC 2 compliance details
1 parent 3ca2ce8 commit c2c11b2

14 files changed

Lines changed: 19 additions & 14 deletions

File tree

apps/sim/lib/compare/data/competitors/crewai.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -835,7 +835,7 @@ export const crewaiProfile: CompetitorProfile = {
835835
value:
836836
'SOC 2 Type 1 for CrewAI AMP (audit report dated November 2025) and HIPAA for the Enterprise edition (audit report dated February 2026); no ISO 27001, PCI, or FedRAMP certification confirmed',
837837
detail:
838-
"CrewAI's Trust Center lists a HIPAA Audit Report dated February 2026 for the Enterprise edition, alongside the SOC 2 Type 1 report. CrewAI's pricing page separately references 'FedRamp High compliance' language for its Enterprise tier, but no independent FedRAMP authorization listing corroborates that claim, so it is not treated as confirmed here.",
838+
"CrewAI's Vanta-indexed Trust Center lists a HIPAA Audit Report dated February 2026 for the Enterprise edition, alongside the SOC 2 Type 1 report. The certifications apply to the Enterprise/AMP offering, not to self-hosted deployments of the open-source framework, which have no compliance certification of their own because they are not a hosted service. CrewAI's pricing page separately references 'FedRamp High compliance' language for its Enterprise tier, but no independent FedRAMP authorization listing corroborates that claim, so it is not treated as confirmed here.",
839839
shortValue: 'SOC 2 Type 1 (AMP), HIPAA audit (Feb 2026); FedRAMP claim unconfirmed',
840840
confidence: 'estimated',
841841
sources: [

apps/sim/lib/compare/data/competitors/dust.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -828,7 +828,7 @@ export const dustProfile: CompetitorProfile = {
828828
compliance: {
829829
value: 'GDPR compliant, HIPAA-capable, SOC 2 Type II; no ISO 27001, PCI, or FedRAMP',
830830
detail:
831-
"Dust's security page and enterprise materials state GDPR compliance and HIPAA-compliance capability alongside SOC 2 Type II. No source confirms ISO 27001, PCI-DSS, or FedRAMP.",
831+
"Dust's security page and enterprise materials state GDPR compliance and HIPAA-compliance capability alongside SOC 2 Type II. A Vanta case study says Dust achieved SOC 2 Type II audit readiness in three weeks using Vanta's automation, reducing its compliance workload by roughly 50%; the report is downloadable through Dust's Trust Center. No source confirms ISO 27001, PCI-DSS, or FedRAMP.",
832832
shortValue: 'GDPR, HIPAA-capable, SOC 2 Type II',
833833
confidence: 'estimated',
834834
sources: [

apps/sim/lib/compare/data/competitors/flowise.ts

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -713,6 +713,8 @@ export const flowiseProfile: CompetitorProfile = {
713713
compliance: {
714714
value:
715715
'Unknown: beyond the unconfirmed third-party SOC 2 claim, Flowise has published no HIPAA, ISO 27001, PCI, or FedRAMP certification.',
716+
detail:
717+
"The SOC 2 claim comes from third-party security-scan aggregator Nudge Security; Flowise has published no SOC 2 report, badge, or trust page of its own. The same source also claims FedRAMP and PCI compliance, an atypical combination for a small startup that is not corroborated on Flowise's own website.",
716718
shortValue: 'SOC 2 claim unconfirmed; no official certifications published',
717719
confidence: 'unknown',
718720
sources: [],

apps/sim/lib/compare/data/competitors/langchain.ts

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -821,10 +821,11 @@ export const langchainProfile: CompetitorProfile = {
821821
sources: [],
822822
},
823823
compliance: {
824-
value: 'HIPAA and GDPR, in addition to SOC 2 Type II',
824+
value:
825+
"LangSmith is SOC 2 Type II, HIPAA, and GDPR compliant; LangGraph Platform (now LangSmith Deployment) shares LangSmith's SOC 2 attestation and compliance posture",
825826
detail:
826-
"LangChain's own docs and Trust Center state LangSmith is SOC 2 Type II, HIPAA compliant, and GDPR compliant; no ISO 27001, PCI-DSS, or FedRAMP attestation was found on LangChain's own compliance materials.",
827-
shortValue: 'HIPAA and GDPR compliant, alongside SOC 2 Type II',
827+
"LangChain's own docs and Trust Center state LangSmith is SOC 2 Type II, HIPAA compliant, and GDPR compliant; no ISO 27001, PCI-DSS, or FedRAMP attestation was found on LangChain's own compliance materials. The Trust Center is the canonical source but renders via client-side JavaScript, so it could not be directly verified by an automated fetch; the LangSmith certification is independently confirmed on the static Regions FAQ page.",
828+
shortValue: 'LangSmith/LangGraph SOC 2 Type II; HIPAA and GDPR compliant',
828829
confidence: 'verified',
829830
sources: [
830831
{

apps/sim/lib/compare/data/competitors/langflow.ts

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -731,6 +731,8 @@ export const langflowProfile: CompetitorProfile = {
731731
compliance: {
732732
value:
733733
'Unknown: no public documentation or official page confirms SOC 2, HIPAA, ISO 27001, GDPR-specific attestation, PCI, or FedRAMP certification for Langflow.',
734+
detail:
735+
"Langflow's security documentation treats infrastructure isolation and compliance as the deploying organization's responsibility rather than a certification held by Langflow.",
734736
shortValue: 'Unknown, no SOC 2 or other compliance certifications documented',
735737
confidence: 'unknown',
736738
sources: [],

apps/sim/lib/compare/data/competitors/microsoft-copilot.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -957,7 +957,7 @@ export const microsoftCopilotProfile: CompetitorProfile = {
957957
value:
958958
'SOC 2 Type 2 (Copilot Studio is named in scope), HIPAA (Business Associate Agreement), HITRUST CSF, FedRAMP, multiple ISO standards (9001, 20000-1, 22301, 27001, 27017, 27018, 27701), PCI DSS, CSA STAR, UK G-Cloud, Singapore MTCS Level 3, Korea K-ISMS, and Spain ENS, each with an audit report on the Microsoft Service Trust Portal',
959959
detail:
960-
"This is the full list from Copilot Studio's admin-certification documentation. Each certification links to a corresponding audit report or certificate.",
960+
'This is the full list from Copilot Studio\'s admin-certification documentation. Each certification links to a corresponding audit report or certificate. That page confirms SOC compliance without naming the report type; Microsoft\'s dedicated SOC 2 Type 2 offering page lists the product under its former name, "Copilot Studios," resolving the applicable report type and scope.',
961961
shortValue:
962962
'SOC 2 Type 2, HIPAA, HITRUST, FedRAMP, multiple ISO standards, PCI DSS, and more',
963963
confidence: 'verified',

apps/sim/lib/compare/data/competitors/n8n.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -912,7 +912,7 @@ export const n8nProfile: CompetitorProfile = {
912912
value:
913913
'GDPR (as data processor), SOC 2 Type II certification, and a publicly downloadable SOC 3 report; no HIPAA, ISO 27001, PCI, or FedRAMP certification found',
914914
detail:
915-
"n8n's Trust Center (SafeBase-hosted) and legal/security page list GDPR compliance (as a data processor with a standard DPA), CAIQ self-assessment questionnaires for both cloud and self-hosted deployments, and a SOC 3 report that is publicly downloadable from the Security page. n8n now holds SOC 2 Type II certification, viewable via the Trust Center, in addition to the public SOC 3 report. n8n holds no ISO 27001, HIPAA BAA, PCI-DSS, or FedRAMP certification. Third-party blog posts describe self-hosted n8n as helping organizations map to HIPAA/ISO 27001 requirements, but that is not the same as holding those certifications.",
915+
"n8n's Trust Center (SafeBase-hosted) and legal/security page list GDPR compliance (as a data processor with a standard DPA), CAIQ self-assessment questionnaires for both cloud and self-hosted deployments, and a SOC 3 report that is publicly downloadable from the Security page. n8n now holds SOC 2 Type II certification, viewable via the Trust Center, in addition to the public SOC 3 report. Its security program is continuously evaluated and independently audited annually, with the SOC 2 report available to Enterprise customers on request rather than published openly. n8n holds no ISO 27001, HIPAA BAA, PCI-DSS, or FedRAMP certification. Third-party blog posts describe self-hosted n8n as helping organizations map to HIPAA/ISO 27001 requirements, but that is not the same as holding those certifications.",
916916
shortValue: 'GDPR, SOC 2 Type II certified, public SOC 3 report',
917917
confidence: 'verified',
918918
sources: [

apps/sim/lib/compare/data/competitors/openai-agentkit.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -895,7 +895,7 @@ export const openaiAgentkitProfile: CompetitorProfile = {
895895
value:
896896
'FedRAMP Moderate Authorization (ChatGPT Enterprise and API Platform), PCI DSS v4.0.1, SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 27701:2019; supports customer HIPAA compliance via BAA and GDPR/CCPA via DPA; FERPA covered via a separate Student Data Privacy Agreement for ChatGPT Edu',
897897
detail:
898-
"OpenAI's ChatGPT Enterprise and API Platform hold FedRAMP Moderate (Class C) authorization per the FedRAMP Marketplace listing. OpenAI's trust portal lists PCI DSS v4.0.1 for payment-processing components, a SOC 2 Type 2 examination (Security, Availability, Confidentiality, Privacy criteria) covering the API Platform, ChatGPT Enterprise, ChatGPT Edu, and ChatGPT Team, plus ISO/IEC 27001:2022, 27017:2015, 27018:2019, and 27701:2019 certifications, and lists GDPR and CCPA. OpenAI offers a Data Processing Addendum for GDPR/CCPA and a Business Associate Agreement for HIPAA-regulated customers on ChatGPT Enterprise/Edu and the API (not standard ChatGPT Business); this is enablement rather than OpenAI itself being HIPAA-certified, since HIPAA has no formal certification body. FERPA compliance for ChatGPT Edu/for Teachers runs through a separate Student Data Privacy Agreement rather than the general DPA.",
898+
"OpenAI's ChatGPT Enterprise and API Platform hold FedRAMP Moderate (Class C) authorization per the FedRAMP Marketplace listing. OpenAI's most recent SOC 2 report covers January 1, 2025 through June 30, 2025 for the Security, Availability, Confidentiality, and Privacy Trust Services Criteria across the API Platform, ChatGPT Enterprise, ChatGPT Edu, and ChatGPT Team. OpenAI's trust portal also lists PCI DSS v4.0.1 for payment-processing components, plus ISO/IEC 27001:2022, 27017:2015, 27018:2019, and 27701:2019 certifications, and lists GDPR and CCPA. OpenAI offers a Data Processing Addendum for GDPR/CCPA and a Business Associate Agreement for HIPAA-regulated customers on ChatGPT Enterprise/Edu and the API (not standard ChatGPT Business); this is enablement rather than OpenAI itself being HIPAA-certified, since HIPAA has no formal certification body. FERPA compliance for ChatGPT Edu/for Teachers runs through a separate Student Data Privacy Agreement rather than the general DPA.",
899899
shortValue: 'FedRAMP Moderate, PCI DSS, SOC 2, ISO 27001/27701, HIPAA BAA',
900900
confidence: 'verified',
901901
sources: [

apps/sim/lib/compare/data/competitors/openclaw.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -868,7 +868,7 @@ export const openClawProfile: CompetitorProfile = {
868868
value:
869869
'No compliance certifications (no SOC 2, HIPAA, ISO 27001, GDPR-specific attestation, PCI, or FedRAMP). As open-source, self-hosted software from a non-profit Foundation, OpenClaw is not the kind of vendor entity that typically pursues these certifications; compliance posture depends entirely on how and where the operator self-hosts it.',
870870
detail:
871-
"China restricted state enterprises and government agencies from deploying OpenClaw in March 2026 over security concerns, per Wikipedia's history summary, a data point on the compliance/trust landscape rather than a certification.",
871+
"OpenClaw publishes no SOC 2 attestation, trust center, or audit report; responsibility for infrastructure security and compliance rests entirely with the self-hosting operator. China restricted state enterprises and government agencies from deploying OpenClaw in March 2026 over security concerns, per Wikipedia's history summary, a data point on the compliance/trust landscape rather than a certification.",
872872
shortValue: 'No SOC 2 or other certifications; compliance depends on self-hosting operator',
873873
confidence: 'estimated',
874874
sources: [

apps/sim/lib/compare/data/competitors/pipedream.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -786,7 +786,7 @@ export const pipedreamProfile: CompetitorProfile = {
786786
value:
787787
'SOC 2 Type 2, HIPAA (via BAA, Enterprise), GDPR (SCCs), and AWS KMS infra with ISO 27001/27017/27018. No independent Pipedream-held ISO 27001/PCI/FedRAMP certification on the trust page',
788788
detail:
789-
"Pipedream's Privacy and Security page states it provides a SOC 2 Type 2 report on request, signs Business Associate Addendums (BAAs) for HIPAA/PHI use cases (Enterprise), and uses Standard Contractual Clauses (SCCs) for GDPR-related data transfers. Sensitive data (OAuth grants, key-based credentials, env vars) is encrypted at rest with AES-256-GCM via AWS KMS, which itself holds SOC 1/2/3 and ISO 27001/27017/27018 certifications. That ISO/PCI/FedRAMP coverage is inherited from the AWS infrastructure layer, not a certification Pipedream independently holds on its own trust page. Some third-party review sites describe Pipedream itself as directly PCI, FedRAMP, and CSA STAR compliant, but Pipedream's own security documentation does not corroborate this.",
789+
"Pipedream's Privacy and Security page states it provides a SOC 2 Type 2 report on request, undergoes annual third-party audits, and uses continuous-compliance monitoring tooling. It signs Business Associate Addendums (BAAs) for HIPAA/PHI use cases (Enterprise) and uses Standard Contractual Clauses (SCCs) for GDPR-related data transfers. Sensitive data (OAuth grants, key-based credentials, env vars) is encrypted at rest with AES-256-GCM via AWS KMS, which itself holds SOC 1/2/3 and ISO 27001/27017/27018 certifications. That ISO/PCI/FedRAMP coverage is inherited from the AWS infrastructure layer, not a certification Pipedream independently holds on its own trust page. Some third-party review sites describe Pipedream itself as directly PCI, FedRAMP, and CSA STAR compliant, but Pipedream's own security documentation does not corroborate this.",
790790
shortValue: 'SOC 2, HIPAA BAA, GDPR SCCs; ISO via AWS only',
791791
confidence: 'estimated',
792792
sources: [

0 commit comments

Comments
 (0)