Skip to content

Commit f611370

Browse files
committed
fix(comparisons): preserve competitor compliance details
1 parent 2a464a5 commit f611370

12 files changed

Lines changed: 34 additions & 22 deletions

File tree

apps/sim/lib/compare/data/competitors/claude-cowork.ts

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -809,16 +809,21 @@ export const claudeCoworkProfile: CompetitorProfile = {
809809
},
810810
additionalCompliance: {
811811
value:
812-
'ISO 27001:2022, ISO/IEC 42001:2023, HIPAA-ready (BAA via sales-assisted Enterprise)',
812+
'SOC 2 Type I and Type II (company-wide, not Cowork-specific), ISO 27001:2022, ISO/IEC 42001:2023, HIPAA-ready (BAA via sales-assisted Enterprise)',
813813
detail: 'Company-wide Anthropic certifications, not Cowork-scoped.',
814-
shortValue: 'ISO 27001, ISO 42001, HIPAA-ready',
814+
shortValue: 'SOC 2 Type I/II, ISO 27001, ISO 42001, HIPAA-ready',
815815
confidence: 'estimated',
816816
sources: [
817817
{
818818
url: 'https://support.claude.com/en/articles/10015870-what-certifications-has-anthropic-obtained',
819819
label: 'What Certifications has Anthropic obtained?',
820820
asOf: '2026-07-08',
821821
},
822+
{
823+
url: 'https://trust.anthropic.com/',
824+
label: 'Anthropic Trust Center',
825+
asOf: '2026-07-02',
826+
},
822827
],
823828
},
824829
modelAndToolGovernance: {

apps/sim/lib/compare/data/competitors/crewai.ts

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -848,10 +848,10 @@ export const crewaiProfile: CompetitorProfile = {
848848
},
849849
additionalCompliance: {
850850
value:
851-
'HIPAA (Enterprise edition, audit report dated February 2026); no ISO 27001, PCI, or FedRAMP certification confirmed',
851+
'SOC 2 Type 1 for CrewAI AMP (audit report dated November 2025) and HIPAA for the Enterprise edition (audit report dated February 2026); no ISO 27001, PCI, or FedRAMP certification confirmed',
852852
detail:
853853
"CrewAI's Trust Center lists a HIPAA Audit Report dated February 2026 for the Enterprise edition, alongside the SOC 2 Type 1 report. CrewAI's pricing page separately references 'FedRamp High compliance' language for its Enterprise tier, but no independent FedRAMP authorization listing corroborates that claim, so it is not treated as confirmed here.",
854-
shortValue: 'HIPAA audit (Feb 2026); FedRAMP claim unconfirmed',
854+
shortValue: 'SOC 2 Type 1 (AMP), HIPAA audit (Feb 2026); FedRAMP claim unconfirmed',
855855
confidence: 'estimated',
856856
sources: [
857857
{

apps/sim/lib/compare/data/competitors/flowise.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -722,7 +722,7 @@ export const flowiseProfile: CompetitorProfile = {
722722
additionalCompliance: {
723723
value:
724724
'Unknown: beyond the unconfirmed third-party SOC 2 claim, Flowise has published no HIPAA, ISO 27001, PCI, or FedRAMP certification.',
725-
shortValue: 'Unknown, no official certifications published',
725+
shortValue: 'SOC 2 claim unconfirmed; no official certifications published',
726726
confidence: 'unknown',
727727
sources: [],
728728
},

apps/sim/lib/compare/data/competitors/langflow.ts

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -739,8 +739,8 @@ export const langflowProfile: CompetitorProfile = {
739739
},
740740
additionalCompliance: {
741741
value:
742-
'Unknown: no public documentation or official page confirms HIPAA, ISO 27001, GDPR-specific attestation, PCI, or FedRAMP certification for Langflow.',
743-
shortValue: 'Unknown, no compliance certifications documented',
742+
'Unknown: no public documentation or official page confirms SOC 2, HIPAA, ISO 27001, GDPR-specific attestation, PCI, or FedRAMP certification for Langflow.',
743+
shortValue: 'Unknown, no SOC 2 or other compliance certifications documented',
744744
confidence: 'unknown',
745745
sources: [],
746746
},

apps/sim/lib/compare/data/competitors/make.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -923,7 +923,7 @@ export const makeProfile: CompetitorProfile = {
923923
'SOC 2 Type II, SOC 3, and ISO 27001 certified, plus GDPR adherence; no HIPAA, PCI, or FedRAMP mentioned',
924924
detail:
925925
"Make's Security page states the company operates an ISO 27001-certified information security program and runs infrastructure compliant with SOC 3 and SOC 2 Type II audits, alongside GDPR adherence (Make also has a dedicated GDPR page). HIPAA compliance is not mentioned or offered.",
926-
shortValue: 'No HIPAA, PCI, or FedRAMP',
926+
shortValue: 'SOC 2 Type II, SOC 3, ISO 27001, GDPR; no HIPAA, PCI, or FedRAMP',
927927
confidence: 'verified',
928928
sources: [
929929
{

apps/sim/lib/compare/data/competitors/microsoft-copilot.ts

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -976,10 +976,11 @@ export const microsoftCopilotProfile: CompetitorProfile = {
976976
},
977977
additionalCompliance: {
978978
value:
979-
'HIPAA (Business Associate Agreement), HITRUST CSF, FedRAMP, multiple ISO standards (9001, 20000-1, 22301, 27001, 27017, 27018, 27701), PCI DSS, CSA STAR, UK G-Cloud, Singapore MTCS Level 3, Korea K-ISMS, and Spain ENS, each with an audit report on the Microsoft Service Trust Portal',
979+
'SOC 2 Type 2 (Copilot Studio is named in scope), HIPAA (Business Associate Agreement), HITRUST CSF, FedRAMP, multiple ISO standards (9001, 20000-1, 22301, 27001, 27017, 27018, 27701), PCI DSS, CSA STAR, UK G-Cloud, Singapore MTCS Level 3, Korea K-ISMS, and Spain ENS, each with an audit report on the Microsoft Service Trust Portal',
980980
detail:
981981
"This is the full list from Copilot Studio's admin-certification documentation. Each certification links to a corresponding audit report or certificate.",
982-
shortValue: 'HIPAA, HITRUST, FedRAMP, multiple ISO standards, PCI DSS, CSA STAR, and more',
982+
shortValue:
983+
'SOC 2 Type 2, HIPAA, HITRUST, FedRAMP, multiple ISO standards, PCI DSS, and more',
983984
confidence: 'verified',
984985
sources: [
985986
{
@@ -988,6 +989,11 @@ export const microsoftCopilotProfile: CompetitorProfile = {
988989
'Review ISO, SOC, and HIPAA compliance - Microsoft Copilot Studio | Microsoft Learn',
989990
asOf: '2026-07-02',
990991
},
992+
{
993+
url: 'https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2',
994+
label: 'SOC 2 Type 2 - Microsoft Compliance | Microsoft Learn',
995+
asOf: '2026-07-04',
996+
},
991997
],
992998
},
993999
modelAndToolGovernance: {

apps/sim/lib/compare/data/competitors/openclaw.ts

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -881,10 +881,10 @@ export const openClawProfile: CompetitorProfile = {
881881
},
882882
additionalCompliance: {
883883
value:
884-
'No compliance certifications (no HIPAA, ISO 27001, GDPR-specific attestation, PCI, or FedRAMP). As open-source, self-hosted software from a non-profit Foundation, OpenClaw is not the kind of vendor entity that typically pursues these certifications; compliance posture depends entirely on how and where the operator self-hosts it.',
884+
'No compliance certifications (no SOC 2, HIPAA, ISO 27001, GDPR-specific attestation, PCI, or FedRAMP). As open-source, self-hosted software from a non-profit Foundation, OpenClaw is not the kind of vendor entity that typically pursues these certifications; compliance posture depends entirely on how and where the operator self-hosts it.',
885885
detail:
886886
"China restricted state enterprises and government agencies from deploying OpenClaw in March 2026 over security concerns, per Wikipedia's history summary, a data point on the compliance/trust landscape rather than a certification.",
887-
shortValue: 'None documented; compliance posture depends on self-hosting operator',
887+
shortValue: 'No SOC 2 or other certifications; compliance depends on self-hosting operator',
888888
confidence: 'estimated',
889889
sources: [
890890
{

apps/sim/lib/compare/data/competitors/power-automate.ts

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -966,10 +966,11 @@ export const powerAutomateProfile: CompetitorProfile = {
966966
},
967967
additionalCompliance: {
968968
value:
969-
'HIPAA/HITECH (Microsoft will sign a BAA as a business associate) and inclusion in the broader Office 365/Azure compliance program, which separately covers ISO 27001, FedRAMP, and other certifications at the Azure/Office 365 platform level. The SOC 2 Type 2 report also incorporates the Cloud Security Alliance CCM and German BSI C5:2020 criteria.',
969+
'SOC 2 Type 2 in-scope for Commercial and GCC environments only; HIPAA/HITECH (Microsoft will sign a BAA as a business associate); and inclusion in the broader Office 365/Azure compliance program, which separately covers ISO 27001, FedRAMP, and other certifications at the Azure/Office 365 platform level. The SOC 2 Type 2 report also incorporates the Cloud Security Alliance CCM and German BSI C5:2020 criteria.',
970970
detail:
971971
"HIPAA/BAA support and CSA CCM/BSI C5:2020 coverage are documented directly in Microsoft's SOC 2 documentation. No Power Automate-specific ISO 27001/FedRAMP attestation page exists, so treat those two as platform-level coverage rather than product-specific certification.",
972-
shortValue: 'HIPAA/BAA, CSA CCM, BSI C5:2020; ISO/FedRAMP at platform level',
972+
shortValue:
973+
'SOC 2 Type 2 (Commercial/GCC), HIPAA/BAA, CSA CCM, BSI C5; ISO/FedRAMP platform-level',
973974
confidence: 'estimated',
974975
sources: [
975976
{

apps/sim/lib/compare/data/competitors/stackai.ts

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -748,10 +748,10 @@ export const stackaiProfile: CompetitorProfile = {
748748
},
749749
additionalCompliance: {
750750
value:
751-
'ISO 27001 certified, and audited against HIPAA in the same review cycle as its SOC 2 Type II audit, though the public Trust Center page itself lists only SOC 2 and ISO 27001, not HIPAA',
751+
'SOC 2 Type II and ISO 27001 certified, and audited against HIPAA in the same review cycle, though the public Trust Center page itself lists only SOC 2 and ISO 27001, not HIPAA',
752752
detail:
753753
'The Trust Center confirms SOC 2 Type II and ISO 27001, DPAs with OpenAI and Anthropic, and a May 2025 penetration test with a Low risk rating. A separate StackAI blog post states the company "was also audited against HIPAA standards during the same period as the SOC 2 Type II audit." GDPR compliance is referenced on the Enterprise pricing page but has no dedicated audit source.',
754-
shortValue: 'ISO 27001 certified; HIPAA audited, GDPR marketing-only',
754+
shortValue: 'SOC 2 Type II and ISO 27001 certified; HIPAA audited, GDPR marketing-only',
755755
confidence: 'estimated',
756756
sources: [
757757
{ url: 'https://trust.stackai.com/', label: 'StackAI Trust Center', asOf: '2026-07-02' },

apps/sim/lib/compare/data/competitors/tines.ts

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -842,8 +842,8 @@ export const tinesProfile: CompetitorProfile = {
842842
},
843843
additionalCompliance: {
844844
value:
845-
'ISO 27001, ISO 27701, and ISO 42001 (AI management systems), announced April 14, 2026 as the "ISO trifecta." No HIPAA, PCI, or FedRAMP certification; Tines says self-hosting can help meet regimes like FedRAMP, not that it holds FedRAMP certification',
846-
shortValue: 'ISO 27001, 27701, and 42001 certified',
845+
'SOC 2 Type II, audited annually, plus ISO 27001, ISO 27701, and ISO 42001 (AI management systems), announced April 14, 2026 as the "ISO trifecta." No HIPAA, PCI, or FedRAMP certification; Tines says self-hosting can help meet regimes like FedRAMP, not that it holds FedRAMP certification',
846+
shortValue: 'SOC 2 Type II; ISO 27001, 27701, and 42001 certified',
847847
confidence: 'verified',
848848
sources: [
849849
{

0 commit comments

Comments
 (0)