Honest status. Public roadmap.
We only claim what we can evidence. Where a program is in progress, we say so — and share the current gap-assessment under NDA.
This page is maintained by llmcloud.ai and is not an independent certification. No badge on this page implies audit completion. Requests for evidence bundles and letters of engagement go through your account team.
| Program | Status | Target | Scope |
|---|---|---|---|
| SOC 2 Type II | In progress | Q1 2027 (Type I target: Q3 2026) | Security, availability, confidentiality trust services criteria across the managed gateway. |
| ISO/IEC 27001:2022 | In progress | Q2 2027 | ISMS covering product engineering, cloud infrastructure and customer support. |
| ISO/IEC 42001 (AI Management System) | Roadmap | Type I: Q4 2026 | AI-specific management system covering model catalog, routing, guardrails. |
| HIPAA BAA | Available under NDA | Available today for eligible plans | BAA covers PHI processed via BAA-signed upstream providers, HIPAA-scoped log store, retention controls. |
| PCI DSS SAQ D | In progress | Q2 2027 | Applies to card-data adjacent flows. Cardholder data is blocked at the router today — use tokenized references. |
| GDPR / EU-US DPF | Available under NDA | DPA, SCCs and DPF self-cert available today | Data-processor role for customer content. DPF certification for US-EU transfers. |
| DORA readiness | In progress | January 2027 applicability | ICT third-party register, incident-reporting SLAs, operational-resilience testing hooks. |
| FedRAMP Moderate | Roadmap | In-process listing target: 2027 | Gov-cloud region + sponsor required. Self-host recommended in the interim. |
| IRAP (Australia) | Roadmap | Assessment target: 2027 | PROTECTED-level assessment for Sydney region. |
| C5 (Germany) | Roadmap | Assessment target: 2027 | BSI C5 attestation for the EU-Frankfurt region. |
How do I get a copy of a report?+
Sign our mutual NDA (available click-through). Reports and letters of engagement are then shared through the trust portal.
Can I use llmcloud.ai in a regulated workload before you're certified?+
Yes if your framework permits. Many buyers accept documented controls, contractual commitments (DPA/BAA) and self-hosted deployments during a vendor's certification runway. Discuss with your compliance team.
Do subprocessors need to be certified too?+
Yes — see Subprocessors. Every upstream we route to lists its own certifications, and provider allow-lists in your policy can require specific ones.