llmcloud.ai
Trust · Certifications

Honest status. Public roadmap.

We only claim what we can evidence. Where a program is in progress, we say so — and share the current gap-assessment under NDA.

MVP · join waitlist

This page is maintained by llmcloud.ai and is not an independent certification. No badge on this page implies audit completion. Requests for evidence bundles and letters of engagement go through your account team.

ProgramStatusTargetScope
SOC 2 Type IIIn progressQ1 2027 (Type I target: Q3 2026)Security, availability, confidentiality trust services criteria across the managed gateway.
ISO/IEC 27001:2022In progressQ2 2027ISMS covering product engineering, cloud infrastructure and customer support.
ISO/IEC 42001 (AI Management System)RoadmapType I: Q4 2026AI-specific management system covering model catalog, routing, guardrails.
HIPAA BAAAvailable under NDAAvailable today for eligible plansBAA covers PHI processed via BAA-signed upstream providers, HIPAA-scoped log store, retention controls.
PCI DSS SAQ DIn progressQ2 2027Applies to card-data adjacent flows. Cardholder data is blocked at the router today — use tokenized references.
GDPR / EU-US DPFAvailable under NDADPA, SCCs and DPF self-cert available todayData-processor role for customer content. DPF certification for US-EU transfers.
DORA readinessIn progressJanuary 2027 applicabilityICT third-party register, incident-reporting SLAs, operational-resilience testing hooks.
FedRAMP ModerateRoadmapIn-process listing target: 2027Gov-cloud region + sponsor required. Self-host recommended in the interim.
IRAP (Australia)RoadmapAssessment target: 2027PROTECTED-level assessment for Sydney region.
C5 (Germany)RoadmapAssessment target: 2027BSI C5 attestation for the EU-Frankfurt region.
How do I get a copy of a report?+

Sign our mutual NDA (available click-through). Reports and letters of engagement are then shared through the trust portal.

Can I use llmcloud.ai in a regulated workload before you're certified?+

Yes if your framework permits. Many buyers accept documented controls, contractual commitments (DPA/BAA) and self-hosted deployments during a vendor's certification runway. Discuss with your compliance team.

Do subprocessors need to be certified too?+

Yes — see Subprocessors. Every upstream we route to lists its own certifications, and provider allow-lists in your policy can require specific ones.