generated: '2026-09-06' method: searched probe: true url: https://trust.dremio.com/ http_status: 200 verified: '2026-09-06' title: Dremio Corporation Trust Center certifications: - SOC 2 Type 2 - ISO/IEC 27001:2022 - HIPAA evidence: - source: https://trust.dremio.com/ status: 200 kind: trust center note: >- Live and titled "Dremio Corporation Trust Center". The page is JS-rendered — the served HTML is a ~6KB shell carrying only the title — so the certification list below was read from Dremio's public security page rather than scraped from the trust center itself. The automated keyword probe (probe-security-programs.py) recorded trust=none for exactly that reason; this file is the searched correction. - source: https://www.dremio.com/platform/security/ status: 200 kind: security page keywords: - SOC 2 Type 2 - ISO/IEC 27001:2022 - HIPAA - responsible disclosure detail: soc2: >- Dremio maintains compliance with AICPA SOC 2 Trust Services Criteria and makes the SOC 2 Type 2 report available on request through an account or sales representative. iso27001: >- Dremio operates an ISMS conforming to ISO/IEC 27001:2022; the certificate is available on request through an account or sales representative. hipaa: >- Dremio describes itself as HIPAA-ready, enabling covered entities and business associates to analyze PHI on the platform. This is a readiness statement, not a certification. security_assurance: >- SAST and third-party dependency scanning on every build, periodic automated scans on daily builds, and vulnerability scanning of containers and images. security_bulletins: >- Security notifications are published under a Security Bulletins section, with security fixes and supply-chain/vendor/dependency responses listed in the release notes. gap: >- Nothing is self-serve. Both the SOC 2 report and the ISO 27001 certificate require contacting sales, so a buyer cannot verify either without entering a sales conversation.