generated: '2026-07-19' method: searched source: https://www.fiddler.ai/security standards: - id: soc2-type-ii conforms: true evidence: >- SOC 2 Type II covering security, confidentiality, and availability; audited annually. Report available to customers/prospects under NDA. source: https://www.fiddler.ai/security - id: hipaa conforms: true evidence: Fiddler is compliant with the U.S. HIPAA regulation for handling PHI. source: https://www.fiddler.ai/blog/fiddler-is-now-hipaa-compliant - id: tls-encryption-in-transit conforms: true evidence: All communications encrypted with HTTPS/TLS 1.2 or higher. - id: aes256-encryption-at-rest conforms: true evidence: All data-at-rest encrypted with AES-256 (or higher). - id: oauth2 conforms: false evidence: API uses Bearer access-key authentication, not OAuth2 flows. - id: openid-connect conforms: false - id: rfc9457-problem-details conforms: false evidence: Uses a custom error envelope (code/message/errors[]), not application/problem+json. - id: iso-27001 conforms: false evidence: Not named on the public security page as of this pass. compliance_programs: - SOC 2 Type II - HIPAA