generated: '2026-08-05' method: searched probe: true url: https://trust.read.ai/ description: >- Read AI runs a Vanta-hosted Trust Center at trust.read.ai. The page itself is a client-rendered single-page app — the only text a fetch returns is the title "Read AI Trust Center", and every /api/* path answers 200 with the same HTML shell — so the certification list below is taken from Read AI's own Security & Privacy Overview help article, which names what the Trust Center holds. The documents themselves are behind the Trust Center's request/NDA flow and were not fetched. platform: Vanta certifications: - name: SOC 2 Type 2 claimed_at: https://support.read.ai/hc/en-us/articles/25702259763091-Security-Privacy-Overview artifact_access: request via https://trust.read.ai/ - name: HIPAA note: Listed as an Enterprise+ plan capability; BAA available. claimed_at: https://www.read.ai/plans-pricing - name: GDPR claimed_at: https://support.read.ai/hc/en-us/articles/25702259763091-Security-Privacy-Overview - name: EU-U.S. Data Privacy Framework claimed_at: https://support.read.ai/hc/en-us/articles/25702259763091-Security-Privacy-Overview independently_verifiable_at: https://www.dataprivacyframework.gov/list documents_referenced: - SOC 2 Type 2 report - Data Processing Agreement - Other compliance forms related_public_pages: - {name: Security & Privacy Overview, url: 'https://support.read.ai/hc/en-us/articles/25702259763091-Security-Privacy-Overview'} - {name: Data Processing Addendum, url: 'https://www.read.ai/data-processing-addendum'} - {name: Privacy Policy, url: 'https://www.read.ai/privacy-policy'} - {name: 'Workspace Audit Logs (OCSF 1.7.0)', url: 'https://support.read.ai/hc/en-us/articles/50196944604563-Workspace-Audit-Logs-Event-Types-and-Schema'} security_practices_claimed: - Regular SOC 2 audits and penetration tests - Encryption in transit and at rest - Data stored in AWS us-east-1 (Northern Virginia, USA) - SSO, SAML, SCIM and two-factor authentication - User-set data retention policies - Customer data not used to train AI models evidence: - {source: 'https://trust.read.ai/', http_status: 200, observed: 'Vanta trust-report SPA; title "Read AI Trust Center"'} - {source: 'https://support.read.ai/hc/en-us/articles/25702259763091-Security-Privacy-Overview', http_status: 200, keywords: ['soc 2 type 2', 'trust center', 'data privacy framework', gdpr, hipaa, 'penetration tests']} x-evidence: fetched: '2026-08-05' note: >- The automated probe (0-working/probe-security-programs.py) returned trust=none because the SPA body carries fewer than two trust keywords. This file supersedes that null with a docs-searched result.