Compliance evidence, verified before you buy
Every vendor’s compliance evidence, checked before you buy
SOC 2, ISO 27001, HIPAA, GDPR, FedRAMP and PCI DSS for any B2B software vendor: what it has, since when, audited by whom, and where the public evidence is, before you email sales.
By framework
The right question for each framework
HIPAA and BAA
No certification exists. The BAA is the artefact.

SOC 2
A report with a period and an auditor, never a certificate.
GDPR and DPA
DPA, SCCs, EU representative, Data Privacy Framework.
FedRAMP
Authorization status synced daily from the official data file.

PCI DSS
Registry listings with assessor and validation date.

ISO 27001
Certificate, scope and expiry; 2013-edition certificates flagged.
Evidence, not claims
Registry rows, auditor confirmations and vendor statements are kept apart and labelled. A badge on a marketing page is a claim until a primary source confirms it.
Dated and re-checked
Every row shows when it was captured and expires on its own terms: certificate expiry, report period, registry usage-end date.
Snapshot-backed
Click through from any state to the captured page, its content hash and a Wayback Machine citation.
Never "non-compliant"
CertReports states what is public. "No public evidence" is literally true and always comes with the explanation, plus a dispute link with a two-business-day SLA.
Most evidence, freshest
Vendors with registry-verified rows
The index is loading. Registry rows appear here as soon as the first sync completes.