Is Ada SOC 2 compliant?
YesAda · Customer support
Yes. Ada holds a SOC 2 report covering Ada, which gives independent assurance over its security controls.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- SOC 2 report
- Confirmed
- Ada reports a SOC 2 attestation. Request the current report and relevant bridge letter during procurement.
- ISO 27001
- Not verified
- No ISO/IEC 27001 certification was confirmed in the sources reviewed for this profile.
- Default data training
- No by default
- Customer data is never used to train shared or public models; zero data retention with LLM providers, and any fine-tuning uses a single customer's own de-identified data. Ada is enterprise-only, so there is no consumer tier.
- Business-tier training
- No by default
- Enterprise (the only tier) with an executed DPA, HIPAA documentation obtained during procurement, and a negotiated EU data-residency clause is the business tier recorded for this profile.
Practical risk: Ada is enterprise-only and says it never trains shared models on your data, holds SOC 2 Type II, publishes subprocessors and offers HIPAA documentation and negotiated EU residency. The open questions are ISO 27001 (not listed on its trust center) and confirming a named BAA before regulated deployment.
How to make a decision
Check the precise account tier, written contract and intended data before approving Ada. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Ada
Is Ada HIPAA compliant?Is Ada GDPR compliant?Is Ada ISO 27001 certified?Does Ada train on your data?
See the full Ada risk profile, with every data-handling fact and its source, or browse all rated AI tools.