Is ClickUp Brain ISO 27001 certified?
YesClickUp · Productivity
Yes. ClickUp is ISO/IEC 27001 certified for ClickUp Brain, the international information-security management standard.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- ISO/IEC 27001
- Confirmed
- ClickUp reports ISO/IEC 27001 certification. Ask for scope and current certificate dates before treating it as supplier assurance.
- SOC 2
- Confirmed
- ClickUp also reports a SOC 2 attestation, which can complement but does not replace ISO scope evidence.
- Default data training
- No by default
- ClickUp's AI partners are prohibited from using your data to train their models, and ClickUp gains no right to use Customer Data for training; zero third-party data retention.
- Business-tier training
- No by default
- Enterprise (HIPAA BAA, EU and APAC residency and full compliance-report access are Enterprise-gated) is the business tier recorded for this profile.
Practical risk: ClickUp Brain does not train on customer data and enforces zero data retention with its LLM partners, backed by SOC 2 Type II and ISO 27001. HIPAA BAA and EU and APAC data residency are available but Enterprise-tier only.
How to make a decision
Check the precise account tier, written contract and intended data before approving ClickUp Brain. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on ClickUp Brain
Is ClickUp Brain HIPAA compliant?Is ClickUp Brain GDPR compliant?Is ClickUp Brain SOC 2 compliant?Does ClickUp Brain train on your data?
See the full ClickUp Brain risk profile, with every data-handling fact and its source, or browse all rated AI tools.