Is Decagon ISO 27001 certified?
UnverifiedDecagon · Customer support
Not verified. We could not confirm an ISO/IEC 27001 certification for Decagon.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- ISO/IEC 27001
- Not verified
- No public ISO/IEC 27001 certification was confirmed. Request evidence from Decagon if this is a procurement requirement.
- SOC 2
- Not verified
- No SOC 2 report was confirmed in the sources reviewed for this profile.
- Default data training
- Not verified
- Decagon enforces zero-day retention with LLM providers (no foundation-model training), but fine-tunes per-customer models on that customer's own historical conversations with PII removed (not cross-customer). No opt-in or opt-out is documented.
- Business-tier training
- Not verified
- No separate business tier was confirmed for this profile.
Practical risk: Decagon confirms zero-day retention with its LLM providers and offers SSO with Okta and Entra, but its SOC 2, ISO 27001 and HIPAA claims appear only as badges without a primary source stating type, scope or date, and no subprocessor list or DPA was found publicly.
How to make a decision
Check the precise account tier, written contract and intended data before approving Decagon. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Decagon
Is Decagon HIPAA compliant?Is Decagon GDPR compliant?Is Decagon SOC 2 compliant?Does Decagon train on your data?
See the full Decagon risk profile, with every data-handling fact and its source, or browse all rated AI tools.