ModelCharter

Is Decagon SOC 2 compliant?

Unverified

Decagon · Customer support

Not verified. Decagon has not published a SOC 2 report we could confirm for Decagon.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

SOC 2 report
Not verified
No public SOC 2 report was confirmed. Ask Decagon for current assurance evidence before approving sensitive use.
ISO 27001
Not verified
No ISO/IEC 27001 certification was confirmed in the sources reviewed for this profile.
Default data training
Not verified
Decagon enforces zero-day retention with LLM providers (no foundation-model training), but fine-tunes per-customer models on that customer's own historical conversations with PII removed (not cross-customer). No opt-in or opt-out is documented.
Business-tier training
Not verified
No separate business tier was confirmed for this profile.
Practical risk: Decagon confirms zero-day retention with its LLM providers and offers SSO with Okta and Entra, but its SOC 2, ISO 27001 and HIPAA claims appear only as badges without a primary source stating type, scope or date, and no subprocessor list or DPA was found publicly.

How to make a decision

Check the precise account tier, written contract and intended data before approving Decagon. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Decagon

See the full Decagon risk profile, with every data-handling fact and its source, or browse all rated AI tools.