Is HeyGen ISO 27001 certified?
UnverifiedHeyGen · Video
Not verified. We could not confirm an ISO/IEC 27001 certification for HeyGen.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- ISO/IEC 27001
- Not verified
- No public ISO/IEC 27001 certification was confirmed. Request evidence from HeyGen if this is a procurement requirement.
- SOC 2
- Confirmed
- HeyGen also reports a SOC 2 attestation, which can complement but does not replace ISO scope evidence.
- Default data training
- Opt-out required
- Non-enterprise inputs and outputs may be used to train and improve HeyGen's avatar models; consumer users can request opt-out by emailing [email protected].
- Business-tier training
- No by default
- Enterprise customer data is excluded from training by default under the Master SaaS Agreement.
Practical risk: HeyGen holds SOC 2 Type II and stays US only. On consumer plans HeyGen may use your inputs to improve its models unless you email to opt out, and there is no BAA, so keep PHI out of it.
How to make a decision
Check the precise account tier, written contract and intended data before approving HeyGen. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on HeyGen
Is HeyGen HIPAA compliant?Is HeyGen GDPR compliant?Is HeyGen SOC 2 compliant?Does HeyGen train on your data?
See the full HeyGen risk profile, with every data-handling fact and its source, or browse all rated AI tools.