Is Vapi ISO 27001 certified?
UnverifiedVapi · Audio
Not verified. We could not confirm an ISO/IEC 27001 certification for Vapi.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- ISO/IEC 27001
- Not verified
- No public ISO/IEC 27001 certification was confirmed. Request evidence from Vapi if this is a procurement requirement.
- SOC 2
- Confirmed
- Vapi also reports a SOC 2 attestation, which can complement but does not replace ISO scope evidence.
- Default data training
- Opt-out required
- By default, call recordings, transcripts and logs may be retained to help train and improve the AI models. Enabling HIPAA mode (hipaaEnabled true) disables data persistence entirely, which stops this use.
- Business-tier training
- Opt-out required
- Any plan with HIPAA mode (hipaaEnabled true) enabled and only HIPAA-compliant provider keys configured: a per-assistant configuration flag, not a separate paid tier. is the business tier recorded for this profile.
Practical risk: Vapi's default configuration retains call data and can use it to improve the service; you have to explicitly turn on HIPAA mode to disable storage and training use, and even then you choose HIPAA-compliant providers yourself. Treat it as developer infrastructure that requires deliberate configuration.
How to make a decision
Check the precise account tier, written contract and intended data before approving Vapi. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Vapi
Is Vapi HIPAA compliant?Is Vapi GDPR compliant?Is Vapi SOC 2 compliant?Does Vapi train on your data?
See the full Vapi risk profile, with every data-handling fact and its source, or browse all rated AI tools.