ModelCharter

Is Vapi ISO 27001 certified?

Unverified

Vapi · Audio

Not verified. We could not confirm an ISO/IEC 27001 certification for Vapi.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

ISO/IEC 27001
Not verified
No public ISO/IEC 27001 certification was confirmed. Request evidence from Vapi if this is a procurement requirement.
SOC 2
Confirmed
Vapi also reports a SOC 2 attestation, which can complement but does not replace ISO scope evidence.
Default data training
Opt-out required
By default, call recordings, transcripts and logs may be retained to help train and improve the AI models. Enabling HIPAA mode (hipaaEnabled true) disables data persistence entirely, which stops this use.
Business-tier training
Opt-out required
Any plan with HIPAA mode (hipaaEnabled true) enabled and only HIPAA-compliant provider keys configured: a per-assistant configuration flag, not a separate paid tier. is the business tier recorded for this profile.
Practical risk: Vapi's default configuration retains call data and can use it to improve the service; you have to explicitly turn on HIPAA mode to disable storage and training use, and even then you choose HIPAA-compliant providers yourself. Treat it as developer infrastructure that requires deliberate configuration.

How to make a decision

Check the precise account tier, written contract and intended data before approving Vapi. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Vapi

See the full Vapi risk profile, with every data-handling fact and its source, or browse all rated AI tools.