Effortlessly centralize all the data you need so your team can deliver better insights, faster. Start for free.
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
-
HIPAA
Public claim of compliance with US health-data privacy and security rules. HIPAA has no certification; compliance is self-attested.
-
CCPA
Publicly advertised on the organization’s trust center.
-
HITRUST
Publicly advertised on the organization’s trust center.
-
ISO 27701
Publicly advertised on the organization’s trust center.
-
SOC 1
Publicly advertised on the organization’s trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Security & compliance hiring
Open roles on the organization’s public job board, a signal of active investment in security and compliance.
- Compliance, Employment & Litigation Counsel
- Compliance, Employment & Litigation Counsel
- Compliance, Employment & Litigation Counsel
- Compliance, Employment & Litigation Counsel
- Compliance, Employment & Litigation Counsel
- Lead Sales Engineering Specialist - Security
- Technical Program Manager, Security
Named as a subprocessor by
Organizations in the Trust Index that disclose Fivetran as a subprocessor.
- Archonsystems
- Aurorasolar
- Aviron
- Binti
- Brightmove
- Calibermind
- Cartesia
- Chartbeat
- Clar
- Clay
- CodeRabbit
- Coincover
- Couchdrop
- Cube
- Cyberresilience
- Daily
- DataCamp
- Digits
- Dovetail
- Dreamdata
- Drivetrain
- DualEntry
- ElevenLabs
- Employmenthero
- Expanamarkets
- Fathom
- Flowinc
- Fyld
- Getzipline
- Gigs
- Happeo
- Joinmodernhealth
- Maze
- Oraion
- Perplexity
- Persefoni
- Planetscale
- Posit PBC
- Powerdigitalmarketing
- Graphcool, Inc
- Quantum Workplace
- Quartzy
- Saucelabs
- Scaledagile
- Tessl
- Xpon
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.