Glean is the Enterprise AI platform connected to your enterprise's data. Find, create, and automate anything. Explore what Glean can do for you!
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
ISO 27001
International standard for an information security management system, certified by accredited bodies.
-
ISO 42001
International standard for AI management systems. Adoption is early; advertising it is a notable signal.
-
HIPAA
Public claim of compliance with US health-data privacy and security rules. HIPAA has no certification; compliance is self-attested.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Glean discloses on its trust center. Linked entries have their own profile in the Trust Index.
83% chain trust: 15 of 18 disclosed subprocessors are themselves in the Trust Index.
- Google LLC Cloud Service Provider / LLM Provider
- Amazon Web Services Cloud Service Provider / LLM Provider
- Microsoft Corporation Cloud Service Provider / LLM Provider
- Intercom, Inc. Cloud-based Customer Support Services
- Twilio Inc. Communication Services
- Salesforce Inc. CRM
- Slack Technologies, LLC Customer Communications
- Zendesk Inc. Customer Support Portal
- Sendgrid, Inc Email Provider
- Anthropic PBC LLM Provider
- Fireworks.ai, Inc. LLM Provider
- Groq Inc. LLM Provider
- OpenAI OpCo, LLC LLM Provider
- Brave Software Inc. Search
- Palo Alto Networks, Inc. AI security provider (Prisma AI Runtime Security)
- Snowflake, Inc. LLM Provider
- Exa Labs, Inc. Web crawling and rendering
- Deepgram, Inc. Speech-to-text transcription
Named as a subprocessor by
Organizations in the Trust Index that disclose Glean as a subprocessor.
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.