ReflexAI helps teams train, perform, and improve in the moments that matter most
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
HIPAA
Public claim of compliance with US health-data privacy and security rules. HIPAA has no certification; compliance is self-attested.
-
HITRUST
Publicly advertised on the organization’s trust center.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
-
ISO 27001
International standard for an information security management system, certified by accredited bodies.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Reflexai discloses on its trust center. Linked entries have their own profile in the Trust Index.
71% chain trust: 10 of 14 disclosed subprocessors are themselves in the Trust Index.
- Anthropic AI-powered content and response generation
- Amazon Business Cloud hosting and data storage
- Amplitude User behavior analytics for product usage tracking
- Auth0 User authentication and identity management
- Okta User authentication and identity management
- Datadog Application performance monitoring
- Deepgram Speech-to-text transcription for audio data
- ElevenLabs Text-to-speech / AI voice generation for audio content
- Google Cloud Platform Cloud hosting and data storage
- HubSpot CRM, customer journey management, and marketing
- Langfuse LLM observability, tracing, and monitoring of AI interactions
- OpenAI AI-powered content and response generation
- Twilio Segment Customer data platform and tracking management
- Twilio SMS, voice, and other communication services
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.