Rubrik, Inc. is an American cloud data management and data security company based in Palo Alto, California, founded in January 2014.
Summary from Wikipedia.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 1
Publicly advertised on the organization’s trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
ISO 27001
International standard for an information security management system, certified by accredited bodies.
-
ISO 27017
Publicly advertised on the organization’s trust center.
-
ISO 27018
Publicly advertised on the organization’s trust center.
-
ISO 27701
Publicly advertised on the organization’s trust center.
-
ISO 42001
International standard for AI management systems. Adoption is early; advertising it is a notable signal.
-
HIPAA
Public claim of compliance with US health-data privacy and security rules. HIPAA has no certification; compliance is self-attested.
-
FedRAMP
Publicly advertised on the organization’s trust center.
-
TX-RAMP
Texas state authorization program for cloud products used by state agencies.
-
HITRUST
Publicly advertised on the organization’s trust center.
-
TISAX
Publicly advertised on the organization’s trust center.
-
CSA STAR
Publicly advertised on the organization’s trust center.
-
EU-US DPF
Publicly advertised on the organization’s trust center.
-
C5
Publicly advertised on the organization’s trust center.
Compliance timeline
-
2013
Company founded
-
September 8, 2026
Posture last observed by Trust Index
Security & compliance hiring
Open roles on the organization’s public job board, a signal of active investment in security and compliance.
- Manager, Global Deal Operations & Governance
- Staff Cloud Security Architect
- Staff Platform Product Manager, Platform & Cloud Security
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.