Vespa is the AI Search Platform for fast, accurate AI search, AI agents, personalization, recommendations, and retrieval.
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
-
CCPA
Publicly advertised on the organization’s trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Vespa.ai discloses on its trust center. Linked entries have their own profile in the Trust Index.
67% chain trust: 4 of 6 disclosed subprocessors are themselves in the Trust Index.
- Auth0 External user identity management
- Amazon Web Services Cloud provider
- Google Cloud Platform Cloud provider
- GitHub Version control
- Google Workspace Collaboration suite
- JumpCloud Identity and IT asset management
Named as a subprocessor by
Organizations in the Trust Index that disclose Vespa.ai as a subprocessor.
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.