Phase 01
NeuralSeek's attestation
SOC 2 Type II covers NeuralSeek at the vendor level and is audited annually. The report goes to reviewers under NDA rather than being published.
Certifications and frameworks
NeuralSeek holds one attestation: SOC 2 Type II, report under NDA. Every other framework describes what the product is built to meet inside your own environment.
NeuralSeek ships as containers you run in your own tenant — SaaS, private cloud, sovereign cloud, OpenShift, or fully air-gapped on-prem. It runs inside the compliance perimeter you already operate, so your controls extend to it and your data does not leave your firewall. Which is why the honest answer to “is it certified?” is two answers rather than one.
Held by NeuralSeek
Attested
SOC 2 Type II
Attested at the vendor level and audited annually. The report is available under NDA; it is not published for download.
Built to meet in your environment
The frameworks below are not certifications NeuralSeek holds. They are requirements the product is built to meet inside your environment, where your own controls and your own audit apply. FedRAMP is the one most often misread: NeuralSeek does not hold a FedRAMP authorization — the posture is gov-ready, on GovCloud-eligible topologies inside a boundary you operate.
These are control mappings, not compliance claims. Your obligations remain yours to validate, with your own counsel and your own auditor.
Where the line sits
A vendor attestation and a deployment inside your own perimeter answer different questions. Collapsing them into one badge row is how a framework list starts saying something nobody signed off on.
Phase 01
SOC 2 Type II covers NeuralSeek at the vendor level and is audited annually. The report goes to reviewers under NDA rather than being published.
Phase 02
Run as containers in your own tenant, NeuralSeek sits inside the perimeter you have already had audited — your network controls, your key management, your logging, your incident process.
Phase 03
Whether a framework is met in your environment is validated by your own auditor and your own counsel — not by a badge on a vendor's site.
Why there is no badge grid here: nine logos in a row, one of which is audited, reads as nine claims the moment it is skimmed — and procurement checks.
Short answers. Where the answer is no, it says no.
Yes, under NDA. It is not published for download — request it from the security team and they will route it. The attestation is at the vendor level and is audited annually.
No. ISO 27001 is a framework NeuralSeek is built to meet inside your environment, not a certificate it has been issued. If your own organisation is certified, NeuralSeek runs as a workload inside that boundary under the controls you already operate — what that means for the scope of your certification is a question for your auditor, not for us.
No. NeuralSeek does not hold a FedRAMP authorization. What it offers is a gov-ready posture: containers deployed on GovCloud-eligible topologies inside a boundary you operate, rather than a service we host on your behalf. Treat a FedRAMP requirement as a question about your own environment.
To the security team, at the address on the Trust Center. The SOC 2 report, the security whitepaper and the DPA cover most of what a standard questionnaire asks; anything they do not is routed to the person who can answer it.
Talk to a NeuralSeek expert about how it fits your stack, where your data has to live, and the governance your auditors already expect.