SOC 2 Type II
In progress. Formal attestation is not complete. Request the current security packet and available evidence for your supplier review.
Compliance status
Deployment inside a customer-controlled environment can reduce new data flows. It does not transfer certifications or remove customer obligations. This page states current Calliope AI status separately from the controls available in a deployment.
In progress. Formal attestation is not complete. Request the current security packet and available evidence for your supplier review.
BAA available on request. BYOC can keep Workbench and workload data inside a customer HIPAA-scoped environment. Customers remain responsible for model destinations, access, operating controls, and their own compliance obligations.
Controls aligned. A DPA and subprocessor list are available. Customers select deployment region and model endpoints to meet their own residency, transfer, and lawful-processing requirements.
Roadmap. Calliope AI is not currently ISO 27001 certified. Available security documentation can be reviewed against your supplier requirements.
Not certified. A customer may scope BYOC inside its own PCI environment, subject to its architecture, assessor, service-provider dependencies, and operating controls.
Evaluating. No FedRAMP authorization is claimed. Public-sector and isolated deployment requirements must be scoped with the customer.
Stop choosing between moving fast and staying in control.
See how it works →