Onboarding a limited number of private deployments this quarter. Request access →
← Security

Compliance status

Know what is mapped, in progress, and not certified.

Deployment inside a customer-controlled environment can reduce new data flows. It does not transfer certifications or remove customer obligations. This page states current Calliope AI status separately from the controls available in a deployment.

Current status, framework by framework.

01

SOC 2 Type II

In progress. Formal attestation is not complete. Request the current security packet and available evidence for your supplier review.

02

HIPAA

BAA available on request. BYOC can keep Workbench and workload data inside a customer HIPAA-scoped environment. Customers remain responsible for model destinations, access, operating controls, and their own compliance obligations.

03

GDPR

Controls aligned. A DPA and subprocessor list are available. Customers select deployment region and model endpoints to meet their own residency, transfer, and lawful-processing requirements.

04

ISO 27001

Roadmap. Calliope AI is not currently ISO 27001 certified. Available security documentation can be reviewed against your supplier requirements.

05

PCI DSS

Not certified. A customer may scope BYOC inside its own PCI environment, subject to its architecture, assessor, service-provider dependencies, and operating controls.

06

FedRAMP

Evaluating. No FedRAMP authorization is claimed. Public-sector and isolated deployment requirements must be scoped with the customer.

Enterprises are scaling AI agents, data science, private LLMs and secure ML with Calliope AI

Self-host enterprise AI in days.

Stop choosing between moving fast and staying in control.

See how it works →