Security

Compliance & Certifications

Last reviewed: July 2026

TL;DR

User Intuition complies today with GDPR, the CCPA and CPRA, and the Virginia, Colorado, Connecticut, and Utah state privacy laws. User Intuition's SOC 2 Type II examination is underway: an independent attestation firm is engaged, the SOC 2 control set is implemented, and the examination is progressing — User Intuition is not yet SOC 2 certified. A third-party HIPAA assessment is underway, and ISO 27001 is on the 2026 roadmap. All nine User Intuition sub-processors are SOC 2 Type 2 certified, and a SOC 2 engagement letter and control-inventory summaries are available under NDA.

Certifications status

  • SOC 2 Type II — Examination underway. We have engaged an independent SOC 2 attestation firm, implemented the SOC 2 control set, and are progressing through the examination. User Intuition is not yet SOC 2 certified. A SOC 2 engagement letter, control-inventory summaries, and current status are available under NDA via security@userintuition.ai.
  • ISO 27001: Roadmap 2026.
  • HIPAA — Third-party assessment underway. User Intuition is not a HIPAA-certified entity and does not sign a Business Associate Agreement directly. Our customer authentication provider Clerk and our voice provider both offer HIPAA Business Associate Agreements; the voice integration runs in HIPAA-enabled mode for all User Intuition assistants.
  • EU-US Data Privacy Framework self-certification: Roadmap 2026. We currently rely on Standard Contractual Clauses for cross-border transfers, as documented in our privacy policy.
  • Cyber liability insurance: Roadmap 2026.

Need to begin before our SOC 2 Type II examination completes? User Intuition also offers fully managed research — you send a brief by email and receive transcripts, reports, and deliverables by email or secure link, with no account and no platform access required.

Regulations we comply with today

  • EU General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
  • Virginia Consumer Data Protection Act (VCDPA)
  • Colorado Privacy Act (CPA)
  • Connecticut Data Privacy Act (CTDPA)
  • Utah Consumer Privacy Act (UCPA)

Compliance is verified through our internal Data Privacy Compliance Policy, reviewed annually, and an independent GDPR assessment is underway to formalize this posture. Data subject requests (access, deletion, portability) are honored at privacy@userintuition.ai.

Sub-processor compliance

All nine sub-processors are SOC 2 Type 2 certified. Clerk (our customer authentication provider) and our voice provider additionally offer HIPAA Business Associate Agreements. The full list, including provider names, is on our sub-processors page.

Customer audit rights

The sub-processor list is public at /sub-processors/. For enterprise customers under signed master agreement, additional security artifacts are available under NDA via security@userintuition.ai — including policy summaries, vulnerability scan summaries, the SOC 2 engagement letter, control inventory, and current examination status. Customer audit rights against User Intuition systems will be available alongside our SOC 2 Type II report.

← Back to Security & Trust