Back to Guardra

Everything procurement asks for, in one place.

Reports, certificates, legal templates, SBOMs, subprocessor lists. If your team needs it to close the deal, it's here. Most items are gated by NDA — request via the portal.

SOC 2 Type II report (2025)

NDA required · 94 pages

Report

ISO 27001:2022 certificate

Issued: Mar 2026 · BSI

Cert

Annual penetration test summary

Bishop Fox · Feb 2026

Report

Red-team exercise (Q4 2025)

Partner: NCC Group

Report

Data Processing Agreement (DPA)

GDPR · CCPA compliant

Legal

Business Associate Agreement (BAA)

HIPAA · Enterprise+

Legal

Master Services Agreement

Enterprise template

Legal

Subprocessor list

Last updated Apr 2026

Policy

SBOM — Guardra v2.4.0

CycloneDX · Sigstore signed

Artifact

Service Level Agreement

99.99% Enterprise & Premium

Legal

Subprocessors

30-day advance notice before any change · email alerts on /contact

SubprocessorPurposeData region
AWSInfrastructure · data processingUS · EU · APAC
GCPLLM inference · vector storageUS · EU
CloudflareEdge · DDoS protectionGlobal
AnthropicLLM-as-judge (opt-in)US
OpenAILLM-as-judge (opt-in)US
StripeBillingUS
Auth0 (Okta)AuthenticationUS · EU
SentryError monitoring (scrubbed)US

Public status page

99.99% rolling 90-day uptime · updated in real time

status.guardra.ai