Certification status
For audit reports, attestation letters, and signed agreements (DPA, BAA), contact our team. NDA required before sensitive documentation is shared.
SOC 2 Type II
xpander.ai is SOC 2 Type II certified. The audit covers the Trust Services Criteria for Security, Availability, and Confidentiality, meaning an external auditor evaluated xpander’s controls over a period of time, not just on a single date, and confirmed they operated as designed. The report covers logical and physical access, encryption in transit and at rest, change management, incident response, backup and disaster recovery, and vendor management. The full report is available to current and prospective enterprise customers under NDA. Request the SOC 2 report.GDPR
Data residency is determined by deployment choice. In the Hybrid or Air-gapped deployment, runtime data (task execution, memory, knowledge base contents, audit logs) stays in the region you operate. Hybrid additionally syncs agent definitions, the skills catalog, and heartbeats with xpander Cloud - see what leaves the on-prem installation. xpander Cloud customers can request region-specific deployment for their workspace. Right to erasure and portability are exposed through the API and Xpander Chat: conversation history, knowledge base documents, and user memories can be deleted on request; agent configurations and task history can be exported in standard formats. Controller relationships depend on the deployment model. For Managed Runtime customers (xpander Cloud), xpander is the data processor and the customer is the controller. For Unmanaged Runtime customers using their own AI service provider with private skills, the customer is the controller and xpander’s privacy policy doesn’t extend to those processing activities. See the Privacy Policy for the full breakdown. DPAs and sub-processor lists are available with enterprise contracts.HIPAA, ISO 27001, FedRAMP
These three are in progress. While formal attestation is being completed, customers commonly bring xpander.ai under their own compliance program by deploying in their own infrastructure.- HIPAA: technical controls for handling PHI (encryption at rest and in transit, audit logging of all data access, isolation of customer data) are in place under SOC 2 coverage. Formal HIPAA attestation and Business Associate Agreement program in progress. For healthcare deployments that need PHI to stay in customer-controlled infrastructure, contact us about BAA availability and deployment configuration: Hybrid or Air-Gapped.
- ISO 27001: most control families overlap with SOC 2 Type II coverage. Certification in progress.
- FedRAMP: federal customers deploying under their existing Authority to Operate (ATO) use the Hybrid or Air-gapped deployment, which keeps data inside infrastructure their ATO already covers, while formal FedRAMP authorization is being completed.
Deployment patterns by industry
Cloud Architecture
xpander cloud: TLS at ingress, managed keys, GDPR processor/controller
Hybrid Architecture
Data plane in your VPC; catalog and heartbeat sync to Cloud
Air-Gapped Architecture
Zero egress to xpander Cloud; signed Ed25519 license in-cluster
Supporting documentation
To request anything from this list, contact our team and describe what your security or compliance review needs. Enterprise customers receive ongoing access to compliance updates as new certifications complete.

