SOC2C

Is this your company? Buyers are checking Forethought here. Claim forethought.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Forethought logo

Forethought

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Forethought is SOC 2 Type II compliant. Forethought also holds HIPAA, NIST CSF, GDPR, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Forethought uses AI to create a better self-service experience, improve routing and tagging, and help customer service agents deliver fast, accurate answers to new inquiries. More details at https://forethought.ai/

Compliance & infrastructure

Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

12

Compliance leadership

The person who leads Forethought's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Forethought's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Forethought SOC 2 compliant?
Forethought is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Forethought HIPAA compliant?
According to Forethought's public trust center, Forethought is HIPAA compliant. On SOC2C this listing is Listed.
Is Forethought NIST CSF compliant?
According to Forethought's public trust center, Forethought is NIST CSF compliant. On SOC2C this listing is Listed.
Is Forethought GDPR compliant?
According to Forethought's public trust center, Forethought is GDPR compliant. On SOC2C this listing is Listed.
Is Forethought CCPA compliant?
According to Forethought's public trust center, Forethought is CCPA compliant. On SOC2C this listing is Listed.

Answers published by Forethought

Reproduced from Forethought's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Is sensitive data (ex: PII, PHI, etc.) captured or stored with Forethought?
Forethought's services operate effectively without requiring personal data. For all data captured, Forethought carefully uses automation to redact sensitive data elements, such as Personally Identifiable Information (PII), Protected Health Information (PHI), and financial records (such as bank and credit card information), during the ingestion process in a secure environment. Once the redaction process is completed, the original data is securely deleted within 24 hours. While we make every effort to ensure that all sensitive data elements are removed, the redaction mechanisms are provided on a best effort basis. The final data used by Forethought should not contain any sensitive data elements.
FedRAMP compliant?
We are not FedRAMP compliant but have SOC2 audit report with controls aligned with NIST 800-53 Moderate level. In addition the services are built in AWS which is FedRAMP moderate authorized.
HIPAA Compliant?
Forethought controls and processes are aligned with the HIPAA requirements which can be demonstrated in the HIPAA Audit Report Report on Compliance with The HIPAA Security, Breach Notication, and Privacy Requirements. As required by OCR with all applicable entities (Covered entities and Business Associates) associate should follow the Minimum Necessary Requirements as set forth in 45 CFR 164.502(b), 164.514(d) and not send PHI data to Forethought if not required.
Did we not answer your question?
We have list of all our questions on this section of the Trust page. You can find more detailed information about Forethought’s architecture, security policies, and other technical information in the documents section. You can also contact us at [support@forethought.ai](mailto:support@forethought.ai) or reach out to your sales executive or customer success manager.
Do you have vulnerability disclosure and reward program?
Yes! Forethought maintains a private, invite-only bug bounty program, with the assistance of HackerOne. Invited researchers are eligible for a payment. Those who were not invited to the program may still submit a security bug or vulnerability to Forethought via this form.

Business & Industrial peers that completed SOC 2