SOC2C

Is this your company? Buyers are checking Hypatos GmbH here. Claim hypatos.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Hypatos GmbH logo

Hypatos GmbH

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Hypatos GmbH is SOC 2 Type II compliant. Hypatos GmbH also holds ISO 27001, ISO 27017, ISO 27018, HIPAA, GDPR, and CSA STAR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to our Trust Center. This page reflects our commitment to transparency and building trust with our customers, and offers you comprehensive information and assurance regarding our ability to safeguard your data. Here you can find our compliance documentation, overview of security controls, answers to frequently asked questions and more. Hypatos Cloud has been independently verified for compliance with SOC 2, HIPAA, GDPR and C5, and holds certifications for ISO 27001, ISO 27017, and ISO 27018. Our enterprise-grade cloud service has been developed for high availability, with SLAs of up to

Compliance & infrastructure

SOC 2 Type IIISO 27001ISO 27017ISO 27018HIPAAGDPRCSA STAR
Hosting
AWSGCP
Data handled
Data contained in documents uploaded to Hypatos Cloud platform

Documents

8

Subprocessors

6
  • A
    Amazon Web Services · Infrastructure as a Service (IaaS) provider for Hypatos Cloud services.
    EU and US
  • M
    MongoDB Atlas · Cloud database service used to store customer documents data
    EU and US
  • G
    Google Cloud Platform · LLM services used for AI-based information extraction
    EU and US
  • M
    Microsoft 365 · LLM services used for AI-based information extraction
    EU and US
  • J
    Jira · Service desk for customer support; processing of customer-provided data as part
    EU and US
  • S
    Sinch · Email notification dispatch service for emails sent to customers by Hypatos Clou
    EU and US

Compliance leadership

The person who leads Hypatos GmbH's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Hypatos GmbH's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

New Security Certifications AchievedJun 2025

We’re pleased to announce that following our successful master audit in April, we have renewed our SOC 2, HIPAA, and ISO 27001 certifications. We’ve also added three new certifications: BSI C5, ISO 27017, and ISO 27018. All reports and certificates are now available on our Trust Center.

Common Security Concerns About AI Document Processing - And How Hypatos Resolves ThemFeb 2025

https://www.hypatos.ai/blog/common-security-concerns-about-ai-document-processing--and-how-hypatos-resolves-them

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Hypatos GmbH SOC 2 compliant?
Hypatos GmbH is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Hypatos GmbH ISO 27001 certified?
According to Hypatos GmbH's public trust center, Hypatos GmbH is ISO 27001 certified. On SOC2C this listing is Listed.
Is Hypatos GmbH ISO 27017 certified?
According to Hypatos GmbH's public trust center, Hypatos GmbH is ISO 27017 certified. On SOC2C this listing is Listed.
Is Hypatos GmbH ISO 27018 certified?
According to Hypatos GmbH's public trust center, Hypatos GmbH is ISO 27018 certified. On SOC2C this listing is Listed.
Is Hypatos GmbH HIPAA compliant?
According to Hypatos GmbH's public trust center, Hypatos GmbH is HIPAA compliant. On SOC2C this listing is Listed.

Answers published by Hypatos GmbH

Reproduced from Hypatos GmbH's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What is Hypatos, and how do we use AI?
Hypatos is a software company that specializes in advanced document processing and intelligent process automation. Our AI Agents leverage LLM combined with RAG, prompting and tooling to streamline repetitive, manual tasks, such as invoice processing, document classification, data extraction, master data matching. Our solutions help organizations achieve greater accuracy, operational efficiency, and cost savings.
How is customer data handled?
_Data processed by third-party LLM Providers:_ We only utilise reputable LLM providers that have strict privacy standards in place - any data submitted via API to them is used solely to process the specific request and is not retained or used for training or improving their AI models. Hypatos is only using their base/pretrained models, which are stateless, meaning no prompts or output are stored in the models –after an output is generated, the prompt is immediately discarded. _Data processed and stored by Hypatos:_ By default, documents uploaded by customers to Hypatos Cloud are retained for 6 months. After this period, all data is automatically and permanently deleted. Documents used as a knowledge base may be retained for longer periods based on customer preferences, to ensure that the AI has access to sufficient customer-specific reference data so Hypatos can provide the highest quality and accuracy of services. Customer data is logically segregated between customers on the database layer and all locations where customer data is stored are encrypted using AES-256.
Does Hypatos use customer data to train AI models?
No. Our approach does not involve the conventional sense of “training” a model on customer data. Instead, we leverage pre-existing foundation large language models (LLMs) that are not retrained with customer-specific data. Our method uses in-context learning and advanced retrieval-augmented generation (RAG), which means that the model draws from relevant information provided during specific interactions without modifying the model itself or creating a customer-tailored generative model.
Where is the Hypatos infrastructure hosted?
Hypatos hosts its cloud services on servers provided by Amazon Web Services (AWS). Customers can select between two AWS Regions for hosting their data based on data residency requirements: - eu-west-1 (Europe - Ireland) - us-east-1 (US - N.Virginia)
Do you provide Service Level Agreements (SLAs) for availability your cloud services?
Hypatos commits to offer availability Service Level Agreements (SLAs) between 98% and 99.5% depending on the subscription plan selected by the customer.

Business & Industrial peers that completed SOC 2