Is this your company? Buyers are checking LangChain Inc here. Claim langchain.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
LangChain Inc
Sourced from public information. Not yet verified by the company.
LangChain Inc is SOC 2 Type II compliant. LangChain Inc also holds GDPR, and HIPAA.
About
LangSmith is an all-in-one developer platform for every step of the LLM-powered application lifecycle, whether you’re building with LangChain or not. To track LangSmith & LangGraph Platform incidents and health, please go to: https://status.smith.langchain.com/
Compliance & infrastructure
Subprocessors
10- GGoogle Cloud Platform · Cloud providerUSA or Netherlands
- AAmazon Web Services · Cloud providerUSA
- CClickhouse · Production DatabaseUSA or Netherlands
- SSupabase · Database providerUS or Germany
- AAnthropic · AI model inferenceUSA
- BBaseten · AI model inferenceUSA
- FFireworks AI · AI model inferenceUSA
- OOpenAI · AI model inferenceUSA
- PPylon · Customer Support Ticketing and CommunicationUSA
- SStripe · Payment ProcessingUSA
Compliance leadership
The person who leads LangChain Inc's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. LangChain Inc's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
2026 May Subprocessor UpdatesMay 2026
Dear LangChain Customer, We are writing to inform you of additions to LangChain's subprocessor list in connection with LangSmith AI-powered features, including the LangSmith Engine and other in-product agents. *New Subprocessors (effective June 11, 2026, or upon earlier enablement):* - OpenAI, L.L.C. — to provide AI model inference services - Anthropic, PBC — to provide AI model inference services - Fireworks — to provide AI model inference services - Baseten — to provide AI model inference services These are the same providers previously announced for Fleet. Features using LangChain-managed keys are opt-in for enterprise customers. We have also added the following subprocessors to our list: - Pylon — to provide customer support ticketing and communication services (unrelated to AI features) - Stripe — to provide payment processing services for self-serve customers (unrelated to AI features) Our updated subprocessor list is available at our Trust Center. Questions? Contact [privacy@langchain.dev](mailto:privacy@langchain.dev). Thank you for being a valued customer. Regards, LangChain Privacy Team
No LangSmith impact: Vercel Security Incident (April 2026)Apr 2026
Vercel disclosed a security incident in which an attacker obtained access to a Vercel employee's account through a compromised third-party tool and accessed certain internal systems, including non-sensitive environment variables belonging to a limited subset of Vercel customers. LangSmith was not affected, and no customer data was at risk. What happened ------------- Per Vercel's published bulletin, an attacker compromised a third-party AI tool used by a Vercel employee, pivoted to that employee's Google Workspace account, and accessed certain Vercel internal systems along with non-sensitive environment variables for a limited subset of Vercel customers. Vercel has stated it has no evidence that sensitive (encrypted) environment variables were accessed. Vercel advised customers to rotate non-sensitive environment variables as a precaution, enable two-factor authentication, and review recent activity. Impact to LangSmith ------------------- LangSmith was not affected. LangSmith production — including its frontend, backend services, databases, and authentication systems — is not hosted on Vercel. We use Vercel for preview deployments of engineering branches, which are isolated from production systems and customer data. Following Vercel's initial notification, we nonetheless reviewed every environment variable across all LangChain Vercel projects. Variables already stored as…
No LangSmith impact: Axios npm supply chain attack (March 2026)Mar 2026
On March 30, 2026, a supply chain attack was discovered affecting Axios version 1.14.1 on npm — a highly popular JavaScript library used for making HTTP requests. The package was compromised with malicious code. LangChain was not affected by this event. Axios 1.14.1 is not a dependency in any of our commercial services, and no LangChain customer data was exposed. We're sharing this proactively because Axios is ubiquitous across the development ecosystem and many of our customers may use it independently. ### What happened Version 1.14.1 of the `axios` npm package was compromised to include malicious code. The issue was isolated to the package distributed on the npm registry and did not affect the official Axios source code on GitHub. ### Impact to LangSmith LangSmith was not affected. Upon learning of this event, we audited our commercial services and build pipelines to validate that Axios 1.14.1 was not present as a dependency. We confirmed the compromised version is not used anywhere in our infrastructure. We have no evidence of unauthorized access to customer data, credentials, or infrastructure of any kind. ### Impact to LangChain `@langchain/classic` (an open-source package) contains an `axios` dependency only used in local development, but pinned to a specific version inside of the project lockfiles. Systems that cloned the `langchainjs` monorepo and installed…
Security Advisory: API Key Revocation – Ongoing Supply Chain CampaignMar 2026
Security Advisory: API Key Revocation – Ongoing Supply Chain Campaign Date: March 28, 2026 Status: Resolved On March 28 00:21 UTC, LangChain's Security Team was notified by the Google Threat Intelligence Group (GTIG) that LangSmith API keys were exposed as part of TeamPCP's ongoing supply chain campaign. To date, this campaign has compromised several open source packages in order to harvest credentials and expand access. Neither LangChain open source software, nor LangSmith systems, were compromised. We confirm that we have no evidence of any key being used to access, read, or exfiltrate customer data. In response we investigated additional customer keys that might be leaked, and expired all customer keys that we identified to have any potential exposure to TeamPCP. We're proactively monitoring for additional signs of threat activity, and are actively revoking any keys that are believed to be compromised. --- ### Timeline — March 28, 2026 - ~00:21 UTC — LangChain received initial notification from GTIG - ~02:37 UTC — Initial investigation confirmed reported credentials were customer keys. - ~03:25 UTC — Expiration of keys began. - ~17:40 UTC — LangSmith hotfix applied to proactively expire leaked credentials. - ~18:42 UTC — All keys associated with TeamPCP activity expired. - ~21:40 UTC — Confirmed no evidence of unauthorized data access. --- ### Recommendations If you…
No LangSmith impact: LiteLLM PyPI supply chain attack (March 2026)Mar 2026
On March 24, 2026, a supply chain attack was discovered affecting LiteLLM versions 1.82.7 and 1.82.8 on PyPI — a widely used Python package for LLM API integrations. The malicious packages contained a credential-harvesting payload that executes automatically when installed. LangSmith was not affected by this event. LiteLLM is not a dependency of any of our commercial services, and no LangSmith customer data was exposed. We're sharing this proactively because LiteLLM is widely used across the AI ecosystem and some of our customers may use it independently. * * * ### What happened Versions 1.82.7 and 1.82.8 of the `litellm` PyPI package were published with a malicious `.pth` file embedded in the wheel. This file is designed to execute automatically on every Python process startup in environments where LiteLLM is installed. The full technical details are covered in this writeup by FutureSearch. The attack was absent from LiteLLM's official GitHub repository — only the PyPI-distributed packages were affected. The malicious code was capable of harvesting SSH keys, environment variables, cloud credentials (AWS, GCP, Azure), Kubernetes configurations, database connection strings, shell history, and local wallet files. * * * ### Impact to LangSmith LangSmith was not affected. Upon learning of this event, we audited our commercial services to validate that LiteLLM was not present as a…
This listing is partial
6/11 details · 55%SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is LangChain Inc SOC 2 compliant?
Is LangChain Inc GDPR compliant?
Is LangChain Inc HIPAA compliant?
Is LangChain Inc SOC 2 Type I or Type II?
Can I use LangChain Inc's SOC 2 for a vendor risk assessment?
Is LangChain Inc penetration tested?
Is LangChain Inc secure?
Does LangChain Inc have a bug bounty or vulnerability disclosure program?
Who are LangChain Inc's subprocessors?
Where does LangChain Inc host or store data?
Where is LangChain Inc's trust center or security page?
What certifications and attestations does LangChain maintain?
What data privacy frameworks and regulations does LangChain comply with
What deployment models are available?
Where can I get an overview of the general architecture?
Do you support Single Sign-On (SSO)?
Do you support SCIM Provisioning?
Do you support role-based access control?
Can customers choose which model providers they use?
Do LangChain Services use customer data to train AI models
Does LangSmith rely upon AI to deliver its services?
Do you have a Data Processing Addendum (DPA)?
How does LangChain protect data in transit and at rest?
Technology peers that completed SOC 2

Action1

ELJUN LLC

equipifi
