SOC2C

Is this your company? Buyers are checking Peppy Health here. Claim peppy.health free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Peppy Health logo

Peppy Health

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Peppy Health is SOC 2 compliant. Peppy Health also holds ISO 27001, and GDPR.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

Peppy Health is a trusted partner in personalised healthcare, offering secure and effective support to individuals and organisations alike. We prioritise the protection of your sensitive health information by adhering to the highest security standards and industry best practices. Our commitment to transparency, integrity, and data protection is demonstrated through the rigorous safeguards in place across all areas of our operations. We hope this trust centre provides clarity on our security practices, and we invite you to reach out with any questions using the contact information below.

Compliance & infrastructure

Hosting
GCP
Data handled
Customer personally identifiable informationPersonal health information

Documents

1

Subprocessors

11
  • G
    Google Cloud Platform · Cloud provider
    London, UK
  • M
    Mixpanel · Data visualisation tool
    GCP eu-west netherlands
  • S
    Sentry · Cloud monitoring
    USA
  • C
    Customer.IO · CRM tool
    AWS EU
  • V
    Vanta · Security
    United Kingdom
  • S
    Sendbird · Customer messaging platform
    AWS Frankfurt, Germany
  • T
    Typeform · User Questionaires
    AWS EU
  • S
    Segment · Event tracking
    AWS S3 Dublin
  • S
    Semble · Clinical consultation and prescriptions
    GCP London, UK
  • H
    HubSpot · Marketing
    AWS US East
  • L
    Linear · Collaboration
    US

Compliance leadership

The person who leads Peppy Health's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Peppy Health's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Cyber Essentials PlusMay 2026

Peppy is please to annouce we have been renewed for our CyberEssentials Plus cerifitcation for 2026. Our latest certificate has been added to our Trust Centre

CyberEssentialsApr 2026

Peppy is please to annouce we have been renewed for our CyberEssentials cerifitcation for 2026. Our latest certificate has been added to our Trust Centre

CyberEssentials and CyberEssentials PlusMar 2026

Peppy is currently going through renewal audits for both of these frameworks and will update our Trust Center with the new certificates as soon as they are issued.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Peppy Health SOC 2 compliant?
Peppy Health is SOC 2 compliant. On SOC2C this listing is Listed.
Is Peppy Health ISO 27001 certified?
According to Peppy Health's public trust center, Peppy Health is ISO 27001 certified. On SOC2C this listing is Listed.
Is Peppy Health GDPR compliant?
According to Peppy Health's public trust center, Peppy Health is GDPR compliant. On SOC2C this listing is Listed.
Can I use Peppy Health's SOC 2 for a vendor risk assessment?
Yes. Peppy Health's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Peppy Health penetration tested?
Peppy Health hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Peppy Health

Reproduced from Peppy Health's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do you encrypt data at rest?
Yes, our data is stored within our Google Cloud instance and use AES-256 for our data encryption.
Do you support Single Sign-On (SSO)?
For our clinical product we don't support SSO. As the product is intended for personal use away from an employers system we have deliberately chosen the option for end users to select a personal email address and password for account creation.
Where are your servers located?
We use cloud servers through Google Cloud to store our data. That data is located in their London, UK cluster.
Which contract terms apply to my order?
Where your Order Form includes a link which brings you to Vanta, the Customer Subscription Terms, Data Protection Terms and the Information Security Terms apply regardless of the Peppy Service included in your Order Form. However, depending on the Peppy Services included in the Order Form, the following additional terms will also apply to your contract with us: - If your Order Form is for Peppy Clinical Services then you should also read the "Peppy Clinical Services - Service Specific Terms and Conditions" - If your Order Form is for Peppy Global Services then you should also read the "Peppy Global Services - Service Specific Terms and Conditions"
If I want to suggest changes to the Peppy terms, how can I do this?
We strongly encourage no/minimal mark up to our terms and conditions as we feel that they already provide a very balanced document which has been agreed with numerous customers. However, if you require any changes to our terms and conditions, we ask that you include these as "Special Conditions" in the Order Form.