SOC2C

Is this your company? Buyers are checking Ultralytics here. Claim ultralytics.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Ultralytics logo

Ultralytics

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Ultralytics is SOC 2 compliant. Ultralytics also holds ISO 27001.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

Ultralytics is a global leader in artificial intelligence, specializing in cutting-edge computer vision solutions. Driven by a mission to empower individuals and organizations with accessible, world-class AI, Ultralytics is the creator of [YOLO](https://www.github.com/ultralytics/ultralytics), the industry's most popular object detection and segmentation models. Through relentless innovation and a commitment to open-source excellence, we deliver state-of-the-art AI tools that enable users to solve real-world challenges across industries such as healthcare, autonomous systems, retail, and more.

Compliance & infrastructure

Hosting
GCP
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

1

Subprocessors

3
  • G
    Google · Cloud provider
    United States
  • M
    MongoDB Atlas · Data storage and processing
    United States
  • M
    Mailersend · Product and design
    United States

Compliance leadership

The person who leads Ultralytics's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Ultralytics's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Ultralytics Achieves ISO/IEC 27001:2022 CertificationJun 2026

We are pleased to announce that Ultralytics is now officially ISO/IEC 27001:2022 certified. Following the successful completion of our certification audit conducted by Insight Assurance LLC, Ultralytics has been awarded ISO/IEC 27001:2022 certification, validating that our Information Security Management System (ISMS) meets the internationally recognized standard for information security. The certification covers both the Ultralytics Platform (SaaS) and the Ultralytics YOLO model family, reflecting our ongoing commitment to protecting customer data, managing risk, and maintaining strong security practices across our organization. To support transparency and help customers understand the scope of our certification, the following documents are available in our Trust Center under NDA: - ISO/IEC 27001:2022 Certificate - Statement of Applicability (SoA) The SoA provides additional detail regarding the security controls included within the scope of our ISMS. This achievement represents the collaborative efforts of our Engineering, Information Security, Legal, Finance, and Operations teams in building, operating, and continuously improving our security program. We remain committed to maintaining the highest standards of security and compliance and will continue to keep our Trust Center updated as our program evolves.

ISO 27001:2022 Certification RecommendedMay 2026

We are pleased to share that Ultralytics has been officially recommended for ISO 27001:2022 certification by our auditor, Insight Assurance LLC. Following the successful completion of our initial certification audit, Insight Assurance has confirmed that Ultralytics met all requirements of the ISO/IEC 27001:2022 standard with no outstanding nonconformities. The formal certificate is currently being issued and will be made available in our Trust Center upon receipt. This milestone reflects the hard work invested across our Engineering, Information Security, Legal, Finance, and Operations teams in building and validating a robust information security management system - covering both the Ultralytics Platform (SaaS) and our Ultralytics YOLO model family. We remain committed to transparency and will continue to keep this Trust Center updated as our compliance program progresses.

Advancing Our Security and Compliance ProgramApr 2026

At Ultralytics, we remain deeply committed to safeguarding our customers’ data and maintaining a strong security and compliance posture. Over the past year, we have made significant progress in strengthening our program. We have successfully completed both Stage 1 and Stage 2 audits for ISO 27001:2022, marking an important milestone in formalizing and validating our information security management system. Upon certification, the official ISO 27001 certificate will be made available in our Trust Center. In parallel, we are currently undergoing our SOC 2 Type I audit, with completion expected by the end of May 2026. Once finalized, the SOC 2 attestation report will also be published in our Trust Center. To complement these initiatives, we have conducted an independent third-party penetration test of the Ultralytics Platform. This assessment helps us proactively identify and remediate potential vulnerabilities, strengthening the overall security of our services. The attestation report is available through our Trust Center upon request, subject to NDA. We will continue to build on this momentum by investing in security best practices, enhancing our controls, and maintaining transparency with our customers. Thank you for trusting Ultralytics with your data.

Commitment to Enhanced Security and ComplianceJan 2025

At Ultralytics, we prioritize the privacy and security of our clients’ data. As part of our ongoing commitment to excellence, we are actively working towards achieving SOC 2, ISO 27001, and GDPR compliance. Achieving these standards will further solidify our dedication to maintaining the highest standards of data protection and trust. We’ll continue to implement best practices throughout this journey and will provide regular updates as we progress. Thank you for trusting Ultralytics with your data.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Ultralytics SOC 2 compliant?
Ultralytics is SOC 2 compliant. On SOC2C this listing is Listed.
Is Ultralytics ISO 27001 certified?
According to Ultralytics's public trust center, Ultralytics is ISO 27001 certified. On SOC2C this listing is Listed.
Can I use Ultralytics's SOC 2 for a vendor risk assessment?
Yes. Ultralytics's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Ultralytics penetration tested?
Ultralytics hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Ultralytics secure?
Security isn't a single yes/no, but Ultralytics is SOC 2 compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.

Answers published by Ultralytics

Reproduced from Ultralytics's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What measures does Ultralytics take to ensure compliance with evolving regulations?
Ultralytics actively monitors changes in global data protection and AI regulations, updating our policies and practices to ensure compliance. We work closely with legal and technical experts to maintain adherence to standards such as GDPR, CCPA, EU AI Act or other applicable AI-specific guidelines.
Is Ultralytics HIPAA compliant?
Ultralytics does not currently provide compliance certifications or documentation specific to the medical or healthcare sector (e.g., HIPAA). For the Ultralytics Platform (SaaS), we implement robust security and data protection practices aligned with industry standards, including strong access controls, encryption, and monitoring. While these controls support secure handling of data, customers are responsible for ensuring that their specific use of the platform meets applicable regulatory requirements, such as HIPAA. For Ultralytics YOLO models (open source), Ultralytics operates as a model provider rather than a hosted clinical system. These models are deployed and run entirely within customer-controlled environments, meaning customers retain full responsibility for how data is processed, secured, and governed. This is typically where sector-specific compliance (e.g., HIPAA or medical device regulations) is implemented. Across both offerings, Ultralytics focuses on ensuring the security, integrity, and reliability of its technology, enabling customers to build compliant solutions within their own environments where required.
What security and compliance standards do you follow?
Ultralytics aligns its security program with industry-recognized frameworks, including SOC 2 and ISO 27001. Our security program includes: - Formal security policies and procedures - Role-based access controls and least-privilege access - Encryption of data in transit and at rest - Continuous monitoring, logging, and vulnerability management - Incident response and business continuity processes In addition, we conduct independent third-party security testing, including penetration tests, to continuously assess and improve the security of the Ultralytics Platform.
What support does Ultralytics offer for enterprise customers?
Ultralytics provides enterprise customers with dedicated support, including priority issue resolution, custom integrations, and tailored training programs to maximize the value of our AI solutions in their specific use cases.
How does Ultralytics ensure AI model fairness and mitigate bias?
Ultralytics approaches fairness and bias mitigation as part of both model development and responsible deployment. During development, we evaluate model performance across different scenarios to identify limitations and potential sources of bias. This includes testing model outputs, monitoring performance, and iterating on model design to improve robustness and reliability. Because Ultralytics YOLO models are open-source and highly customizable, model behavior ultimately depends on how they are trained, fine-tuned, and deployed. As such, customers are responsible for validating model performance within their specific datasets and use cases, and for conducting any required risk assessments, particularly in regulated or high-risk environments. Ultralytics focuses on providing transparent, well-documented, and flexible models, enabling users to understand model behavior and apply appropriate safeguards in their own applications.