Skip to main content
Cybersecurity Awareness Month: New videos, games, and ready-to-use resources

Trust & Compliance

Compliance & certifications.

Explore the security, privacy, and compliance practices behind a platform you can trust.

Adaptive Security maps product capabilities to key security frameworks and offers training across a broad range of requirements and languages. Assign learning, track completions, and keep evidence organized in one place.

Frameworks mapped
8
Training frameworks
20+
Languages
39+

01 / Our security posture

Trust starts with transparency.

Explore Adaptive Security’s security practices, privacy commitments, and supporting documentation.

Public Trust Center listings checked .

Independent attestation

SOC 2 Type II

Adaptive Security makes its SOC 2 Type II report available through the Trust Center. Request access to review the auditor’s opinion, assessment period, and systems in scope.

Request the SOC 2 report

Compliance program

HIPAA

Review Adaptive’s HIPAA Compliance Policy and discuss your use case, protected health information, and any business associate agreement requirements with our security team.

Request the HIPAA policy

Data protection

GDPR

Review our GDPR Compliance Policy, Data Processing Addendum, and subprocessor disclosures to evaluate personal-data processing and your organization’s obligations.

Request the GDPR policy

Regulatory alignment

EU AI Act

The Trust Center lists the EU AI Act in Adaptive’s compliance program. Ask our security team about applicability and scope. This is not an independent certification.

Review in the Trust Center

An independent attestation, a compliance program, and regulatory alignment are different. The badges above are not four interchangeable certifications. The SOC 2 report defines its own scope; HIPAA, GDPR, and EU AI Act applicability depends on the service, data, and use case.

02 / Security & data handling

See how we protect your data.

Hosting & architecture

Our Trust Center identifies Amazon Web Services (AWS) hosting in the United States. Request architecture and data-flow details for your selected products.

Review hosting details

Security controls

Published controls cover encryption, restricted access to encryption keys, authentication, and penetration testing. Request policies for technical implementation details.

Explore security controls

Privacy & subprocessors

See which providers support our services, what they do, and where they operate. Our Data Processing Addendum explains the contractual data-protection terms.

View subprocessors

03 / Framework mapping

From requirement to evidence.

Explore key framework requirements, see how Adaptive supports them, and identify the evidence your team can prepare.

These mappings describe support, not certification or a guarantee of compliance. Your organization and assessor determine the controls and evidence required.

SOC 2

CC1.4 · CC2.2

What it requires

Develop personnel competence and communicate internal-control responsibilities. Security awareness training helps employees understand and carry out those responsibilities.

How Adaptive helps

Assign role-based awareness training and keep per-user completion records. Use reporting to document participation and follow up on incomplete assignments.

Evidence to prepare: Training assignments, completion records, and policy-specific learning content.

AICPA Trust Services Criteria

ISO/IEC 27001:2022

Annex A · 6.3

What it requires

Provide appropriate information security awareness, education, and training, with regular updates relevant to each person’s role and the organization’s policies.

How Adaptive helps

Deliver recurring, role-based training and tailor content to internal policies. Track completion to support the awareness control in your information security management system.

Evidence to prepare: Role-based learning plans, completion records, and policy training history.

ISO/IEC 27001:2022 (licensed standard)

HIPAA Security Rule

45 CFR §164.308(a)(5)

What it requires

Implement a security awareness and training program for all workforce members, including management. Address security reminders, malicious software, log-in monitoring, and password management as applicable.

How Adaptive helps

Assign HIPAA-focused workforce training, reinforce phishing awareness with simulations, and retain individual completion records for your security program.

Evidence to prepare: Workforce training records, assigned HIPAA content, and simulation results.

Electronic Code of Federal Regulations

PCI DSS v4.0.1

12.6 · Security awareness

What it requires

Maintain a formal security awareness program. Requirement 12.6.3 calls for training at hire and at least annually; 12.6.3.1 includes phishing and related social-engineering attacks.

How Adaptive helps

Automate onboarding and recurring training, run phishing simulations, and export completion evidence. Simulations reinforce the program; they do not replace the full set of PCI DSS requirements.

Evidence to prepare: Onboarding and annual completion records, training content, and simulation reports.

PCI SSC · PCI DSS v4.0.1

GDPR

Articles 32 · 39(1)(b)

What it requires

Article 32 requires security measures appropriate to risk. Article 39 includes staff awareness and training within the data protection officer’s compliance-monitoring responsibilities.

How Adaptive helps

Deliver data-protection training to staff who process personal data. Tailor assignments by role and use completion reporting to support your broader privacy program.

Evidence to prepare: Privacy training content, role-based assignments, and completion reports.

EUR-Lex · Regulation (EU) 2016/679

NIST CSF 2.0

PR.AT-01 · PR.AT-02

What it requires

Provide personnel with awareness and training for general tasks, and give people in specialized roles the knowledge and skills to perform those tasks with cybersecurity risks in mind.

How Adaptive helps

Combine general awareness training, role-specific learning, and realistic simulations. Use human-risk reporting to identify gaps and focus follow-up training.

Evidence to prepare: Learning progress, simulation outcomes, and human-risk reporting.

NIST · The Cybersecurity Framework 2.0

CMMC 2.0 · Level 2

AT.L2-3.2.1 · AT.L2-3.2.2

What it requires

Make managers, administrators, and users aware of security risks and applicable policies. Train personnel to carry out assigned information-security duties and responsibilities.

How Adaptive helps

Assign awareness and role-based training, customize content for organizational policies, and retain training records for assessors. Training support does not mean Adaptive is CMMC certified or authorized to handle CUI.

Evidence to prepare: Role-based curricula, assigned policies, and personnel training records.

DoD · CMMC Level 2 Assessment Guide

NIS2

Article 21(2)(g) · Article 20(2)

What it requires

Article 21 includes basic cyber hygiene and cybersecurity training. Article 20 addresses training for management bodies. Applicability depends on national implementing law and the entity’s scope.

How Adaptive helps

Deliver awareness training across the workforce and tailored learning for leadership. Use simulations and completion reports to document the training component of your risk-management program.

Evidence to prepare: Management and workforce learning records, cyber-hygiene content, and simulation results.

EUR-Lex · Directive (EU) 2022/2555

04 / Compliance by product

The right support for every team.

See how Adaptive Security products support your compliance program, from employee training and phishing simulations to email security and AI governance.

Adaptive products, relevant frameworks, and compliance activities supported
Security Awareness TrainingSOC 2 · ISO 27001 A.6.3 · HIPAA · PCI DSS 12.6Role-based learning and individual completion records for your awareness program.
Phishing SimulationsPCI DSS 12.6 · NIST CSF PR.AT · NIS2Realistic practice and measurable results to reinforce phishing and social-engineering awareness.
Agentic Email SecurityNIST CSF DE.CMEmail threat detection and remediation to support continuous monitoring.
AI GovernanceAI-use policies · Responsible AI governanceVisibility, policy enforcement, and employee coaching for safer AI use. Confirm regulatory scope for your use case.
Phish TriageNIST CSF RS.ANAnalysis of employee-reported messages to support incident investigation.
Compliance TrainingHIPAA · GDPR · PCI DSS · CCPA and morePre-built and customizable learning tracks, localized assignments, and completion tracking.
Human Risk ManagementNIST CSF ID.RA · PR.ATHuman-risk insights to prioritize awareness training and follow-up.
ReportingEvidence for your selected frameworksTraining completion and simulation results for security reviews, leadership, and audit preparation.
IntegrationsIdentity and workforce administrationConnect identity and HR systems to keep employee access and training assignments current.

05 / Compliance by industry

Built for your industry’s security demands.

Finance

SOX · GLBA · PCI DSS

Train teams on sensitive financial data, phishing, and internal policies. Track participation for your compliance program.

Healthcare

HIPAA · HITECH

Deliver HIPAA-focused workforce education and phishing practice. Review PHI handling and contractual requirements separately.

Technology

SOC 2 · ISO 27001 · GDPR

Document employee awareness, privacy training, and completion evidence for customer reviews and audit preparation.

Government

CMMC · NIST SP 800-171

Support role-based awareness and training records. Training coverage is not FedRAMP authorization or permission to process CUI.

Hospitality

PCI DSS 12.6

Schedule training at onboarding and recurring intervals, with phishing education and documented completion.

Education

FERPA · Data privacy

Help faculty and staff recognize social engineering and understand institutional privacy policies.

Compliance training

Make required training easier to deliver.

Assign training for HIPAA, GDPR, PCI DSS, CCPA, and more, tailor it to your policies, and track completions in one place.

Frequently Asked Questions.

Adaptive Security’s Trust Center lists a SOC 2 Type II report available by access request. Review the report for the auditor’s opinion, assessment period, and systems covered. A report request link is not a substitute for reviewing the report’s scope.

Adaptive supports the awareness, training, and evidence-collection portions of SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIST CSF, CMMC, and NIS2. This page maps those capabilities to specific controls. Meeting a complete framework also requires organizational policies, technical controls, and appropriate assessment.

Adaptive supports onboarding and recurring awareness training, phishing simulations, and completion reporting. PCI DSS v4.0.1 Requirement 12.6.3 calls for training at hire and at least annually, while 12.6.3.1 includes phishing and related social engineering. Your organization remains responsible for the full requirement, including program review and policy acknowledgment.

An attestation covers the systems and services named in its report, not automatically every product. Use the product index on this page to understand supported compliance activities, then request the SOC 2 report and confirm the scope for the products you plan to use.

Yes. Adaptive’s Trust Center offers HIPAA and GDPR compliance policies by access request. The Data Processing Addendum and subprocessor list provide additional context. Confirm processing purposes, data types, transfer arrangements, and any required business associate agreement with the security team before deployment.

Visit security.adaptivesecurity.com to request security reports and policies, review published controls, and see the current subprocessor list. The Trust Center FAQ identifies AWS hosting in the United States, in us-east-2. Contact security@adaptivesecurity.com for architecture and product-specific scope questions.

Human and agent security for the AI era.