# Quake AI: Compliance & Certifications

Source: https://docs.quake.ai/docs/security/compliance-and-certifications
Markdown: https://docs.quake.ai/docs/security/compliance-and-certifications.md

---

# Quake AI: compliance & certifications

This page lists the compliance attestations Quake AI currently holds, and the regulatory frameworks it does not currently hold.

---

## Sarbanes-Oxley (SOX)

The Sarbanes-Oxley Act (SOX) is a U.S. law that applies to publicly traded companies and their financial reporting. It is not a certification that a cloud provider obtains: there is no SOX certification or validation for cloud service providers. If your organization is subject to SOX, you can use Quake AI's SOC 2 report to demonstrate controls over the infrastructure layer as part of your own SOX program. Request the report as described in the SOC 2 section below.

---

{/*  vale Quake.HeadingH2Plus = NO  */}
## SOC 2 (type I & type II)
{/*  vale Quake.HeadingH2Plus = YES  */}

Quake AI holds both **SOC 2 Type I** and **SOC 2 Type II** attestations:

- **SOC 2 Type I**: Covers whether the control environment is suitably designed at a specific moment.
- **SOC 2 Type II**: Covers whether those controls operate over an audit period.

These reports cover controls for security, confidentiality, availability, processing integrity, and privacy.

The report names the auditing firm and states the audit period. To request a copy under NDA, contact support.cloud@rumble.com and ask for the "Quake AI SOC 2 report".

---

## SOC 3 report

A **SOC 3 report** summarizes the SOC 2 controls for general distribution without revealing sensitive internal control details. To request a copy, contact support.cloud@rumble.com and ask for the "Quake AI SOC 3 Public Report".

---

## Summary table

| **Attestation**  | **Description** |
|--------------------|------------------|
| **SOC 2 Type I**       | Assesses control design effectiveness at a specific moment |
| **SOC 2 Type II**      | Reports operational effectiveness of controls over an audit period |
| **SOC 3 Report**       | Shareable summary of the SOC 2 controls |

---

## Not currently certified

Quake AI does not currently hold the following certifications or attestations. If your workload requires any of them, account for the gap in your compliance planning. For questions about compliance scope, contact us at support.cloud@rumble.com.

- HIPAA
- PCI DSS
- FedRAMP
- GDPR readiness
- ISO 27001

---

## What these attestations cover

- **Third-party assurance**: The SOC 2 attestation gives customers and partners independent verification of Quake AI's control environment.
- **Shareable summary**: The SOC 3 report provides a summary of the SOC 2 controls without exposing sensitive internal detail.

---

## Contact us

To ask about certifications or request copies of audit reports, contact us at support.cloud@rumble.com
