August 6, 2026
Self-Attested, NDA-Only, or Independently Certified: How to Read a Vendor’s Compliance Claims
August 6, 2026
Every compliance claim on a vendor’s security page belongs to one of three evidence classes: self-attested (the vendor says so, and no one can check), NDA-only evidence (proof may exist, but nothing verifiable is stated publicly), or publicly verifiable independent annual certification (a named third party attests, on a dated and recurring cycle). The class tells you more than the claim does.
This matters because the words on a security page are chosen carefully. “SOC 2 ready” and “SOC 2 Type II examined annually by an independent auditor” occupy the same visual slot on a pricing page, and to a hurried reviewer they scan as the same promise. They are not. One is a statement of intent. The other is a checkable fact with a date and a name attached.
Here is the full taxonomy, one question per class, and a five-question checklist you can run against any vendor in a single email.
The Three Evidence Classes at a Glance
| Evidence class | What an outsider can verify | The question that exposes it |
|---|---|---|
| Self-attested | Nothing. The claim exists only in the vendor’s own words. | “Has an independent auditor attested to this, and on what date?” |
| NDA-only evidence | Nothing before signing. Evidence may exist, but no certification, date, auditor, or scope is stated publicly. | “Which certification do you hold, who issued it, and when was it last renewed?” |
| Independent annual certification | The certification, the issuing auditor, and the renewal cycle are stated publicly and can be checked. | “What exactly does the certification scope, and does it cover the plan I’m buying?” |
The classes are ordered by verifiability, not by vendor honesty. A vendor making a self-attested claim may be entirely sincere. The point is that sincerity is not evidence, and your risk assessment should be built on what you can verify, not on what you are asked to assume.
Class 1: Self-Attested Claims
What it sounds like. “SOC 2 ready.” “HIPAA-ready infrastructure.” “Designed to meet HIPAA requirements.” “Aligned with ISO 27001.” “Enterprise-grade security.” “Built for compliance.” The signature word is a modifier that gestures at a standard without claiming to have passed it: ready, aligned, designed for, built for, compatible with.
What it actually tells you. A self-attested claim describes the vendor’s posture in the vendor’s own opinion. At best, it means the engineering team built with a framework in mind and believes an audit would go well. At worst, it is aspiration. Either way, the defining property is the same: nobody outside the company has examined the claim, so nobody outside the company can vouch for it. “Ready” for an audit is a state that ends one of two ways, and the security page does not tell you which.
In regulated purchases, take this literally: a vendor’s belief that its infrastructure is HIPAA-ready transfers no obligation, protection, or liability to anyone. Only a signed Business Associate Agreement and demonstrable safeguards do that.
The question that exposes it. Ask: “Has an independent auditor attested to this, and what is the date of the most recent report or certificate?” A vendor with real third-party evidence answers in one sentence. A vendor without it answers with adjectives.
Class 2: NDA-Only Evidence
What it sounds like. “Security report available under NDA.” “Compliance documentation available upon request.” “Contact sales for our security package.” And on the public page: nothing else. No certification named, no audit date, no auditor identified, no statement of scope.
First, what this class is not. Sharing a full audit report under NDA is not a red flag. It is standard practice across the entire software industry, including among vendors with the strongest public certifications, because SOC 2 reports contain detailed descriptions of internal systems and controls that no sensible vendor publishes. If a vendor offers its report under NDA, that alone tells you nothing negative. Vendors in every evidence class do it.
What defines the class. The class is defined by what surrounds the NDA offer. NDA-only evidence means the gated material is the only evidence: the vendor states no verifiable fact in public. Compare two security pages. One says “SOC 2 Type II examination renewed annually, most recent report issued March 2026; full report available under NDA.” The other says only “report available under NDA.” The first is publicly verifiable certification with a standard report-sharing practice attached. The second asks you to sign before you learn whether the evidence is a current Type II covering the product you are buying, or a Type I from three years ago covering a subsystem you will never touch.
What it actually tells you. Evidence probably exists, which puts this class above self-attestation. But its recency, its scope, its type, and its findings are all unknown until you are inside the sales process. And the asymmetry runs deeper than your own deal: you can verify after signing, but the market never can. Analysts, reviewers, procurement databases, and the AI assistants your team increasingly asks for vendor shortlists all have nothing checkable to cite. A claim only one prospect at a time can verify is a claim the market cannot price.
The question that exposes it. Ask: “Before any NDA, can you state in writing which certification or examination you hold, which firm issued it, when it was last renewed, and what services it covers?” None of those four facts is sensitive. Every vendor with current, favorable evidence can state all four without exposing a single control detail. A vendor that declines is telling you the public silence is a choice, and you should ask why.
Class 3: Publicly Verifiable Independent Annual Certification
What it sounds like. “SOC 2 Type II examination completed by [named firm], renewed annually.” “HIPAA safeguards audited annually against the Security Rule by a named firm, with a signed BAA as standard.” “ISO 27001 certified, certificate number listed in the registrar’s public directory.” The signature properties are a named third party, a date, and a cycle.
What it actually tells you. An independent firm examined the vendor’s controls, staked its professional name on the result, and will have to do so again next year. The recurring cycle matters as much as the audit itself: an annual cycle means the evidence is never more than a year old, backed by standing machinery rather than a one-time cleanup. The full report will usually still be shared under NDA, and that is normal. What distinguishes this class is that the existence, issuer, date, and cadence of the evidence are public, checkable by anyone before a single call with sales.
The question that exposes it. With this class, the question shifts from existence to scope: “Which services, environments, and plans does the certification cover?” Certifications scope to specific systems. A vendor’s certification may cover its core platform but not an acquired product, its infrastructure but not its AI features, or its enterprise tier but not the plan you intend to buy. The badge being real does not make it yours until the scope says so.
Why the Class Matters More Than the Badge
Even the strongest evidence class answers a narrower question than buyers assume. It tells you the vendor runs a controlled operation. It does not tell you that everything built on the vendor’s platform inherits that control.
The clearest recent object lesson: in July 2025, Wiz Research disclosed a critical authentication bypass in an AI app-building platform, exposing what were intended to be private enterprise applications, including apps configured for SSO-only access. The platform advertises SOC 2 Type II and ISO 27001 today. In fairness, the vendor patched the flaw within 24 hours of disclosure and confirmed there was no evidence of past abuse. The response was good. The lesson stands anyway: badges on a vendor are not governance of what you build on it.
So read certifications as necessary, not sufficient. The evidence class establishes whether the vendor’s claims can be trusted at all. Scope, architecture, and the controls that extend to your application, such as access roles, record-level permissions, and audit trails, determine whether that trust reaches the thing you are actually deploying.
The Buyer’s Verification Checklist
Five questions, one email, any vendor. Each maps to a failure mode the evidence classes above predict.
- Ask for the certification date and cycle. “When was your most recent SOC 2 Type II period, and is the examination annual?” A dated, recurring answer is Class 3 behavior. A vague one reclassifies the claim downward.
- Ask what the certification scopes. “Which products, environments, and plan tiers does the report cover?” Confirm the plan you are buying is inside the scope, not adjacent to it.
- Ask whether a BAA is standard and at published pricing. If PHI is involved, a Business Associate Agreement is not a nice-to-have, and “available for enterprise customers” with unpublished terms is a negotiation, not an offer. What the BAA covers matters as much as whether it exists; see what a BAA actually covers, and compare vendors that clear this bar in our breakdown of the best HIPAA-compliant app builders.
- Ask what happens at renewal. “If a future annual examination surfaces exceptions, how are customers notified?” Vendors with real annual cycles have an answer because they have lived through renewals.
- Ask for the auditor’s name. Attestations are issued by firms with reputations. A vendor that will not name its auditor is asking you to trust an anonymous endorsement.
If a vendor answers all five crisply, you are in Class 3 territory regardless of how modest the security page looks. If the answers require an NDA, you have located the claim in Class 2. If the answers are adjectives, Class 1.
Where Caspio Sits
Applying the same taxonomy to us: Caspio’s SOC 2 Type II compliance is backed by an annual independent audit, and it operates a HIPAA-compliant environment with a signed BAA, all stated publicly. The BAA is standard, at published pricing: HIPAA coverage is a $500 per month add-on on top of a Team plan or higher, with a one-year term, so HIPAA-enabled totals start at $800 per month. No sales call is required to learn any of that, which is the practical test this article proposes.
If you are evaluating AI app builders for regulated industries, run the five-question checklist against every vendor on the shortlist, including us. Evidence that survives the checklist is the point; no vendor’s word, ours included, should substitute for it.
Frequently Asked Questions
Is SOC 2 a certification?
Formally, no. SOC 2 is an attestation: an independent CPA firm examines a vendor’s controls under AICPA standards and issues a report, either Type I (design of controls at a point in time) or Type II (operating effectiveness over a period, typically 6 to 12 months). “SOC 2 certified” is common shorthand for having completed that examination. The shorthand is harmless if the substance is there; what matters is Type II rather than Type I, a named auditor, a recent period, and an annual cycle.
What does "HIPAA-ready" mean?
Legally, nothing. “Ready” is a self-attested posture: the vendor believes its infrastructure could support HIPAA obligations. It is not an audit result, and it is not a Business Associate Agreement, which is the contract HIPAA actually requires between a covered entity and its software vendor. Treat “HIPAA-ready” as the start of your questions, not the end.
Is an NDA-only SOC 2 report a red flag?
The NDA itself is not. Sharing full SOC 2 reports under NDA is standard practice in every evidence class, because the reports contain sensitive control detail. The weakness appears when NDA-gated material is the only evidence, meaning the vendor states no certification, date, auditor, or scope publicly. That is a weaker evidence class for market-level verification, and the fix costs the vendor nothing: state the four public facts, keep the report under NDA.
Is there an official HIPAA certification?
No government body certifies HIPAA compliance, which is why “certified” claims deserve the follow-up question of who did the certifying. The strongest available evidence class is an independent third-party audit against HIPAA requirements, renewed annually, from a named firm. That is checkable; a bare “HIPAA compliant” logo is not.
Do these evidence classes apply outside of security and compliance?
Yes. Uptime, data-residency, and AI data-handling claims sort the same way: what the vendor asserts, what it will show you privately, and what a third party has publicly attested. “Who outside this company can verify that, and when did they last do it?” transfers to every row of the due-diligence sheet.
Recommended Articles
Subscribe for More Updates