News icon

Kimi K3 is now available on Runpod

Runpod is ISO 27001 certified

The certification audit closed with zero findings, giving international customers a standing answer instead of a bespoke security questionnaire.

Runpod is ISO 27001 certified

We're excited to announce that Runpod has achieved certification to ISO/IEC 27001, the international standard for information security management. The certification audit closed with zero findings and zero remediations.

🔔 The certificate and supporting documentation can be retrieved now from our Trust Portal through the same access process customers already use for our SOC 2 report.

The practical effect for most evaluations is that an ISO 27001 requirement can be satisfied with standing documentation rather than a bespoke response from us, including in jurisdictions where SOC 2 carries no weight.

What ISO 27001 certifies

ISO 27001 certifies an information security management system, not a product or an individual service. The term "ISO certified" is used loosely in this market, so it is worth being precise about what was assessed.

The audit evaluated whether we maintain a documented set of security controls, whether we operate in accordance with them, and whether we can produce supporting evidence on demand. The control areas assessed include:

  • Access control, including approval and review trails for production systems
  • Cryptography and the protection of data in transit and at rest
  • Incident response and business continuity management
  • Privacy risk assessment conducted prior to deployment
  • Supplier and third-party risk management
  • Asset management, change control, and secure development practices

Certification is not a one-time event. The ISMS is subject to annual surveillance audits and full recertification on a three-year cycle, which is a more meaningful signal of operating discipline than the certificate itself.

Scope and limitations

The scope statement on our certificate reads:

"The scope of the ISO/IEC 27001:2022 certification is limited to the Information Security Management System (ISMS) of Runpod directly supporting Runpod's services and platform solutions including the infrastructure, people, and technologies, in accordance with the Statement of Applicability (SoA)."

We operate across 31 global regions, and the data centers underlying those regions are third-party providers holding their own certifications. Our ISO 27001 certificate covers Runpod's information security management system, including the controls by which we assess, onboard, and monitor those providers. It does not certify each individual facility. Customers with requirements tied to a specific region or facility should contact us, and we will confirm the certifications held by that site.

What this changes for your evaluation

International procurement. SOC 2 is a US framework and is not recognized by many procurement organizations in Europe, APAC and the Middle East, where ISO 27001 is the expected standard. Prior to certification, we were unable to satisfy that requirement, and evaluations were closed on that basis before reaching technical assessment. That requirement is now met.

Security review cycle time. We hold SOC 2 Type II, SOC 3, HIPAA and GDPR documentation, and ISO 27001 is built on the same underlying control set. Questionnaire items covering access control, encryption, incident response, business continuity and vendor risk can now be satisfied with standing documentation rather than a bespoke response. All documentation sits in the trust portal, which also now supports self-service execution of a Data Processing Agreement.

Your own audit obligations. Assessors conducting your SOC 2 or ISO audit will request information on vendors in your critical path. A certified vendor is a documented line item rather than an open question your compliance function must resolve.c

Our broader compliance program

Our certifications were obtained in sequence, with each providing the control foundation for the next: SOC 2 Type I, followed by SOC 2 Type II, followed by HIPAA and GDPR attestations, and now ISO/IEC 27001.

We currently maintain:

  • ISO/IEC 27001 certification
  • SOC 2 Type II
  • SOC 3
  • HIPAA compliance, with BAAs available
  • GDPR compliance, with DPAs available

Retrieving documentation

All of the following can be retrieved by customers directly from our Trust Portal using the same access process as our SOC 2 report:

  • ISO/IEC 27001 certificate
  • SOC 2 Type II report and current bridge letter
  • SOC 3 report
  • HIPAA documentation
  • GDPR documentation and Data Processing Agreement

Build what’s next.

Build, train, and scale AI workloads on Runpod with cloud GPUs, Serverless, and Clusters.

Star field background