> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Trust center and compliance

> Orq.ai Trust Center: request the SOC 2 Type II report, ISO 27001 status, penetration test reports, HIPAA BAA, DPA, and sub-processor list.

The **Orq.ai** Trust Center at [trust.orq.ai](https://trust.orq.ai) is the source for security certifications and audit evidence. The artifacts sit behind an access request.

<Card title="Open the Orq.ai Trust Center" icon="shield-check" href="https://trust.orq.ai">
  Request access to reports, certifications, and compliance documentation.
</Card>

## What the Trust Center holds

| Artifact                 | Covers                                                                   |
| ------------------------ | ------------------------------------------------------------------------ |
| SOC 2 Type II report     | Independent audit of security controls                                   |
| ISO 27001 status         | Certification status and current reports                                 |
| Penetration test reports | Independent testing of the platform                                      |
| HIPAA BAA                | Business Associate Agreement for processing protected health information |
| DPA                      | Data Processing Agreement under Article 28 GDPR                          |
| Sub-processor list       | Third parties that process customer data                                 |
| Control list             | Security controls in place across the platform                           |

Access is requested from the Trust Center itself. For anything not listed there, contact [support@orq.ai](mailto:support@orq.ai).

See [Data Compliance](/ai-studio/organization/data-compliance) for data handling, masking, and retention.
