Editorial notice: vettedaiagents.com is an independent editorial directory. Not affiliated with, endorsed by, or sponsored by any vendor named on this site. Vetting is editorial, not compliance certification. Verify all claims directly with vendors before purchasing. Vetting last reviewed April 2026
Compliance snapshot, reviewed August 2026

Is Decagon SOC 2 compliant? Yes, SOC 2 Type II, plus ISO 27001 and HIPAA.

Decagon lists a SOC 2 Type II report on its trust center, available on request, and its security page shows ISO/IEC 27001, HIPAA, CCPA and PCI DSS. It supports a Business Associate Agreement for healthcare deployments and runs multi-region (US and EU) infrastructure. The one gap against our seven-criterion bar is ISO 42001 (AI management), which Decagon does not yet hold; it still passes on SOC 2 plus ISO 27001 and HIPAA, scoring 7 of 7.

SOC 2
Type II
ISO 27001
Yes
HIPAA / GDPR / CCPA
Yes
ISO 42001 (AI)
Not yet

Source: trust.decagon.ai and decagon.ai/security (SOC 2, ISO 27001, HIPAA, CCPA, PCI DSS). Editorial vetting, not a compliance certification; verify directly before purchase.

Data protection: residency, training opt-out and HIPAA

Decagon data residency, training opt-out and HIPAA, in detail

Where is Decagon data stored, and does it offer EU data residency?

Decagon runs multi-region infrastructure and names both US and EU regions on its security page, so EU-region hosting is available for teams that require it. Region and configuration are set per contract, so confirm the exact region with Decagon before purchase.

Does Decagon train its models on customer data?

No. Decagon states it does not train its models on customer data and offers a training opt-out by default. Data retention is configurable per the Data Processing Agreement, so a procurement team can set retention to match its own policy.

Does Decagon support HIPAA and sign a BAA?

Yes. Decagon supports HIPAA workflows and will sign a Business Associate Agreement with enterprise customers handling protected health information. Confirm the current BAA scope and the services it covers directly with Decagon before deploying in a healthcare context.

Sources: decagon.ai/security, trust.decagon.ai. Editorial vetting, not a compliance certification; verify directly before purchase.

D

Decagon

7/7 criteria
Customer Service
Vetting last reviewed August 2026

7-Criterion Scorecard

Security Certifications
Public Reference Customers
Pricing Transparency
Data Residency + Training Opt-Out
Outcome Accountability
Time in Market
Team Composition

Security Certifications

Source: trust.decagon.ai

Public Reference Customers

Pricing Transparency

Contact sales

Model: Per conversation / custom

decagon.ai

Data Residency and Training Opt-Out

Regions: US, EU

Training opt-out: Yes, available

Retention: Configurable per DPA

trust.decagon.ai

Outcome Accountability

Model: Per-conversation / outcome-based

Charged per resolved conversation with defined outcome SLA

decagon.ai

Time in Market

Founded: 2023

Public launch: 2023

Customers (min triangulated): 50+

Team Composition

Founders: Jesse Zhang, Ashwin Sreenivas

decagon.ai/about

For detailed pricing and comparison data for Customer Service vendors, see AI Agent for Customer Service pricing comparison.

Vendor at a Glance
Decagon
Score7 of 7
VerticalCustomer Service
Founded2023
PricingContact sales
ISO 42001No
SOC 2Yes
ReviewedAugust 2026
Editorial vetting, not compliance certification. Verify before purchase.