Compliance

Enterprise-grade standards and safeguards.

When you hand us your customers and your data, you're trusting us to protect them. We're built for that — certified, audited and compliant to the standards enterprise buyers require.

PCI DSS compliantISO 27001 certifiedSOC 2 Type IIHIPAA compliantGDPR compliant
What each means for you

Standards, in plain terms.

PCI DSS compliant

Cardholder and payment data is handled to the payment-card industry's security standard.

Attestation of Compliance on request.
ISO 27001 certified

Our information-security management system is independently certified to the global standard.

Certificate on request.
SOC 2 Type II

An independent auditor has verified our security controls operate effectively over time — not just at a point in time.

Report available under NDA.
HIPAA compliant

Protected health information is handled to US healthcare privacy and security requirements.

Key for CareHub and healthcare clients.
GDPR compliant

Personal data is processed to EU privacy standards, with data-processing agreements available.

Key for EU/UK data.
How we protect your data

Security, built into how we operate.

Beyond the certifications, security is built into how we operate: encryption in transit and at rest, role-based access controls, secure and monitored infrastructure, full audit trails, agent-level security policies, and business-continuity through multi-site redundancy. Human-in-the-loop controls and audit logging apply to our AI agents too.

Evidence, on request

Proof for your security team.

We hold the documentation behind every standard above — certificates, our PCI Attestation of Compliance, and our SOC 2 Type II report — and provide them to your security and vendor-risk team under NDA during evaluation. We're glad to complete security questionnaires and join a review call.

Compliance by industry

The standards that matter for you.

Healthcare

HIPAA + SOC 2 Type II (CareHub).

Payments / finance

PCI DSS + SOC 2 Type II.

EU / UK data

GDPR + ISO 27001.

FAQ

Compliance, answered.

Is Tribe Consulting PCI compliant?
Yes — Tribe is PCI DSS compliant and can provide its Attestation of Compliance on request.
Does Tribe have SOC 2?
Yes — Tribe holds a SOC 2 Type II report, available to clients under NDA.
Is Tribe ISO 27001 certified?
Yes — Tribe's information-security management is ISO 27001 certified.
Is Tribe HIPAA compliant?
Yes — Tribe handles protected health information to HIPAA requirements, which is core to its healthcare company, CareHub.
Is Tribe GDPR compliant?
Yes — Tribe processes personal data to GDPR standards and can provide a data-processing agreement.
How can I verify Tribe's compliance?
Tribe provides certificates, its PCI AoC and its SOC 2 Type II report to your security team under NDA, and completes security questionnaires during evaluation.

Talk to our team about your security requirements.

Bring us your questionnaire and your standards. We'll show you the documentation and how we deliver.