Skip to content
Security & Compliance

Provider Compliance Matrix

Vendor security evaluation for regulated industries. Compare GPU cloud providers across SOC 2, HIPAA, FedRAMP, ISO 27001, GDPR, and PCI DSS — so your legal, security, and procurement teams can make decisions with verified, structured data.

11 providers6 certifications trackedData residency by regionVerified per entry where sourced

Showing all 11 GPU cloud providers

Legend✓ CertifiedIn ProgressPartial— Not certified~date Prior record — not confirmed in portal we read
Provider
SOC 2
Audit
HIPAA
Health Data
FedRAMP
US Gov
ISO 27001
ISMS
GDPR
EU Privacy
PCI DSS
Payments
Docs
AWS6/6
✓ Type II2026-08
✓ BAA2026-08
High (GovCloud)2026-08
✓ Certified2026-08
✓ Compliant2026-08
Level 12026-08
Trust
GCP6/6
✓ Type II2026-08
✓ BAA2026-08
High2026-08
✓ Certified2026-08
✓ Compliant2026-08
Level 12026-08
Trust
Azure6/6
✓ Type II2026-08
✓ BAA2026-08
High (Gov)2026-08
✓ Certified2026-08
✓ Compliant2026-08
Level 12026-08
Trust
Lambda3/6
✓ Type II2026-08
checked 2026-08
checked 2026-08
✓ Certified2026-08
✓ Compliant2026-08
checked 2026-08
Trust
CoreWeave4/6
✓ Type II2026-08
✓ BAA~2026-08
In Progress~2026-08
✓ Certified2026-08
✓ Compliant2026-08
checked 2026-08
Trust
RunPod3/6
✓ Type II · bridge letter 20262026-08
✓ HIPAA2026-08
checked 2026-08
checked 2026-08
✓ Compliant2026-08
checked 2026-08
Trust
Nebius3/6
✓ Type II2026-08
In SOC 2 scope2026-08
checked 2026-08
✓ Certified2026-08
✓ Compliant2026-08
checked 2026-08
Trust
Together AI4/6
✓ Type II2026-08
✓ BAA~2026-08
checked 2026-08
✓ Certified2026-08
✓ Compliant~2026-08
checked 2026-08
Trust
Crusoe4/6
✓ Type II2026-08
✓ BAA~2026-08
In Progress~2026-08
✓ Certified2026-08
✓ Compliant2026-08
checked 2026-08
Trust
Hyperstack2/6
✓ Certified
✓ Compliant
Trust
Thunder Compute1/6
✓ DPA published
Trust

Data Residency & Region Coverage

All 11 providers
AWS7 regions
USEUAPCASAMEAF

30+ regions

GCP6 regions
USEUAPCASAME

40+ regions

Azure7 regions
USEUAPCASAMEAF

60+ regions

Lambda4 regions
US-EastUS-WestEU-CentralAP
CoreWeave3 regions
US-EastUS-WestEU-West
RunPod3 regions
USEUAP

Community cloud — region not guaranteed

Nebius2 regions
EU (Finland)EU (Netherlands)
Together AI1 region
US

Inference API

Crusoe1 region
US

Multiple DCs, Stargate partner

Hyperstack4 regions
EU (Norway)EU (Sweden)CanadaUS
Thunder Compute2 regions
US-East (Atlanta, GA)Canada

US + Canada (provider-stated, July 2026). YC S24, founded 2024.

HIPAA and gated portals — CoreWeave, Together AI and Crusoe show HIPAA as source-checked rather than provider-stated. All three run trust portals that gate full documentation behind an access request; HIPAA attestations in particular commonly sit behind that gate rather than on the public badge view. A source-checked entry reflects our read of the public layer — not the provider's posture. Request BAA documentation directly for regulated workloads.

Key Takeaways for Security Teams

Hyperscalers: Full Stack

AWS, GCP, and Azure hold all six tracked certifications — including FedRAMP High and PCI DSS Level 1. For workloads requiring FedRAMP authorization or PCI DSS compliance, these three are the only options among tracked providers. For healthcare and SOC 2, the specialist tier now has portal-verified coverage.

Specialist Clouds: Maturing

CoreWeave, Lambda, Nebius, Together AI, Crusoe, and RunPod all have SOC 2 Type II at provider-stated evidence (trust portals read 2026-08). RunPod additionally holds HIPAA at provider-stated evidence. HIPAA posture for CoreWeave, Together AI, and Crusoe is source-checked — not confirmed from public portal documentation; verify directly for regulated workloads. CoreWeave and Crusoe listed FedRAMP as in-progress on their portals at last read (source-checked).

No Portal Verified

Hyperstack and Thunder Compute have no publicly readable trust portal. Hyperstack lists SOC 2 and GDPR compliance; Thunder Compute publishes a GDPR DPA. Neither has been source-checked. Treat both as unknown posture for regulated procurement decisions until direct verification is possible.

Disclaimer: Certification data is verified on a rolling basis; dates are shown per entry where a source has been read directly. Entries without a date have not been verified against a primary source. Certifications change — always verify directly with the provider before procurement decisions. GPUAdvisor is not a legal or compliance authority. Links to provider trust pages are provided for reference only and do not constitute an endorsement or legal opinion. Consult your legal and security teams before committing to any provider for regulated workloads.

Need help mapping compliance requirements to providers?

Our advisory team works with regulated-industry buyers in healthcare, fintech, and government contracting.