Provider Compliance Matrix
Vendor security evaluation for regulated industries. Compare GPU cloud providers across SOC 2, HIPAA, FedRAMP, ISO 27001, GDPR, and PCI DSS — so your legal, security, and procurement teams can make decisions with verified, structured data.
Showing all 11 GPU cloud providers
| Provider | SOC 2 Audit | HIPAA Health Data | FedRAMP US Gov | ISO 27001 ISMS | GDPR EU Privacy | PCI DSS Payments | Docs |
|---|---|---|---|---|---|---|---|
AWS6/6 | ✓ Type II2026-08 | ✓ BAA2026-08 | High (GovCloud)2026-08 | ✓ Certified2026-08 | ✓ Compliant2026-08 | Level 12026-08 | Trust |
GCP6/6 | ✓ Type II2026-08 | ✓ BAA2026-08 | High2026-08 | ✓ Certified2026-08 | ✓ Compliant2026-08 | Level 12026-08 | Trust |
Azure6/6 | ✓ Type II2026-08 | ✓ BAA2026-08 | High (Gov)2026-08 | ✓ Certified2026-08 | ✓ Compliant2026-08 | Level 12026-08 | Trust |
Lambda3/6 | ✓ Type II2026-08 | —checked 2026-08 | —checked 2026-08 | ✓ Certified2026-08 | ✓ Compliant2026-08 | —checked 2026-08 | Trust |
CoreWeave4/6 | ✓ Type II2026-08 | ✓ BAA~2026-08 | In Progress~2026-08 | ✓ Certified2026-08 | ✓ Compliant2026-08 | —checked 2026-08 | Trust |
RunPod3/6 | ✓ Type II · bridge letter 20262026-08 | ✓ HIPAA2026-08 | —checked 2026-08 | —checked 2026-08 | ✓ Compliant2026-08 | —checked 2026-08 | Trust |
Nebius3/6 | ✓ Type II2026-08 | In SOC 2 scope2026-08 | —checked 2026-08 | ✓ Certified2026-08 | ✓ Compliant2026-08 | —checked 2026-08 | Trust |
Together AI4/6 | ✓ Type II2026-08 | ✓ BAA~2026-08 | —checked 2026-08 | ✓ Certified2026-08 | ✓ Compliant~2026-08 | —checked 2026-08 | Trust |
Crusoe4/6 | ✓ Type II2026-08 | ✓ BAA~2026-08 | In Progress~2026-08 | ✓ Certified2026-08 | ✓ Compliant2026-08 | —checked 2026-08 | Trust |
Hyperstack2/6 | ✓ Certified | — | — | — | ✓ Compliant | — | Trust |
Thunder Compute1/6 | — | — | — | — | ✓ DPA published | — | Trust |
Data Residency & Region Coverage
All 11 providers30+ regions
40+ regions
60+ regions
Community cloud — region not guaranteed
Inference API
Multiple DCs, Stargate partner
US + Canada (provider-stated, July 2026). YC S24, founded 2024.
HIPAA and gated portals — CoreWeave, Together AI and Crusoe show HIPAA as source-checked rather than provider-stated. All three run trust portals that gate full documentation behind an access request; HIPAA attestations in particular commonly sit behind that gate rather than on the public badge view. A source-checked entry reflects our read of the public layer — not the provider's posture. Request BAA documentation directly for regulated workloads.
Key Takeaways for Security Teams
AWS, GCP, and Azure hold all six tracked certifications — including FedRAMP High and PCI DSS Level 1. For workloads requiring FedRAMP authorization or PCI DSS compliance, these three are the only options among tracked providers. For healthcare and SOC 2, the specialist tier now has portal-verified coverage.
CoreWeave, Lambda, Nebius, Together AI, Crusoe, and RunPod all have SOC 2 Type II at provider-stated evidence (trust portals read 2026-08). RunPod additionally holds HIPAA at provider-stated evidence. HIPAA posture for CoreWeave, Together AI, and Crusoe is source-checked — not confirmed from public portal documentation; verify directly for regulated workloads. CoreWeave and Crusoe listed FedRAMP as in-progress on their portals at last read (source-checked).
Hyperstack and Thunder Compute have no publicly readable trust portal. Hyperstack lists SOC 2 and GDPR compliance; Thunder Compute publishes a GDPR DPA. Neither has been source-checked. Treat both as unknown posture for regulated procurement decisions until direct verification is possible.
Disclaimer: Certification data is verified on a rolling basis; dates are shown per entry where a source has been read directly. Entries without a date have not been verified against a primary source. Certifications change — always verify directly with the provider before procurement decisions. GPUAdvisor is not a legal or compliance authority. Links to provider trust pages are provided for reference only and do not constitute an endorsement or legal opinion. Consult your legal and security teams before committing to any provider for regulated workloads.
Our advisory team works with regulated-industry buyers in healthcare, fintech, and government contracting.