# Security certifications and compliance

Pushwoosh maintains security and data privacy practices aligned with recognized compliance standards. For an overview of how Pushwoosh approaches data protection, see [Data safety](https://www.pushwoosh.com/products/data-safety/).

## Which compliance standards does Pushwoosh follow?

Pushwoosh follows the compliance standards listed below. Use this table for a quick view of status and scope. For standards with formal certificates or audit reports, see the next section.

| Compliance standard | Compliant | Details |
| --- | --- | --- |
| ISO 27001:2022 | Yes | Pushwoosh meets industry standards for online security and is certified by ISO 27001:2022. |
| GDPR | Yes | Pushwoosh maintains the highest standards of compliance with data protection regulations. |
| OWASP principles | Yes | The Pushwoosh platform embraces the Security by Design approach to prevent potential threats. |
| HIPAA | Yes | Pushwoosh is HIPAA compliant, ensuring the confidentiality, integrity, and availability of PHI (ePHI). |
| SOC 2 Type 1 | Yes | Pushwoosh possesses a SOC 2 Type 1 report, reflecting its commitment to ensuring the utmost security of user data. |
| EU-U.S. Data Privacy Framework (DPF) | Yes | Pushwoosh is officially certified under the EU-U.S. Data Privacy Framework, including the UK extension and the Swiss DPF. |

## Certificates and reports

The details below explain how each standard was verified and where to find supporting information.

### ISO 27001:2022

Covers Pushwoosh's information security management system (ISMS). Confirmed by Americo, a globally recognized ISO certification body. [Learn more](https://www.pushwoosh.com/blog/iso-27001-certification/).

### SOC 2 Type 1

Report based on an independent auditor's assessment. The SOC 2 framework is built around the AICPA Trust Services Criteria, including security, availability, processing integrity, confidentiality, and privacy. [Learn more](https://www.pushwoosh.com/blog/soc-2-type-1-certification/).

### HIPAA

Confirmed by an independent gap assessment conducted by Riskpro India. Pushwoosh enters into Business Associate Agreements (BAA) with covered entities. [Learn more](https://www.pushwoosh.com/blog/hipaa-compliance/).

### EU-U.S. Data Privacy Framework (DPF)

Pushwoosh, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF, the UK extension, and the Swiss-U.S. DPF. [Learn more](https://www.pushwoosh.com/data-privacy-frameworks/).