Research methodology

How ComplySaaS reviews public vendor compliance signals

The research separates public evidence from assumptions. A BAA, HIPAA statement, or SOC 2 report is one part of vendor review, not a blanket approval for every product, plan, configuration, or use.

Last reviewed: July 25, 2026

Source hierarchy

Stronger conclusions require current first-party evidence. Source levels guide research priority, but every document is still reviewed for date, scope, covered product, and stated limitations.

  1. 1

    Vendor legal and product documents

    BAA terms, HIPAA documentation, covered-service lists, product help centers, legal agreements, trust centers, and official security pages.

  2. 2

    Government and standards sources

    HHS, OCR, NIST, and other authoritative materials used to explain regulatory or security concepts. These sources do not certify individual vendors.

  3. 3

    Current vendor statements

    Official support responses, plan documentation, release notes, or sales materials used only when their scope and date can be identified.

  4. 4

    Third-party discovery signals

    Directories, articles, and comparison pages may identify a question or source lead, but do not establish a vendor compliance status by themselves.

Review process

  1. 1

    Identify the exact product, plan, feature, and workflow being reviewed.

  2. 2

    Find current first-party HIPAA, BAA, security, legal, and product-scope sources.

  3. 3

    Separate BAA availability from covered services, configuration, and customer responsibilities.

  4. 4

    Map where PHI may enter fields, files, logs, notifications, support channels, exports, AI features, and integrations.

  5. 5

    Record what public evidence supports, what remains unconfirmed, the source links, and the review date.

  6. 6

    Use the most cautious status supported by the available evidence and direct readers to vendor verification.

How to read status labels

LabelResearch meaning
ConditionalPublic materials indicate possible regulated use only under specific plan, BAA, covered-service, configuration, or workflow conditions.
Not supported for PHIThe reviewed public vendor material excludes PHI use or does not offer the required HIPAA workflow support.
Unable to confirmThe reviewed public sources do not provide enough current evidence to support a stronger conclusion.
Public SOC 2 evidenceThe vendor publicly references SOC 2 evidence. Report scope, period, exceptions, and product coverage still require review.

Updates and corrections

Review dates

Core profiles display a last-checked date and source notes. Vendor terms can change between reviews, so the date is context, not a guarantee that every source remains current.

Corrections

Correction requests should identify the affected ComplySaaS URL, the statement in question, and a current first-party source. Material corrections are reviewed against the same evidence hierarchy.

Submit a research correction

Editorial independence

Vendors cannot purchase a favorable compliance status or the removal of documented caveats. Commercial relationships, if present, do not replace first-party evidence and should be disclosed separately from research conclusions.

Research limitations

ComplySaaS reviews public information and does not inspect private contracts, customer configurations, audit workpapers, internal controls, or the complete data flow of a reader's organization. Direct vendor and professional review remains necessary.