Research methodology
How ComplySaaS reviews public vendor compliance signals
The research separates public evidence from assumptions. A BAA, HIPAA statement, or SOC 2 report is one part of vendor review, not a blanket approval for every product, plan, configuration, or use.
Last reviewed: July 25, 2026
Source hierarchy
Stronger conclusions require current first-party evidence. Source levels guide research priority, but every document is still reviewed for date, scope, covered product, and stated limitations.
- 1
Vendor legal and product documents
BAA terms, HIPAA documentation, covered-service lists, product help centers, legal agreements, trust centers, and official security pages.
- 2
Government and standards sources
HHS, OCR, NIST, and other authoritative materials used to explain regulatory or security concepts. These sources do not certify individual vendors.
- 3
Current vendor statements
Official support responses, plan documentation, release notes, or sales materials used only when their scope and date can be identified.
- 4
Third-party discovery signals
Directories, articles, and comparison pages may identify a question or source lead, but do not establish a vendor compliance status by themselves.
Review process
- 1
Identify the exact product, plan, feature, and workflow being reviewed.
- 2
Find current first-party HIPAA, BAA, security, legal, and product-scope sources.
- 3
Separate BAA availability from covered services, configuration, and customer responsibilities.
- 4
Map where PHI may enter fields, files, logs, notifications, support channels, exports, AI features, and integrations.
- 5
Record what public evidence supports, what remains unconfirmed, the source links, and the review date.
- 6
Use the most cautious status supported by the available evidence and direct readers to vendor verification.
How to read status labels
| Label | Research meaning |
|---|---|
| Conditional | Public materials indicate possible regulated use only under specific plan, BAA, covered-service, configuration, or workflow conditions. |
| Not supported for PHI | The reviewed public vendor material excludes PHI use or does not offer the required HIPAA workflow support. |
| Unable to confirm | The reviewed public sources do not provide enough current evidence to support a stronger conclusion. |
| Public SOC 2 evidence | The vendor publicly references SOC 2 evidence. Report scope, period, exceptions, and product coverage still require review. |
Updates and corrections
Review dates
Core profiles display a last-checked date and source notes. Vendor terms can change between reviews, so the date is context, not a guarantee that every source remains current.
Corrections
Correction requests should identify the affected ComplySaaS URL, the statement in question, and a current first-party source. Material corrections are reviewed against the same evidence hierarchy.
Submit a research correctionEditorial independence
Vendors cannot purchase a favorable compliance status or the removal of documented caveats. Commercial relationships, if present, do not replace first-party evidence and should be disclosed separately from research conclusions.
Research limitations
ComplySaaS reviews public information and does not inspect private contracts, customer configurations, audit workpapers, internal controls, or the complete data flow of a reader's organization. Direct vendor and professional review remains necessary.