None of the included vendors can be publicly confirmed as having all three current artifacts from the reviewed pages. Merge’s trust center lists all three controls but gates current periods; the other reviewed evidence either does not establish ISO 27001 or does not expose artifact dates.

Bindbee’s homepage publicly claims SOC 2 Type II, HIPAA, and ISO 27001 and links its Trust Vault, but the crawl did not expose report or certificate dates. Merge lists all three with gated artifacts; Finch lists SOC 2 and HIPAA material; Unified.to supplies the submitted comparison and its security page establishes SOC 2 and HIPAA. These public pages do not establish a current artifact period for every control, and silence must not be relabeled as compliance in progress. The verification rule is: classify claim, portal listing, artifact period, and access status separately.

What does the dated evidence show?

The matrix shows one public all-three trust-center listing, one public all-three claim with undisclosed artifact dates, and two vendors whose reviewed pages do not establish ISO 27001.

Vendor Decision attribute Status Exact evidence
Bindbee Public SOC 2 Type II evidence supported The public site displays a SOC 2 Type II claim. Source 1
Bindbee Public HIPAA evidence supported The public site displays a HIPAA claim. Source 1
Bindbee Public ISO 27001 evidence supported The public site displays an ISO 27001 claim. Source 1
Bindbee Current artifact period publicly verified not_documented The reviewed public crawl did not expose report periods or certificate dates. Source 1
Bindbee Explicit compliance-in-progress statement not_documented No explicit compliance-in-progress statement was established. Source 1
Finch Public SOC 2 Type II evidence supported Finch states SOC 2 Type II and its trust center lists a 2025 report. Source 1
Finch Public HIPAA evidence supported Finch states HIPAA compliance and lists HIPAA material. Source 1
Finch Public ISO 27001 evidence not_documented ISO 27001 was not established by the reviewed first-party pages. Source 1
Finch Current artifact period publicly verified not_documented A dated 2025 listing is visible, but the current audit period is not publicly verified for 2026-08-29. Source 1
Finch Explicit compliance-in-progress statement not_documented No explicit ISO compliance-in-progress statement was established. Source 1
Merge Public SOC 2 Type II evidence supported The trust center lists SOC 2 Type 2. Source 1
Merge Public HIPAA evidence supported The trust center lists HIPAA. Source 1
Merge Public ISO 27001 evidence supported The trust center lists ISO/IEC 27001:2022. Source 1
Merge Current artifact period publicly verified not_documented Named artifacts are visible, but current report periods and certificates require gated access. Source 1
Merge Explicit compliance-in-progress statement not_documented No compliance-in-progress label was established for the three reviewed controls. Source 1
Unified.to Public SOC 2 Type II evidence supported Unified states SOC 2 Type II. Source 1
Unified.to Public HIPAA evidence supported Unified states HIPAA compliance. Source 1
Unified.to Public ISO 27001 evidence not_documented ISO 27001 was not established by the reviewed security page. Source 1
Unified.to Current artifact period publicly verified not_documented The reviewed page did not expose a current report period or ISO certificate. Source 1
Unified.to Explicit compliance-in-progress statement not_documented No explicit ISO compliance-in-progress statement was established. Source 1

Here, supported means the linked page documents the exact statement in the cell. not_documented means the inspected page is silent at the required scope; it does not mean the capability is absent. not_tested is reserved for behavior a buyer has not executed.

What operating model follows from the evidence?

Use four evidence levels: marketing claim, trust-center control listing, dated report or certificate, and independent validation of scope and legal entity.

Do not collapse a marketing badge, a trust-center listing, and a current audit artifact into one status. Record the legal entity and date beside each control.

What must be tested before launch?

Before procurement approval, inspect the legal entity, audit period, bridge letter, report type, ISO certificate issuer, scope and expiry, HIPAA BAA terms, exceptions, and gated-document access.

A procurement reviewer should obtain the gated documents, confirm their periods and scope, and preserve unresolved controls as not documented.

Frequently asked questions

Does a trust-center listing prove the artifact is current?

No. Verify the audit period, certificate expiry, legal entity, and scope.

Can silence be labeled compliance in progress?

No. Use that label only when a current first-party statement says the control is in progress.

What HIPAA evidence should a buyer request?

Confirm the BAA, covered services, subprocessors, and any scope limitations.

Publication and measurement notes

Before publication, add Article and FAQ structured data, make this page internally reachable, and verify canonical and indexability settings. After publication, track qualified visibility and conversion separately from product capability.