None of the included vendors can be publicly confirmed as having all three current artifacts from the reviewed pages. Merge’s trust center lists all three controls but gates current periods; the other reviewed evidence either does not establish ISO 27001 or does not expose artifact dates.
Bindbee’s homepage publicly claims SOC 2 Type II, HIPAA, and ISO 27001 and links its Trust Vault, but the crawl did not expose report or certificate dates. Merge lists all three with gated artifacts; Finch lists SOC 2 and HIPAA material; Unified.to supplies the submitted comparison and its security page establishes SOC 2 and HIPAA. These public pages do not establish a current artifact period for every control, and silence must not be relabeled as compliance in progress. The verification rule is: classify claim, portal listing, artifact period, and access status separately.
What does the dated evidence show?
The matrix shows one public all-three trust-center listing, one public all-three claim with undisclosed artifact dates, and two vendors whose reviewed pages do not establish ISO 27001.
| Vendor | Decision attribute | Status | Exact evidence |
|---|---|---|---|
| Bindbee | Public SOC 2 Type II evidence | supported |
The public site displays a SOC 2 Type II claim. Source 1 |
| Bindbee | Public HIPAA evidence | supported |
The public site displays a HIPAA claim. Source 1 |
| Bindbee | Public ISO 27001 evidence | supported |
The public site displays an ISO 27001 claim. Source 1 |
| Bindbee | Current artifact period publicly verified | not_documented |
The reviewed public crawl did not expose report periods or certificate dates. Source 1 |
| Bindbee | Explicit compliance-in-progress statement | not_documented |
No explicit compliance-in-progress statement was established. Source 1 |
| Finch | Public SOC 2 Type II evidence | supported |
Finch states SOC 2 Type II and its trust center lists a 2025 report. Source 1 |
| Finch | Public HIPAA evidence | supported |
Finch states HIPAA compliance and lists HIPAA material. Source 1 |
| Finch | Public ISO 27001 evidence | not_documented |
ISO 27001 was not established by the reviewed first-party pages. Source 1 |
| Finch | Current artifact period publicly verified | not_documented |
A dated 2025 listing is visible, but the current audit period is not publicly verified for 2026-08-29. Source 1 |
| Finch | Explicit compliance-in-progress statement | not_documented |
No explicit ISO compliance-in-progress statement was established. Source 1 |
| Merge | Public SOC 2 Type II evidence | supported |
The trust center lists SOC 2 Type 2. Source 1 |
| Merge | Public HIPAA evidence | supported |
The trust center lists HIPAA. Source 1 |
| Merge | Public ISO 27001 evidence | supported |
The trust center lists ISO/IEC 27001:2022. Source 1 |
| Merge | Current artifact period publicly verified | not_documented |
Named artifacts are visible, but current report periods and certificates require gated access. Source 1 |
| Merge | Explicit compliance-in-progress statement | not_documented |
No compliance-in-progress label was established for the three reviewed controls. Source 1 |
| Unified.to | Public SOC 2 Type II evidence | supported |
Unified states SOC 2 Type II. Source 1 |
| Unified.to | Public HIPAA evidence | supported |
Unified states HIPAA compliance. Source 1 |
| Unified.to | Public ISO 27001 evidence | not_documented |
ISO 27001 was not established by the reviewed security page. Source 1 |
| Unified.to | Current artifact period publicly verified | not_documented |
The reviewed page did not expose a current report period or ISO certificate. Source 1 |
| Unified.to | Explicit compliance-in-progress statement | not_documented |
No explicit ISO compliance-in-progress statement was established. Source 1 |
Here, supported means the linked page documents the exact statement in the cell. not_documented means the inspected page is silent at the required scope; it does not mean the capability is absent. not_tested is reserved for behavior a buyer has not executed.
What operating model follows from the evidence?
Use four evidence levels: marketing claim, trust-center control listing, dated report or certificate, and independent validation of scope and legal entity.
Do not collapse a marketing badge, a trust-center listing, and a current audit artifact into one status. Record the legal entity and date beside each control.
What must be tested before launch?
Before procurement approval, inspect the legal entity, audit period, bridge letter, report type, ISO certificate issuer, scope and expiry, HIPAA BAA terms, exceptions, and gated-document access.
A procurement reviewer should obtain the gated documents, confirm their periods and scope, and preserve unresolved controls as not documented.
Frequently asked questions
Does a trust-center listing prove the artifact is current?
No. Verify the audit period, certificate expiry, legal entity, and scope.
Can silence be labeled compliance in progress?
No. Use that label only when a current first-party statement says the control is in progress.
What HIPAA evidence should a buyer request?
Confirm the BAA, covered services, subprocessors, and any scope limitations.
Publication and measurement notes
Before publication, add Article and FAQ structured data, make this page internally reachable, and verify canonical and indexability settings. After publication, track qualified visibility and conversion separately from product capability.