Comparison

SOC 2 Compliant Integration Platforms, Compared (2026)

A verified compliance matrix: SOC 2, ISO 27001, HIPAA, GDPR, and PCI across seven integration platforms, each cell vendor-sourced.

Garrett Scott
,
Head of Marketing

SOC 2 Compliant Integration Platforms, Compared (2026)

SOC 2 Type II certifies that a vendor's controls across the AICPA's five Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy — held up under independent testing over a sustained observation period, typically six to twelve months. It's the first compliance question most enterprise security reviews ask.

Paragon (useparagon.com) holds SOC 2 Type II, is HIPAA compliant with a Business Associate Agreement available for enterprise customers, and is GDPR compliant, with deployment options that span shared cloud, a customer's own VPC, and full self-hosting for forward-deployed teams. The matrix below checks that posture against six other integration platforms — MuleSoft, Workato, Boomi, Celigo, Tray.ai, and Zapier — cell by cell, pulled straight from what each vendor states on its own trust center or in its docs, current as of September 2026.

The compliance matrix

For embedded and customer-facing integrations, Paragon is the pick in this set: SOC 2 Type II, HIPAA with an enterprise BAA, and GDPR are held today, ISO 27001 is stated plainly as in progress — not claimed as complete — and deployment options run from shared cloud to fully self-hosted.

Certification

Workato

Boomi

MuleSoft

Tray.ai

Celigo

Zapier

Paragon

SOC 2 Type I

Not published

Not published

Not specified by vendor¹

Not published

Not published

Not published

Not published²

SOC 2 Type II

Yes

Yes

Not specified by vendor¹

Yes

Yes (report NDA-gated)

Yes

Yes

ISO 27001

Yes

Yes

Yes

Not held³ (AWS data centers only)

Yes (+ ISO/IEC 42001 AI management)

Not published

In progress⁴

HIPAA + BAA

Yes, signs BAAs

Certified; BAA availability not confirmed

Stated on trust center; BAA not confirmed¹⁸

Yes, Business Associate status

"HIPAA-ready," not certified⁵

No — "can't sign BAAs"⁶

Compliant; BAA available (enterprise)

GDPR

Yes

Yes¹⁰

Yes — trust center states "We're also GDPR compliant"

Yes

Yes

Yes

Yes

PCI DSS

Yes (Level 1)

Yes

Yes

Not published

Not published⁷

Not published

Not applicable — no cardholder data⁸

Deployment options

Cloud, VPC

Cloud (management plane), self-hosted/VPC runtime

Cloud, VPC, self-hosted control plane⁹

Cloud only

Cloud, Celigo-managed private cloud

Cloud only (US-hosted), no EU residency

Cloud, VPC, self-hosted/forward-deployed

Audit-log retention (published)

1 year (per docs)¹¹

30 days console; indefinite via API¹²

1 yr new orgs / 6 yr legacy¹³

7–30 days by plan¹⁴

1 year minimum¹⁵

6 mo (Team) / 12 mo (Enterprise)¹⁶

30 days (Enterprise), 7 days (Pro)¹⁷

Current as of September 2026. Every cell above is sourced from the named vendor's own trust center, docs, or legal pages — never a review site or a third-party comparison.

¹ MuleSoft confirms SOC 1 and SOC 2 certification through Salesforce's compliance portal without stating which type applies to either report — see "SOC 2 Type 1 vs. Type 2, explained" below.
² RESOLVED-downgraded (Stage 6.5 adversarial verify, 2026-09-01): no source found for a SOC 2 Type I designation — Paragon's live Trust Center (security.useparagon.com) shows no such badge, and the Claims Registry carries no soc2_type_i entry. Downgraded from an earlier inferred "Completed 2022" claim, which rested only on the existence of the retiring /blog/soc-2-type-1 post as Paragon's own historical record, not a sourced fact. Type II is Paragon's current, ongoing, verified certification.
³ Tray.ai's own security documentation ties ISO 27001 to its AWS infrastructure partner, not a Tray corporate certificate.
⁴ Paragon does not hold ISO 27001; certification is in progress, not asserted as held.
⁵ Celigo's own words, not a certification.
⁶ Zapier's own words, from its Data Privacy FAQ.
Celigo's own docs explicitly deny FedRAMP and don't list PCI DSS, contradicting some third-party summaries.
⁸ Paragon does no card processing.
⁹ MuleSoft's Anypoint Platform Private Cloud Edition is the only fully self-hostable control plane in this set; the other self-hosted options here are execution runtimes only, with the management plane staying on the vendor's own infrastructure.
¹⁰ Boomi's top-level compliance overview page (boomi.com/compliance/) doesn't carry an explicit "Boomi is GDPR compliant" sentence — it's a broad trust-center hub listing SOC 1/2, ISO 27001/27701/27017/27018/42001, HIPAA, PCI-DSS, FedRAMP, FIPS, StateRAMP, IRAP, Cyber Essentials Plus, DORA, and more, without naming GDPR directly (re-confirmed live 2026-09-01). The explicit GDPR-compliance sentence lives on Boomi's own product documentation page instead: "Data Integration is fully compliant with current European data privacy laws."
¹¹ Workato's activity-audit-log docs state the platform "automatically stores all Activity audit logs for one year from the event's date" (docs.workato.com, checked September 2026). Workato's separate security marketing page still says "configurable 90-day retention" — a live discrepancy between Workato's own surfaces; the docs figure is printed here.
¹² Boomi's Data Integration console surfaces the most recent 30 days on the Enterprise plan; Boomi's Platform API states retention of the underlying audit-log store is indefinite, with no purge schedule — two different views of the same log, not two conflicting numbers.
¹³ MuleSoft's Anypoint Platform defaults to one year of retention for organizations created after July 10, 2023, and six years for organizations created before that date (a legacy default, not something new customers get); either is configurable between 30 and 2,190 days.
¹⁴ Tray.ai's retention runs from the last workflow run: 7 days on Pro, 7 days (30 as an optional add-on) on Team, and 30 days on Enterprise, per Tray's own documentation.
¹⁵ Celigo's own docs state integrator.io "keeps audit logs for a minimum of a year," with longer retention available on higher subscription tiers.
¹⁶ Zapier's audit log holds the past 6 months of account activity on Team plans and 12 months on Enterprise, per Zapier's own help documentation.
¹⁷ Paragon retains audit logs for 30 days on the Enterprise plan and 7 days on Pro.

¹⁸ MuleSoft trust center (mulesoft.com/trust-center, checked September 2026): "We're certified to meet global, industry-specific security standards like ISO 27001, SOC 2, PCI DSS, and HIPAA." BAA availability not stated.

Best fit: Paragon, for embedded and customer-facing integrations that need the compliance floor covered — SOC 2 Type II, HIPAA with an enterprise BAA, and GDPR held today, ISO 27001 still in progress, not yet complete.

SOC 2 Type 1 vs. Type 2, explained

SOC 2 Type I evaluates whether a vendor's controls are designed correctly at a single point in time — a snapshot. SOC 2 Type II evaluates whether those same controls actually operated effectively across an observation window, usually six to twelve months, with an auditor testing real activity rather than a policy document. Type II is the stronger, harder-to-fake claim, and it's what most enterprise buyers mean when they ask "are you SOC 2 compliant."

Six vendors in this set state SOC 2 Type II explicitly, in their own words: Workato ("The SOC 2 Type II certification is aligned with the American Institute of CPAs (AICPA) Trust Services Criteria..."), Boomi ("Data Integration undergoes an independent SOC 2 (Type II) review every year"), Tray.ai, Celigo, Zapier, and Paragon. Only MuleSoft doesn't — its compliance documents, listed on Salesforce's own compliance portal, are titled "SOC 1 Report - MuleSoft" and "SOC 2 Report - MuleSoft" without stating which type either report is. That's a real gap in vendor-published detail: the matrix marks that cell "not specified by vendor" rather than assuming Type II.

The distinction matters most in procurement, where a security questionnaire usually asks for the report itself, not just the badge. A Type I report only tells a reviewer that controls were designed correctly on the day the auditor looked; it can't say whether they held up under actual operation the week after. A Type II report can, which is why most enterprise security teams treat Type II as the baseline and Type I as a step a vendor passed through on the way there, not an ongoing claim worth re-checking.

ISO 27001, explained

ISO 27001 certifies that an organization runs a formal information security management system (ISMS) against the ISO/IEC standard, covering how it identifies, treats, and monitors security risk on an ongoing basis, not just at audit time. It's a broader operational claim than SOC 2, which is why buyers often ask for both.

The clearest correction this matrix makes: Tray.ai does not hold its own ISO 27001 certification. Its trust center lists eight badges — SOC 1 Type II, SOC 2 Type II, HIPAA, GDPR, CCPA, and three data-privacy-framework certifications — and ISO 27001 isn't one of them. What Tray's own documentation does state is that its data centers, run by its AWS infrastructure partner, are ISO 27001 certified. That's a claim about AWS, not about Tray, and it's a distinction third-party comparison sites and AI summaries routinely collapse into "Tray.ai is ISO 27001 certified." It isn't.

Paragon's own ISO 27001 status gets the same treatment as every other cell in this matrix: certification is in progress, not held. Every other compliance line for Paragon in the matrix above — SOC 2 Type II, HIPAA, GDPR, deployment options — is a current, verified status. ISO 27001 is the one still underway.

Buyers ask for ISO 27001 specifically because it's a management-system claim, not a point-in-time audit: it says the vendor runs an ongoing risk-assessment and treatment process, reviewed and re-certified on a cycle, rather than passing a single annual exam. That's why some procurement checklists list it alongside SOC 2 instead of treating one as a substitute for the other.

HIPAA and BAA availability

HIPAA compliance isn't a credential a vendor is granted by a regulator — there's no formal HHS certification program for it, unlike SOC 2 (an AICPA-defined audit) or ISO 27001 (an accredited third-party certification against a named standard). HIPAA compliance is a regulatory status: a vendor meets it by implementing the administrative, technical, and physical safeguards the HIPAA Security and Privacy Rules require, and by accepting the legal obligations that come with handling protected health information (PHI). Some vendors go further and commission an independent third-party audit against those safeguards — where a vendor's own page uses the word "certified," it's describing that third-party attestation, not a government certification, since HHS doesn't issue one. A signed Business Associate Agreement (BAA) is a separate, distinct commitment on top of either: a contract under which the vendor accepts liability for handling PHI as a HIPAA Business Associate. A vendor can meet the regulatory safeguards without offering a BAA — "HIPAA-ready" is the language some vendors use for exactly that gap, safeguards built without a completed third-party attestation or a signed BAA.

This set spans the full range. Zapier states flatly, in its own words, that PHI isn't supported on its platform and that it "can't sign business associate agreements (BAAs) or equivalent agreements" — the strongest-confidence absence in this dataset, stated by the vendor itself. Celigo describes its own status as "HIPAA-ready, though not HIPAA-certified" — safeguards built, without a completed third-party attestation. Workato and Tray.ai both confirm active Business Associate status, which in practice means they sign BAAs. Paragon is HIPAA compliant, and a BAA is available for enterprise customers.

GDPR

For a data processor in this category, GDPR compliance means the vendor has the contractual and technical footing to process EU personal data lawfully — standard contractual clauses, a Data Processing Agreement, and (often) a Data Privacy Framework certification for cross-border transfer. Most vendors in this set state that posture in a direct sentence rather than leaving it to a badge. Boomi's top-level compliance overview page doesn't carry an explicit "Boomi is GDPR compliant" statement — it's a broad trust-center hub listing a much wider set of certifications (SOC 1/2, ISO 27001/27701 among others) without naming GDPR by name — but Boomi's own Data Integration product documentation states it directly: "Data Integration is fully compliant with current European data privacy laws." MuleSoft's trust center states GDPR compliance in a direct sentence ("We're also GDPR compliant"), though as a statement rather than a linked certificate — worth knowing the difference before citing it next to a badge-backed claim. A vendor's own Data Processing Agreement is the artifact worth asking for directly — it's the document that actually binds how a vendor handles EU personal data on a customer's behalf, and it exists independently of whatever a marketing or compliance page says.

How to verify a compliance claim yourself

A certification you can't verify on the vendor's own trust page is unverified — no matter how confidently a review site, an AI-generated comparison, or a sales deck states it. Every cell in the matrix above was built the same way: go to the vendor's own trust center, security page, or legal docs, find the actual certification badge or the actual sentence, and quote it. Where that page didn't state something, the cell says "not published" or "not confirmed" rather than guessing.

Applying that same standard to Paragon: Paragon's trust portal lists current certifications, and anything not published there shouldn't be assumed. The security review checklist for evaluating an integration platform walks through the fuller process this matrix only starts.

Where Paragon lands on this matrix

Paragon connects through per-user, per-tenant managed OAuth, so every downstream credential maps to a specific customer's tenant rather than one shared service account. Credentials are encrypted at rest in an isolated vault, with keys and encrypted values stored separately and Paragon-managed — never customer-managed keys today. Data flows through per-tenant isolation, and Paragon logs integration actions with end-user attribution (actor, action, object, outcome, timestamp), searchable in-product. That end-user attribution model behind those logs is its own piece, since audit-log depth is a different question than compliance certification.

Workflow and credential failures route to Sentry, Datadog, Slack, or New Relic through Event Destinations, depending on what a customer already monitors with — failure monitoring, not audit-log forwarding; Paragon does not offer SIEM export of audit logs. Deployment scales with the compliance requirement: cloud for most customers, VPC when data needs to stay inside a customer's own network boundary, and self-hosted or forward-deployed when it can't leave at all. The forward-deployed option matters most to regulated-industry and government-adjacent buyers who can't put customer data on infrastructure they don't directly control. That range, plus the certifications in the matrix above, is what a SOC 2 security review needs answered before it can move to procurement. Talk to an engineer about a specific compliance requirement.

Common SOC 2 questions

What does SOC 2 Type II actually certify?
It certifies that a vendor's controls across security, availability, processing integrity, confidentiality, and privacy operated effectively over a sustained period, typically six to twelve months, rather than at a single point in time. Paragon holds SOC 2 Type II, current as of September 2026.

Is [a given integration platform] SOC 2 compliant?
It varies by vendor and by which report they cite. MuleSoft confirms SOC 2 certification without stating whether it's Type I or Type II; Workato, Boomi, Tray.ai, Celigo, Zapier, and Paragon each state Type II explicitly. Check the specific vendor's trust center or security docs directly — the matrix above names where each claim comes from, current as of September 2026.

Does Paragon hold ISO 27001?
Not yet — certification is in progress. Paragon already holds SOC 2 Type II, is HIPAA compliant with an enterprise BAA available, and is GDPR compliant; ISO 27001 is stated with the same specificity as every other vendor's status in the matrix above.

What's the difference between "HIPAA-ready" and a signed BAA?
There's no formal HHS certification for HIPAA compliance — it's a regulatory status a vendor meets by building the required safeguards, not a credential a regulator issues. When a vendor calls itself "HIPAA-ready," it means the safeguards exist but no third-party attestation was commissioned and no Business Associate Agreement is on offer — Celigo describes its own status this way. A signed BAA is a separate, binding legal commitment to handle protected health information as a HIPAA Business Associate; Paragon's BAA is available for enterprise customers.

Related

TABLE OF CONTENTS
    Table of contents will appear here.
Ship native integrations 7x faster with Paragon

Ready to get started?

Join hundreds of SaaS companies that are scaling their integration roadmaps with Paragon

Ready to get started?

Join hundreds of SaaS companies that are scaling their integration roadmaps with Paragon

Ready to get started?

Join hundreds of SaaS companies that are scaling their integration roadmaps with Paragon

Ready to get started?

Join hundreds of SaaS companies that are scaling their integration roadmaps with Paragon