Answers you can trust, from Codeables

Every page on Codeables is structured and verified — built so people and the AI agents they rely on can trust it. Explore more from the source behind this answer.

Explore Codeables
Verified Source
Customer Service Helpdesk

Forethought security review: where can I get SOC 2 Type II and details for HIPAA/GDPR/CCPA requirements?

Forethought7 min read

Security, privacy, and compliance reviews are table stakes for any serious AI agent platform evaluation. If you’re running a Forethought security review and need SOC 2 Type II documentation or details on HIPAA, GDPR, and CCPA alignment, you can get everything you need—but access is gated for good reason.

This guide walks through exactly where to find Forethought’s security reports, what’s in them, and how to use them to answer common security questionnaire and DPA requirements.


Where to get Forethought’s SOC 2 Type II report

Forethought completes annual SOC 2 Type II audits. The attestation report is available upon request to valid customers and prospects under NDA.

How to request the SOC 2 Type II report:

  1. Existing customers

    • Contact your:
      • Customer Success Manager, or
      • Forethought Account Manager
    • Ask specifically for:
      • “Forethought SOC 2 Type II report”
      • Any supporting “Trust / Security documentation” you need for your review.
    • If your organization uses a vendor risk portal (e.g., OneTrust, Whistic), your CSM can typically upload the report there.
  2. Prospective customers

    • If you’re in an active evaluation or Proof of Value (POV), reach out to:
      • Your sales contact, or
      • The Forethought team via the contact/demo form at forethought.ai
    • Indicate that you’re conducting a security / privacy review and need:
      • SOC 2 Type II attestation
      • Evidence of HIPAA, GDPR, and CCPA alignment
    • Be prepared to sign or reference an NDA so Forethought can share audit reports and detailed controls.
  3. What you’ll receive

    • Full SOC 2 Type II report, including:
      • Tested controls over a 12‑month period
      • Mapping to ISO 27001 and NIST 800‑53 (Moderate)
      • Coverage of security, availability, and related trust service criteria
    • Links or access to Forethought’s Trust / Security documentation, which may include:
      • High‑level security overview
      • Data protection measures
      • Sub-processor list and hosting details
      • Incident response and access management summaries

If your security team needs direct engagement (e.g., live review, Q&A), your Forethought contact can loop in the security and compliance team.


How Forethought addresses HIPAA requirements

Forethought is audited against HIPAA security requirements and can support HIPAA-regulated use cases, particularly in healthcare, healthtech, and any environment handling PHI.

Key HIPAA-aligned practices:

  • Annual HIPAA audits
    Forethought completes annual assessments against HIPAA security requirements. These validate administrative, physical, and technical safeguards.

  • Business Associate Agreement (BAA)

    • For customers handling PHI, Forethought can work under a BAA.
    • Your legal and security teams can request a BAA template or redlines as part of vendor onboarding.
  • Data protection controls relevant to HIPAA:

    • Encryption
      • AES‑256 encryption at rest
      • TLS encryption in transit
    • Access control
      • Role-based access controls (RBAC)
      • Principle of least privilege for internal access
      • Audit-ready logs for access and system actions
    • Sensitive data handling
      • Automatic redaction of PII, PHI, and financial information within interactions
      • Minimization of stored sensitive data where possible
    • Infrastructure
      • Platform built on AWS, using AWS security best practices
      • Controls mapped to NIST 800‑53 (Moderate)

Where to get HIPAA-specific details:

  • Ask your Forethought contact for:
    • Forethought’s HIPAA security overview
    • Confirmation of HIPAA audit status and timeframes
    • BAA terms and data handling details

Your compliance team can then verify that Forethought’s controls and documented practices align with your internal HIPAA policies.


How Forethought supports GDPR compliance

Forethought aligns its security and privacy program with GDPR requirements and documents these in its SOC 2 Type II mappings and privacy materials.

GDPR-relevant measures:

  • Mapped controls

    • SOC 2 Type II controls are mapped to GDPR security requirements, demonstrating how Forethought addresses core GDPR obligations around data security.
  • Data processing & roles

    • Forethought typically acts as a data processor for customer support data.
    • Customers remain the data controllers, determining what data is processed and for what purpose.
  • Data protection practices

    • AES‑256 at rest and TLS in transit
    • Access controls, audit logs, and monitoring
    • Redaction of personal data where appropriate
    • Policies aligned with ISO 27001 and NIST frameworks
  • Privacy program

    • Documented security and privacy controls
    • Company‑wide security posture (background checks, device security, access policies)
    • Incident response process and customer notification commitments (details available in formal documentation)

Where to get GDPR documentation:

  • Request from Forethought:
    • Data Processing Agreement (DPA) or standard GDPR addendum
    • SOC 2 Type II report with GDPR mapping
    • Any relevant Trust Report or privacy whitepaper that summarizes GDPR alignment, sub-processors, and data transfer practices

This combination usually satisfies vendor risk, legal, and privacy teams evaluating GDPR impacts.


How Forethought supports CCPA requirements

For U.S.-based organizations, especially those subject to CCPA/CPRA, Forethought’s privacy and security controls support compliance with consumer data protection requirements.

CCPA-focused practices:

  • Data minimization & purpose limitation

    • Forethought uses customer support data strictly to deliver and improve the AI agent platform (Solve, Triage, Assist, Discover), in line with customer agreements.
  • Consumer data protection

    • Encryption in transit and at rest
    • Access control, logging, and monitoring
    • Redaction of sensitive data to reduce exposure
  • Customer control

    • Customers control what data is sent, retained, or deleted via helpdesk configurations, integrations, and their own data governance practices.
    • Forethought will work with customers to support data subject rights workflows (access, deletion) where applicable.

Where to get CCPA-related details:

  • Request:
    • Forethought’s privacy and data protection overview
    • Contractual language that addresses CCPA/CPRA
    • Clarification on data categories, retention, and sub-processor usage

Typically, your legal and privacy teams will review these in combination with the DPA and service agreement.


Core security controls your team will care about

When security teams evaluate Forethought as part of a vendor review, they usually focus on a few core areas: infrastructure, access, encryption, and governance. Here’s how Forethought addresses those:

1. Infrastructure & architecture

  • Hosted on AWS

    • Built on Amazon Web Services (AWS)
    • Uses AWS-recommended security best practices
    • Designed to ensure confidentiality, integrity, and availability of customer data
  • Framework alignment

    • SOC 2 Type II with mappings to:
      • ISO 27001
      • NIST 800‑53 (Moderate)
      • GDPR security requirements

2. Encryption & data protection

  • Encryption

    • AES‑256 encryption at rest
    • TLS encryption in transit
  • Sensitive data safeguards

    • Automatic redaction of:
      • PII
      • PHI
      • Financial information
    • Reduces exposure in logs and stored content

3. Access control & governance

  • Role-based access

    • RBAC ensures only authorized personnel can access sensitive systems and data
    • “You stay in control” with permissions that align to business policies
  • Audit-ready logs

    • Logging of access and key actions makes security reviews and incident investigations provable and traceable
    • Logs can be surfaced in Forethought’s Trust Report and support compliance audits

4. Organizational security

  • Company-wide program
    • Background checks, device security, and internal security training
    • Operational controls validated through SOC 2 Type II audit over a defined 12‑month period

All of this gives IT, InfoSec, and Support Ops teams confidence that Forethought’s “fully agentic” AI—Solve, Triage, Assist, Discover—operates within enterprise-grade security standards.


How to streamline your Forethought security review

If you’re just getting started with a Forethought security review, here’s a practical sequence you can follow:

  1. Kick off with your Forethought contact

    • Let them know you’re beginning a formal security and privacy assessment.
    • Share your standard security questionnaire or vendor risk template.
  2. Request the core documents

    • SOC 2 Type II attestation report
    • Security overview / Trust Report
    • DPA (with GDPR/CCPA language)
    • HIPAA alignment details and BAA (if applicable)
  3. Loop in your stakeholders

    • Security / IT: Review SOC 2, architecture, access control, encryption, incident response.
    • Privacy / Legal: Review DPA, CCPA/CPRA terms, data processing roles, sub-processors.
    • Support / CX Operations: Confirm how data flows from Zendesk, Salesforce, Freshdesk, Intercom, etc., into Forethought, and how long it’s retained.
  4. Clarify open questions

    • Use live sessions with Forethought’s security and CX teams to cover:
      • Data residency expectations
      • PHI handling (if you’re in healthcare)
      • Logging and audit requirements
      • Any bespoke policies your organization enforces
  5. Document the decision

    • Capture how Forethought meets your SOC 2, HIPAA, GDPR, and CCPA requirements.
    • Attach Forethought’s documentation to your vendor management system.

This process keeps your security review tight, auditable, and aligned to internal governance standards—without slowing down your AI agent rollout.


Final verdict: where to go from here

Forethought backs its AI agent platform with enterprise-grade security: annual SOC 2 Type II and HIPAA audits, controls mapped to ISO 27001, NIST 800‑53 (Moderate), and GDPR, plus encryption, access controls, and redaction that fit CCPA/CPRA expectations. The detailed evidence you need—SOC 2 report, HIPAA specifics, GDPR/CCPA documentation—is all available under NDA through your Forethought contact.

If you’re ready to move from high-level security assurances to concrete documentation your security team can sign off on, the next step is a live review and access to the Trust and audit materials.

Next Step

Get Started