Medallia

SafeBaseVerified May 2026

Medallia Compliance & Certifications

SOC 2 Type IISOC 2 Type IISO 27001ISO 27017ISO 27018ISO 27701ISO 42001HIPAAHITRUSTFedRAMPPCI DSSGDPRCCPACSA STARNIST

Frequently Asked Questions

Does Medallia have SOC 2 Type II?

Yes. Medallia holds SOC 2 Type II, SOC 2 Type I, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, HIPAA, HITRUST, FedRAMP, PCI DSS, GDPR, CCPA, CSA STAR, NIST certifications. You can view their trust center at trust.medallia.com for full security and compliance documentation.

Where can I find Medallia's security documentation?

Medallia publishes their trust center on SafeBase at trust.medallia.com. It includes security policies, compliance certifications (SOC 2 Type II, SOC 2 Type I, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, HIPAA, HITRUST, FedRAMP, PCI DSS, GDPR, CCPA, CSA STAR, NIST), and other documentation.

Does Medallia have ISO 27001 certification?

Yes, Medallia is ISO 27001 certified. This international standard confirms they have implemented a comprehensive information security management system (ISMS).

Is Medallia HIPAA compliant?

Yes, Medallia is HIPAA compliant and can support healthcare organizations that handle protected health information (PHI).