Glean
low riskEnterprise AI Search & Knowledge Discoveryglean.comverified 2025-03-08
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Indexed metadata is updated continuously in real-time or daily to match source systems. Upon contract termination, Glean deletes all customer data within 30 days.
- Data region
- United States, Europe, and Asia Pacific (deployed via Glean-hosted GCP/AWS or customer-managed VPC)
- Certifications
- SOC 2 Type IIISO/IEC 27001ISO/IEC 27017ISO/IEC 27018HIPAA Compliance
- DPA available
- Yes
- Breach history
- none
- EU AI Act
- Glean acts as an AI provider and data processor under user control. It is generally classified as a minimal-risk application under the EU AI Act, with transparency obligations for its generative AI features (Glean Chat).
Sources
- https://www.glean.com/security
- https://www.glean.com/privacy-policy
- https://www.glean.com/terms-of-service
- https://trust.glean.com/
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.