Moveworks
low riskAI-Powered Enterprise Automation/IT Service Managementmoveworks.comverified 2024-05-22
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Data is retained only as long as necessary to provide the services under the customer agreement; upon termination, data is typically deleted or returned within 30-60 days per the DPA/MSA.
- Data region
- United States (default), with options for EU/regional data residency via specific enterprise deployments.
- Certifications
- SOC 2 Type IIISO/IEC 27001ISO/IEC 27017ISO/IEC 27018HIPAA compliant
- DPA available
- Yes
- Breach history
- None publicly reported.
- EU AI Act
- Moveworks operates as a B2B enterprise platform; they maintain compliance frameworks aligned with GDPR and evolving international AI governance, though specific EU AI Act categorization depends on the customer's implementation.
Sources
- https://www.moveworks.com/privacy-policy
- https://www.moveworks.com/privacy-policy
- https://www.moveworks.com/security
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.