Compliance frameworks, security audits, and quality certifications this company maintains.
Coveo maintains SOC 2 Type II certification covering security, availability, and confidentiality, providing enterprise customers with third-party validated assurance that the Coveo Relevance Cloud platform protects indexed organizational content and user behavioral data.
Coveo is ISO 27001 certified, demonstrating that its information security management system meets international standards for protecting the sensitive enterprise content and behavioral data processed by the Coveo AI search and relevance platform.
Coveo complies with the EU General Data Protection Regulation (GDPR), governing how behavioral data, search queries, and indexed content from European customers are collected, processed, and stored within the Coveo Relevance Cloud platform infrastructure.
Coveo complies with Canada Personal Information Protection and Electronic Documents Act (PIPEDA), ensuring that customer data collected through the Coveo platform from Canadian enterprise users is handled in accordance with federal privacy law requirements.
Coveo complies with the California Consumer Privacy Act (CCPA), providing US-based enterprise customers with the data transparency, deletion, and opt-out rights required for Coveo-indexed user behavioral data and search personalization profiles.
Coveo is pursuing FedRAMP authorization to enable US federal government agencies to deploy the Coveo enterprise search and relevance platform on government intranets and citizen-facing portals subject to federal cloud security requirements.
Coveo search interfaces, including embedded search components and the Coveo Headless UI library, conform to WCAG 2.1 AA accessibility guidelines, ensuring enterprise customers can deploy accessible search experiences for users with disabilities.
Coveo holds ISO 9001:2015 certification for its product development and professional services delivery processes, providing enterprise customers with assurance that Coveo applies a consistent quality management system across its platform and implementation services.
Coveo participates in the Cloud Security Alliance (CSA) STAR Level 1 self-assessment program, publishing its cloud security practices through the CSA CAIQ to support enterprise customer due diligence evaluations of the Coveo Relevance Cloud platform.
Coveo complies with Canada Anti-Spam Legislation (CASL) governing commercial electronic messages sent to Canadian customers and prospects, ensuring that Coveo marketing and transactional communications meet express and implied consent requirements.