Psynth Earns ISO/IEC 27001 Certification for Psychological Assessment AI
Accredited certification joins Psynth's SOC 2 Type II attestation and HIPAA, GDPR, and PIPEDA programs, with evidence
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
Accredited certification joins Psynth’s SOC 2 Type II attestation and HIPAA, GDPR, and PIPEDA programs, with evidence published at trust.psynth.ai.
TULSA, OK, UNITED STATES, October 6, 2026 /EINPresswire.com/ — Psynth, the AI platform purpose-built for psychological assessment, today announced it has achieved ISO/IEC 27001:2022 certification for its information security management system. The certificate was issued on September 30, 2026 by Glocert International Certifications (UK) Limited, an accredited certification body, following an independent audit. The certification covers the development, delivery, and support of Psynth’s AI-assisted psychological assessment platform, which enables clinicians to process patient data, clinical documents, and test results into assessment reports, including the web application, supporting cloud environments, and AI model integrations.
ISO/IEC 27001 is the internationally recognized standard for managing information security. The certification completes a program Psynth began in November 2025 to meet five security and privacy frameworks: ISO/IEC 27001, SOC 2 Type II, HIPAA, GDPR, and PIPEDA. In August 2026, Psynth received an unmodified opinion with no exceptions on its SOC 2 Type II examination. The company operates as a HIPAA Business Associate to its clinician customers and as a data processor under GDPR and PIPEDA. Psynth’s certificates, audit reports, policies, and subprocessor list are available at trust.psynth.ai, with some reports provided on request.
Since the audit began, Psynth has brought its core AI operations inside its own Google Cloud environment. All data extraction now runs there on Google Gemini models, with processing kept in-region for customers in Canada and the European Union. Report generation also runs entirely within Psynth’s Google Cloud environment and is processed in-region wherever the required models are available; where they are not, processing is covered by data transfer agreements described in Psynth’s Terms. Patient records, session data, and finalized reports are always stored at rest in the customer’s region: the United States, the European Union, or Canada.
“Last November, we committed to meeting five demanding security and privacy frameworks. For a company our size, that was a significant undertaking, and we took it on because psychologists and their patients deserve verified security, not assurances,” said Stephen Stearman, CEO of Psynth. “I’m proud of our team for the discipline this required. ISO/IEC 27001 and SOC 2 Type II are independent confirmation that security is built into how Psynth operates, and we publish the evidence openly rather than behind a sales process. We have not found another psychological assessment platform that publicly shares this combination of certifications. We also didn’t stop at the audit. Since it began, we have brought our AI extraction and report generation inside our own cloud environment, and data for our Canadian and European customers is always stored at rest in their region. This is only the beginning.”
Psynth is building the domain-specific harness for testing psychologists, serving clinical, neuropsychological, and forensic practitioners across the United States and Canada. Ambient listening and AI-assisted report generation are in market today, with structured intake capabilities scheduled to follow. All clinical judgment remains with the licensed provider: Psynth drafts, and the clinician reviews, edits, and finalizes.
Psynth has also published a guide to what ISO/IEC 27001 certification means for psychologists, covering what was audited, how the certification differs from SOC 2 Type II and privacy laws such as HIPAA, and what certification does not guarantee. The guide is available at psynth.ai/articles/psynth-iso-27001-certified.
Fast Facts
Company: Psynth, Inc., Tulsa, Oklahoma
Announcement: ISO/IEC 27001:2022 certification for Psynth’s information security management system
Certification body: Glocert International Certifications (UK) Limited, an IAS-accredited certification body
Certificate number: 26ISMS-1263
Certified: September 30, 2026; valid through September 29, 2029, subject to ongoing surveillance audits
Certificate scope: The development, delivery, and support of an AI-assisted psychological assessment platform that enables clinicians to process patient data, clinical documents, and test results into assessment reports, including the web application, supporting cloud environments, and AI model integrations
Security and privacy frameworks: ISO/IEC 27001:2022 (certified); SOC 2 Type II (unmodified opinion, no exceptions); HIPAA (Business Associate); GDPR (data processor); PIPEDA
Program timeline: Began November 2025; SOC 2 Type II report issued August 2026; ISO/IEC 27001 certificate issued September 30, 2026
AI infrastructure: Data extraction and report generation run within Psynth’s own Google Cloud environment. Extraction uses Google Gemini models processed in-region for Canada and the EU. Generation is processed in-region where the required models are available, with data transfer agreements covering the remainder, as described in Psynth’s Terms.
Data residency: Data is always stored at rest in the customer’s region: United States, European Union, or Canada.
Products in market: Ambient session listening; AI-assisted psychological evaluation report generation
Coming next: Structured intake
Served specialties: Clinical, neuropsychological, and forensic psychology
Psynth is an AI-assisted platform for psychological assessment, built for licensed clinical, neuropsychological, and forensic psychologists. Psynth reduces the documentation burden of psychological evaluations through ambient session listening, structured data extraction, and AI-assisted report drafting, while keeping clinical judgment and final authorship with the provider. Psynth is ISO/IEC 27001 certified, holds a SOC 2 Type II attestation, and maintains HIPAA, GDPR, and PIPEDA compliance programs, with evidence published at trust.psynth.ai. The company is headquartered in Tulsa, Oklahoma. Learn more at psynth.ai.
Stephen Stearman
Psynth, Inc.
+1 502-762-4445
email us here
Visit us on social media:
LinkedIn
Legal Disclaimer:
EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
![]()
Media gallery
