Review the current compliance status, security safeguards, and compliance resources available for Knowledge Base in Acrobat.
Knowledge Base in Acrobat is HIPAA Ready, and Adobe is working toward the additional compliance certifications and assessments listed below. Because these items aren't added to the Adobe Trust Center for Knowledge Base until the applicable work is complete, this page provides their current public status. As each item is completed, Adobe will publish its authoritative status in the Adobe Trust Center.
Review the current compliance status
| Compliance program | Status |
|---|---|
| HIPAA readiness | Available now |
| SOC 2 | Targeted by end of 2026 |
| SOC 3 | Targeted by end of 2026 |
| ISO 9001 | Targeted by end of 2026 |
| ISO 27001 | Targeted by end of 2026 |
| ISO 27017 | Targeted by end of 2026 |
| ISO 27018 | Targeted by end of 2026 |
| ISO 22301 | Targeted by end of 2026 |
| C5 Certification (Germany) | Targeted by end of 2026 |
| FedRAMP Tailored | Targeted by end of 2026 |
| EudraLex Volume 4, Annex 11 | Targeted by end of 2026 |
| CSA STAR Level 2 | Targeted by end of 2026 |
A target date indicates work in progress. It doesn't mean that Knowledge Base currently holds the listed certification or assessment. Adobe will publish completed compliance information in the Adobe Trust Center.
Understand how Knowledge Base protects your data
Knowledge Base uses Adobe identity services to authenticate users and control access to the service. Users can access collections and content only according to their entitlement and sharing permissions.
Adobe protects Knowledge Base data using:
- Encryption in transit: Data is encrypted over HTTPS using TLS 1.2 or later.
- Encryption at rest: Data stored by Knowledge Base is encrypted using AES 256-bit encryption.
- Access controls: Adobe Identity Management Services authenticates users before granting access to Knowledge Base.
- Collection-level sharing: Uploaded content remains available only to authorized users with access to the collection.
Understand generative AI processing
Knowledge Base uses Microsoft Azure OpenAI together with Adobe technology to process collection content and generate responses.
To perform operations such as answering questions, Adobe may send Microsoft Azure OpenAI:
- The user's query.
- Relevant document content needed to answer the query.
- Instructions used to generate the response.
Adobe has disabled logging for this processing so Microsoft cannot collect, review, or store the data that Adobe sends to Azure OpenAI. Adobe doesn't use customer data to train or fine-tune Azure OpenAI.
Knowledge Base also uses Microsoft Azure AI Content Safety to filter supported categories of potentially harmful content.
Understand data storage and retention
Knowledge Base stores uploaded documents and the information generated to index and retrieve their content. AI Assistant chat history remains in Knowledge Base data storage until the associated document or collection is deleted.
When a user deletes a document, Knowledge Base deletes the document and its corresponding metadata from the application. The deleted document is no longer available to users and can't be recovered through Knowledge Base.
For content synchronized from SharePoint or Google Drive, Knowledge Base maintains copies of the synchronized documents. If authorization to the source repository becomes invalid, synchronization stops and the existing copies remain in Knowledge Base until they are removed.
Knowledge Base hosts its application, generative AI services, and associated data storage in AWS data centers in the United States and Germany. Adobe restricts Azure OpenAI processing to the customer's provisioned North America or European Union data sovereignty zone.
For more information about retention, deletion, offboarding, and data residency, see Data privacy and handling in Knowledge Base in Acrobat.
Use Knowledge Base with HIPAA-regulated data
Knowledge Base is HIPAA Ready. Organizations that plan to process protected health information (PHI) must complete the applicable Business Associate Agreement (BAA) process with Adobe before using Knowledge Base for that purpose.
Contact your Adobe account team to begin the BAA process.
Customers with regulated use cases must also disable access to Knowledge Base collections from PDF Spaces before ingesting regulated data. Disabling the integration prevents users from linking Knowledge Base collections to PDF Spaces or accessing collection content through PDF Spaces. Other Knowledge Base access methods continue to operate.
Disabling PDF Spaces integration doesn't by itself establish compliance with a regulatory framework. Don't process PHI in Knowledge Base until the applicable BAA process and HIPAA enablement are complete.
For the complete process and configuration requirements, see Enable HIPAA readiness for Knowledge Base in Acrobat.
Access additional security and compliance documentation
Adobe provides additional security and compliance information to authorized customers under NDA.
Use the secured Knowledge Base NDA packet to access supporting materials for customer security and compliance reviews, including information that Adobe doesn't publish on public Help pages.
Review completed compliance information
The Adobe Trust Center provides authoritative information about completed Adobe certifications, standards, and compliance programs.
As compliance work for Knowledge Base is completed, Adobe will publish the applicable status in the Adobe Trust Center. Until then, use the current status on this page and the secured NDA documentation when additional supporting information is required.
Things to know
- HIPAA Ready doesn't mean that every use of Knowledge Base automatically complies with HIPAA.
- Compliance programs shown with a target date are still in progress.
- Target dates can change while certification and assessment work is underway.
- Your organization remains responsible for using Knowledge Base in accordance with its agreements with Adobe and applicable legal and regulatory requirements.
- Detailed architecture and other controlled security information are available through the NDA documentation rather than this public Help page.