HITRUST

HITRUST provides cybersecurity assurance and information risk management built around the HITRUST CSF, a threat-adaptive control framework that harmonizes major regulations and standards into a single assessment model. Its business centers on helping organizations assess controls, obtain certifications, and communicate security posture in a consistent, externally validated way.

Beyond the framework itself, HITRUST combines assessment programs, SaaS workflow tools, AI-focused assurance, and third-party risk services to support the lifecycle from scoping and evidence collection through certification and secure results sharing. HITRUST serves organizations across industries that need defensible assurance for sensitive data, regulated operations, and complex vendor ecosystems.

Offerings, Capabilities, and Integrations

HITRUST’s core capability is translating complex security, privacy, and compliance obligations into a standardized assurance program. It supports foundational, intermediate, and risk-based assessment paths, along with AI-specific security and AI risk management offerings. Across these programs, HITRUST emphasizes control harmonization, threat-adaptive updates, centralized quality review, and structured reporting.

Operationally, HITRUST extends those capabilities through SaaS workflow automation, control inheritance, secure results distribution, and tools that connect assessments to procurement and third-party risk processes. Its integration approach includes API-enabled sharing of validated assurance data and ServiceNow-based workflows for vendor risk operations, helping organizations reuse prior work, reduce duplicate evidence requests, and make assessment outputs easier to operationalize.

Products and Services

  • HITRUST CSF: HITRUST’s core control framework, used to harmonize multiple regulations and standards into a single, threat-adaptive model for cybersecurity assurance and compliance management.
  • e1: A one-year validated assessment and certification designed to provide foundational cybersecurity assurance for lower-risk programs, smaller organizations, and teams beginning their HITRUST journey.
  • i1: A one-year validated assessment and certification with a fixed, threat-adaptive control set for organizations that need stronger, scalable assurance without full risk-based tailoring.
  • r2: A two-year, risk-based validated assessment and certification tailored to an organization’s environment, data sensitivity, and regulatory obligations for higher-assurance use cases.
  • AI Security: An AI-focused assessment and certification offering that applies tailored controls to deployed AI systems and is designed for AI platform providers, application providers, and organizations delivering AI-enabled services.
  • AI Risk Management: A non-certified assessment focused on AI governance and risk management, aligned to NIST AI RMF and ISO/IEC 23894 to help organizations identify, assess, and manage AI-specific risks.
  • MyCSF: HITRUST’s secure SaaS platform for managing the assessment and certification lifecycle, including collaboration, evidence collection, workflow automation, inheritance, and reporting.
  • Results Distribution System (RDS): An API-enabled platform for secure delivery, access, and validation of HITRUST assessment results to improve assurance sharing and reduce manual reporting workflows.
  • HITRUST TPRM Services: A HITRUST-managed third-party risk management offering available as a managed service or ServiceNow-enabled solution for onboarding, assessment validation, and vendor risk operations.
  • Products & Services Directory (PSD): A public directory that helps organizations find products and services mapped to HITRUST CSF and other frameworks to support security, compliance, privacy, and AI use cases.
  • HITRUST Assessment XChange for ServiceNow: A ServiceNow application that embeds HITRUST assessment data and workflows into third-party risk management processes to automate onboarding, evidence handling, and vendor reviews.
  • Insights Reports: Supplemental reporting outputs that help organizations communicate security and compliance posture to stakeholders who need additional views beyond standard HITRUST reports.

Target Customers

HITRUST targets organizations that create, store, process, or exchange sensitive and regulated data and need credible proof of cybersecurity maturity. This includes enterprises, midmarket firms, and growth-stage companies that need an assurance path matched to their risk profile, as well as vendors and service providers facing security reviews from customers, regulators, or insurers.

Its customer base spans regulated and high-trust environments such as healthcare, financial services, technology, and organizations managing broad third-party ecosystems. HITRUST also serves AI platform providers, AI-enabled software companies, and enterprises adopting AI that need structured ways to assess AI governance and AI security, along with procurement, risk, and compliance teams consuming those results.

Cloud Integrations and Marketplace

  • AWS Marketplace: HITRUST maintains an official seller presence in AWS Marketplace for subscription-based access to its SaaS offerings, giving customers an AWS procurement path for HITRUST solutions.
  • Azure Marketplace: HITRUST offers MyCSF subscriptions through Azure Marketplace, enabling Azure customers to buy and manage HITRUST’s assessment platform through Microsoft’s marketplace channel.

Key People

  • Daniel Nutkis: Founder and Executive Chairman
  • Gregory Webb: Chief Executive Officer
  • Earl Charles: Chief Financial Officer
  • Sean Foster: Chief Revenue Officer
  • Jeremy Huval: Chief Innovation Officer
  • Bimal Sheth: Executive Vice President, Standards Development & Assurance Operations
  • Marc Solomon: Chief Marketing Officer
  • KC Chewning: Executive Vice President, Operations and Process Improvement
  • Ryan Patrick: Executive Vice President, TPRM Customer Solutions

Key Facts

  • Headquarters: Frisco, Texas, United States
  • Employees: Approximately 140
  • Annual Revenue: Undisclosed
  • Parent Company: None
  • Subsidiaries: None
  • Publicly Listed: Privately held
HiTrust

Enter a search