Heidi is early-stage software built on certified infrastructure, with the architecture, isolation, encryption, audit trails, doing the real work. Formal certifications follow company maturity; ask via the waitlist for the current compliance status.
An honest answer beats a vague one: certifications are point-in-time attestations that young companies acquire as they grow, and claiming otherwise would be exactly the kind of unverifiable assertion Heidi exists to end.
What you can evaluate today is the architecture, which this site documents unusually thoroughly, and the underlying infrastructure providers' certifications, which are industry-standard. Security reviews get real answers, engineer to engineer.