75F · Trust Center

75F Trust Center

Trust center

75F maintains a public trust center documenting SOC 2 and VAPT compliance.

CompanyBuilding AutomationSmart BuildingsHVACIoTEnergy ManagementProject HaystackFacilities ManagementSensorsBuilding Management System
Trust center: https://www.75f.io/software/security/

Certifications & Compliance

SOC 2VAPT

Source

Trust Center

75f-trust-center.yml Raw ↑
generated: '2026-09-05'
method: searched
probe: true
probe_result: >-
  0-working/probe-security-programs.py returned trust=none because it checks trust.<domain>,
  security.<domain> and <domain>/trust|/security|/compliance, and 75F's page is at /software/security/.
  https://www.75f.io/security 301-redirects there and was fetched and read by hand (HTTP 200), which is
  why this file is method: searched rather than probed.
url: https://www.75f.io/software/security/
certifications:
- name: SOC 2
  claim: >-
    "75F is proud to join the list of leading organizations that have achieved SOC 2 compliance." The
    page describes SOC 2 as the AICPA guidelines covering security, availability, processing integrity,
    confidentiality and privacy.
  report_available: false
  auditor_named: false
- name: VAPT
  claim: >-
    75F states it is "VAPT Certified" — vulnerability assessment and penetration testing, described as a
    rigorous process probing the system's security measures and resilience against breaches.
  report_available: false
  auditor_named: false
frameworks:
- name: O.R.A.N.G.E. Security Framework
  claim: >-
    75F's own named set of protocols for securing building control systems, data, applications and
    networks.
evidence:
- source: https://www.75f.io/software/security/
  http_status: 200
  keywords: [soc 2, vapt, penetration]
gaps:
  no_trust_portal: true
  no_subprocessor_list: true
  no_public_audit_report: true
  note: >-
    There is no trust.75f.io or security.75f.io host (both fail to resolve), no downloadable attestation,
    no named auditor and no subprocessor list. The claims are marketing-page assertions; a buyer's
    security team would have to request the SOC 2 report through sales.
vulnerability_disclosure:
  found: false
  probed:
  - {url: 'https://www.75f.io/.well-known/security.txt', status: 404}
  - {url: 'https://75f.io/.well-known/security.txt', status: 301}
  - {url: 'https://api.75f.io/.well-known/security.txt', status: 404}
  - {url: 'https://www.75f.io/responsible-disclosure', status: 404}
  - {url: 'https://www.75f.io/security/responsible-disclosure', status: 404}
  - {url: 'https://www.75f.io/vulnerability-disclosure', status: 404}
  - {url: 'https://hackerone.com/75f', status: 404}
  - {url: 'https://bugcrowd.com/75f', status: 404}
  note: >-
    No security.txt, no responsible-disclosure page, no bug bounty program and no published security
    contact address. No security/75f-vulnerability-disclosure.yml is written and no `Security` pointer is
    emitted in apis.yml, because there is nothing to point at. For a vendor whose API physically actuates
    HVAC equipment in occupied commercial buildings, this is the single most consequential gap in the
    profile — a researcher who finds a flaw has no published route to report it.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/75f-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.