ACTO · Trust Center

Acto Trust Center

Trust center

ACTO maintains a public trust center documenting SOC 2 Type 2, ISO/IEC 27001, GDPR, and FDA 21 CFR Part 11 compliance.

Life SciencesPharmaceuticalSales EnablementLearning ManagementField Force EffectivenessMedical AffairsCommercial ExcellenceTraining and CertificationOmnichannel EngagementArtificial IntelligenceMedical DevicesBiotechnologyContent ManagementHealthcare
Trust center: https://trust.acto.com/

Certifications & Compliance

SOC 2 Type 2ISO/IEC 27001GDPRFDA 21 CFR Part 11

Source

Trust Center

acto-trust-center.yml Raw ↑
generated: '2026-09-06'
method: searched
probe: true
source: https://trust.acto.com/
url: https://trust.acto.com/
platform: SafeBase
platform_evidence: >-
  trust.acto.com is a CNAME to acto.portals.safebase.io — a first-party subdomain ACTO
  controls, delegated to the SafeBase trust-center product.
certifications:
- SOC 2 Type 2
- ISO/IEC 27001
- GDPR
- FDA 21 CFR Part 11
evidence:
- source: https://trust.acto.com/
  status: 200
  keywords:
  - soc 2 type 2
  - iso/iec 27001
  - gdpr
  - 21 cfr part 11
  - trust center
  note: >-
    Certification list read from the rendered trust-center page. The host is behind a
    Cloudflare bot challenge and answers 403 to a plain command-line fetch, so the page was
    read with a browser-class client; it is live, not dead.
- source: https://acto.com/platform/
  status: 200
  note: >-
    Corroborates the 21 CFR Part 11 claim independently — "validated closed and open
    systems, secure user authentication, time-stamped audit trails, change control
    processes".
readability: rendered-read
vulnerability_disclosure:
  found: false
  partial: true
  note: >-
    The trust center carries an "App Security" section listing a "Responsible Disclosure"
    document, but the document itself sits inside the SafeBase portal behind a document
    access request and could not be read anonymously, so no policy URL and no security
    contact can be recorded. The automated probe (0-working/probe-security-programs.py)
    correctly declined to write a vulnerability-disclosure artifact on this evidence.
  probed:
  - url: https://acto.com/.well-known/security.txt
    status: 404
  - url: https://acto.com/security
    status: 404
  - url: https://acto.com/responsible-disclosure
    status: 404
  - url: https://acto.com/vulnerability-disclosure
    status: 404
  - url: https://app.acto.com/.well-known/security.txt
    status: 404
  pointer_policy: >-
    NO Security and NO VulnerabilityDisclosure pointer is emitted. There is no publicly
    readable disclosure policy or security contact to point at, and pointing at the trust
    center root for a document we could not open would be a claim we cannot back.
pointer_policy: >-
  A TrustCenter pointer is emitted against security/acto-trust-center.yml, and a Compliance
  pointer against https://trust.acto.com/ — ACTO names four current, verifiable frameworks
  there, which is exactly what compliance_published reads.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/acto-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.