Alleva · Trust Center

Alleva Trust Center

Trust center

Alleva maintains a public trust center documenting SOC 2 Type II, HIPAA, and ONC Certification (ONC Health IT Certification Program) compliance.

behavioral-healthelectronic-health-recordsemrehrsubstance-use-disordermental-healthhealthcaretreatment-centersclinical-documentationrevenue-cycle-managementpatient-intakehealthcare-compliance
Trust center: https://trust.helloalleva.com/

Certifications & Compliance

SOC 2 Type IIHIPAAONC Certification (ONC Health IT Certification Program)

Source

Trust Center

Raw ↑
generated: '2026-08-06'
method: searched
probe: true
url: https://trust.helloalleva.com/
provider: Vanta
title: Alleva Trust Center
certifications:
- SOC 2 Type II
- HIPAA
- ONC Certification (ONC Health IT Certification Program)
certification_source: >-
  Alleva press release, 26 November 2025 — "Alleva Achieves ONC Certification, SOC 2, and HIPAA
  Compliance for Its Behavioral Health Platform". The certifications are asserted by Alleva in that
  release and the release directs readers to the trust center below. The trust center page itself is a
  JS-rendered Vanta SPA whose report data (/api/trust-report) is not readable anonymously, so the
  certification list could not be re-verified from the trust center HTML.
evidence:
- source: https://trust.helloalleva.com/
  http_status: 200
  keywords: [Alleva Trust Center, Vanta]
  note: >-
    verified real, not a wildcard — the page title is "Alleva Trust Center" and it loads the Vanta
    trust-report bundle from assets.vanta.com; a control probe of zzznotreal.helloalleva.com failed DNS
- source: https://www.prnewswire.com/news-releases/alleva-achieves-onc-certification-soc-2-and-hipaa-compliance-for-its-behavioral-health-platform-302626242.html
  kind: press-release
  date: '2025-11-26'
limitations:
  trust_report_readable: false
  trust_report_note: >-
    https://trust.helloalleva.com/api/trust-report returns the SPA HTML shell, and
    https://api.vanta.com/v1/public/trust-page/helloalleva returns 401 — no machine-readable attestation
    inventory, audit date, or report-request flow could be captured.
x-evidence:
  fetched: '2026-08-06'