anchor-x402 · Trust Center

Anchor X402 Trust Center

Trust center

anchor-x402 maintains a public trust center covering its security and compliance posture.

Companyx402AgentsPaymentsBlockchainMCPWeb3pay-per-callAgentic PaymentsStablecoinsComplianceAttestationA2A
Trust center: https://anchor-x402.com/trust/

Certifications & Compliance

Source

Trust Center

Raw ↑
generated: '2026-09-11'
method: searched
probe: true
source: https://anchor-x402.com/trust/
url: https://anchor-x402.com/trust/
http_status: 200
trust_center_present: true
certifications: []
certification_count: 0
certifications_explicitly_disclaimed:
- SOC 2
- ISO 27001
- PCI DSS
- HIPAA
- GDPR DPA
x-correction: >-
  0-working/probe-security-programs.py wrote this file on 2026-09-11 with certifications [SOC 2, ISO 27001,
  HIPAA, GDPR] from a bare keyword match on the trust-portal page. Every one of those matches is a NEGATION.
  The page's own words are "We do not hold SOC 2, ISO 27001, or PCI certifications" and "No SOC 2 / ISO
  27001 / PCI / HIPAA certification. Roadmap items, not blockers for the commodity tier." The list was
  corrected to empty by hand and no Compliance pointer was emitted. A scorer reading the generated file
  would have credited this provider with four certifications it goes out of its way to say it does not hold.
posture: >-
  The trust portal is unusually substantial for an uncertified provider and is built around an explicit
  argument: publish the reasoning instead of the certificates. It carries six documents totalling roughly
  22,000 words - a STRIDE-lite per-service threat model, a pre-filled SIG-Lite vendor security
  questionnaire, a code-level self-audit guide mapping 15 compliance concerns to file and line ranges in the
  MIT-licensed source, a regulated-deployment guide covering trust boundaries and AWS compliance
  inheritance, an on-chain verifiability primer with live mainnet hashes, and observability docs.
documents:
- name: Threat model
  url: https://anchor-x402.com/trust/threat-model.html
  status: 200
  form: STRIDE-lite per-service enumeration with mitigations and residual risk
  approx_words: 5400
- name: Security questionnaire
  url: https://anchor-x402.com/trust/security-questionnaire.html
  status: 200
  form: Pre-filled SIG-Lite-style vendor security response across 11 sections
  approx_words: 4300
- name: Self-audit guide
  url: https://anchor-x402.com/trust/self-audit.html
  form: 15 compliance concerns mapped to specific files and line ranges in the codebase
  approx_words: 4600
- name: Regulated deployment guide
  url: https://anchor-x402.com/trust/regulated-deployment.html
  form: Trust boundaries, AWS compliance inheritance, customer-side responsibilities
  approx_words: 5300
- name: On-chain verifiability
  url: https://anchor-x402.com/trust/on-chain-verifiability
  status: 200
  form: The cryptographic primitive and how a customer verifies anchors without contacting the service
  approx_words: 1800
- name: Observability
  url: https://anchor-x402.com/trust/observability.html
  form: CloudWatch dashboard and status-page setup, what to expose, what consumers should monitor
  approx_words: 1000
compensating_controls_claimed:
- MIT-licensed open-source codebase, auditable line by line
- On-chain verifiability - anchors are readable from Base and Solana mainnet independently of the service
- Deliberately stateless architecture with no per-customer PII at rest
- Compliance inheritance from AWS infrastructure (Lambda, Secrets Manager, CloudWatch)
disclosed_gaps:
- No SOC 2, ISO 27001, PCI-DSS, HIPAA certification - stated as roadmap items, not blockers for the commodity tier
- No cyber liability or tech E&O insurance - to be obtained when first contractually required
- No formal written incident-response runbook - a disclosure email exists, the runbook is on the roadmap
- No DPA template at the commodity tier
scope_limitation_published: >-
  The threat model covers thirteen trust-relevant endpoints. The five LLM content endpoints (roast, oracle,
  tldr, aura, grade) are documented as explicitly out of scope - freeform text in, generated content out,
  no wallet-risk verdict and no compliance evidence.
institutional_tier:
  status: available on request
  price: USD 499-5,000+/mo
  inclusions:
  - per-tenant authentication
  - signed MSA/DPA/SLA
  - WORM evidence vault on S3 Object Lock
  - GDPR Article 17 erasure reconciled with AML retention
  contact: hello@anchor-x402.com
status_page: https://anchor-x402.betteruptime.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/anchor-x402-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.