Authologic Trust Center
Authologic does not run a conventional SaaS trust portal (no trust.authologic.com, no SOC 2 report room, no security.txt). What it publishes instead is an eIDAS trust-service repository: the policy, terms and status-list documents an EU Trust Service Provider is obliged to make public. That is a stronger and more specific disclosure than most vendor trust pages, and it is where the certification claims live.
Authologic maintains a public trust center documenting ISO/IEC 27001, ISO/IEC 22301, and eIDAS non-qualified trust service provider (EAA issuance) compliance.
Certifications & Compliance
Source
Trust Center
generated: '2026-09-14'
method: searched
source: https://authologic.com/ (Trust Service document column),
https://authologic.com/docs/trust-service/Trust-Service-Policy-for-Non-Qualified-EAA-Issuance.pdf,
https://authologic.com/docs/trust-service/TSP-TCs.pdf,
https://authologic.com/docs/trust-service/Authologic-Status-List.pdf,
https://authologic.com/docs/trust-service/Authologic-EAAP-Example.pdf,
https://authologic.com/docs/trust-service/Privacy-Policy.pdf
specification: API Commons Trust Center
specificationVersion: '0.1'
provider: Authologic
providerId: authologic
description: >-
Authologic does not run a conventional SaaS trust portal (no trust.authologic.com, no SOC 2 report
room, no security.txt). What it publishes instead is an eIDAS trust-service repository: the policy,
terms and status-list documents an EU Trust Service Provider is obliged to make public. That is a
stronger and more specific disclosure than most vendor trust pages, and it is where the certification
claims live.
trust_center:
present: true
type: eIDAS trust service repository
url: https://authologic.com/
location: >-
Linked from the marketing site footer as the "Trust Service" column; documents are served from
https://authologic.com/docs/trust-service/. All five were fetched with HTTP 200 on 2026-09-14.
availability: >-
The Trust Service Policy commits to a public repository on the official website accessible 24/7,
subject to reasonable maintenance windows.
legal_entity: Authologic Sp. z o.o.
contact: contact@authologic.com
documents:
- name: Trust Service Policy for the Non-Qualified Electronic Attestation of Attributes Issuance Service
url: https://authologic.com/docs/trust-service/Trust-Service-Policy-for-Non-Qualified-EAA-Issuance.pdf
version: '1.0'
effective: '2026-07-13'
status: 200
content_type: application/pdf
bytes: 427849
note: >-
The governing policy document. Names the eIDAS Regulation, the 2024-2025 Commission Implementing
Regulations (2024/2690, 2024/2977, 2024/2979, 2024/2982, 2025/848, 2025/2160), ETSI EN 319 401,
ETSI TS 119 471, TS 119 472-1 and TS 119 412-6, GDPR, and the ISO/IEC 27001 + 22301 certification
claim.
- name: Terms and Conditions for the Provision of the Service of Issuing Electronic Attestations of Attributes
url: https://authologic.com/docs/trust-service/TSP-TCs.pdf
status: 200
content_type: application/pdf
bytes: 662217
- name: Authologic Status List
url: https://authologic.com/docs/trust-service/Authologic-Status-List.pdf
status: 200
content_type: application/pdf
bytes: 58431
note: >-
The attestation revocation/status list. As of 2026-09-14 its entire content is "Status list is
empty. No attestation has been issued yet." — the EAA issuance service is published and operable
but has not yet issued an attestation.
- name: Authologic EAAP Example
url: https://authologic.com/docs/trust-service/Authologic-EAAP-Example.pdf
status: 200
content_type: application/pdf
bytes: 109759
- name: Trust Service Privacy Policy
url: https://authologic.com/docs/trust-service/Privacy-Policy.pdf
status: 200
content_type: application/pdf
certifications:
- name: ISO/IEC 27001
scope: Information security management system covering the trust service
status: claimed-certified
evidence: >-
"TSP has implemented an information security management system certified against ISO/IEC 27001 and
ISO/IEC 22301."
source: https://authologic.com/docs/trust-service/Trust-Service-Policy-for-Non-Qualified-EAA-Issuance.pdf
certificate_published: false
- name: ISO/IEC 22301
scope: Business continuity management covering the trust service
status: claimed-certified
evidence: Same statement as ISO/IEC 27001 above.
source: https://authologic.com/docs/trust-service/Trust-Service-Policy-for-Non-Qualified-EAA-Issuance.pdf
certificate_published: false
- name: eIDAS non-qualified trust service provider (EAA issuance)
scope: Electronic Attestation of Attributes issuance under Regulation (EU) No 910/2014 as amended
status: self-declared, policy published
source: https://authologic.com/docs/trust-service/Trust-Service-Policy-for-Non-Qualified-EAA-Issuance.pdf
referenced_standards:
- ETSI EN 319 401 v3.1.1
- ETSI TS 119 471 v1.1.1
- ETSI TS 119 472-1
- ETSI TS 119 412-6
- EN 50600
- ISO/IEC 18013-5 and 18013-7
- OpenID for Verifiable Credential Issuance
gaps:
- No SOC 2 report, no HIPAA/PCI attestation, and no certificate PDFs — only the claim in prose.
- >-
No /.well-known/security.txt on any Authologic host, no published vulnerability-disclosure policy and
no bug-bounty program (HackerOne, Bugcrowd and Intigriti all return nothing for this domain).
- No public status page and no published SLA.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/security/authologic-trust-center"
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.