Carefull Corporation · Trust Center

Carefull Corporation Trust Center

Trust center

Carefull Corporation maintains a public trust center documenting SOC 2 compliance.

CompanyFintechFinancial SafetyFraud DetectionIdentity Theft ProtectionElder CareFinancial CaregivingAccount MonitoringConsumer Finance
Trust center: https://getcarefull.com/security-practices

Certifications & Compliance

SOC 2

Source

Trust Center

carefull-corporation-trust-center.yml Raw ↑
generated: '2026-07-18'
method: searched
source: https://getcarefull.com/security-practices
url: https://getcarefull.com/security-practices
certifications:
- SOC 2
evidence:
- source: https://getcarefull.com/security-practices
  detail: 'Carefull states it is the first financial caregiving service to receive
    its SOC 2 certification; independently audited with an unqualified (clean) opinion,
    zero exceptions. SOC 2 report available on request via care@getcarefull.com.'
security_posture:
  encryption_at_rest: AES-256 (per-object keys) for the Carefull Vault
  encryption_in_transit: TLS with HSTS
  tokenization: proprietary aliasing system removes sensitive data from core systems
  data_separation: personal and financial transaction data held in separate databases
  hosting: AWS across at least three separate geographic locations
  credentials: banking credentials never stored; view-only aggregation via Plaid, MX, and Finicity
  ssn_protection: partners with Iris and Equifax; SSN never stored with account data
contact: care@getcarefull.com
notes: No public bug bounty, responsible-disclosure policy, /.well-known/security.txt, or security@ address was found (all /.well-known/* paths return the SPA HTML shell, i.e. soft-404).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/carefull-corporation-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.