Caretta · Trust Center

Caretta Trust Center

Trust center

Caretta maintains a public trust center documenting ISO/IEC 27001, SOC 2, and GDPR compliance.

CompanyArtificial IntelligenceSalesSales IntelligenceReal-TimeConversation IntelligenceRevenue OperationsY CombinatorModel Context ProtocolWebhooksAgents
Trust center: https://trust.caretta.so

Certifications & Compliance

ISO/IEC 27001SOC 2GDPR

Source

Trust Center

caretta-trust-center.yml Raw ↑
generated: '2026-08-13'
method: searched
probe: true
url: https://trust.caretta.so
http_status: 200

vendor: Oneleet
vendor_evidence: >-
  trust.caretta.so is a CNAME to trust.oneleet.com (resolved 2026-08-13), the
  hosted trust-center product.

certifications:
- name: ISO/IEC 27001
  source: https://www.caretta.so
  verified: false
- name: SOC 2
  source: https://www.caretta.so
  verified: false
- name: GDPR
  source: https://www.caretta.so
  verified: false

verification_note: >-
  The certifications above are claimed on Caretta's own marketing site, which
  states "ISO 27001 certified", "SOC 2 compliant", "GDPR compliant" and
  "Enterprise-grade encryption". They could NOT be confirmed from the trust
  center itself: https://trust.caretta.so returns a 604-byte client-rendered
  React shell (an empty #root div plus a bundled JS module) with no server-side
  content, so the certification list, report availability, audit dates and
  subprocessor list are unreadable without executing JavaScript. Each entry is
  therefore recorded as claimed-by-provider, unverified-by-probe. Nothing about
  audit scope, report type (SOC 2 Type I vs Type II) or currency is asserted
  because none of it was observable.

security_claims:
- claim: Enterprise-grade encryption
  source: https://www.caretta.so
  specificity: low
  note: No cipher suites, key management or encryption-at-rest detail published.

vulnerability_disclosure:
  published: false
  security_txt: false
  bug_bounty: null
  contact: null
  note: >-
    No security.txt on caretta.so, www.caretta.so or gateway.caretta.app (all
    404). No /security, /responsible-disclosure or /vulnerability-disclosure
    page (404). No HackerOne, Bugcrowd or Intigriti program found, and no
    security@ address published. Because nothing was verified, no
    security/caretta-vulnerability-disclosure.yml artifact and no
    type: Security pointer are emitted.

data_handling_documented:
- surface: MCP
  claim: >-
    The server follows the signed-in user's existing Caretta access and cannot
    return calls the user could not otherwise see; per-client scope consent and
    per-client revocation.
  source: https://www.caretta.so/docs/caretta-mcp
- surface: Zoom
  claim: >-
    Single Zoom permission requested (meeting:write:meeting). Caretta states it
    does not request permission to read the Zoom profile, list existing
    meetings, access recordings, read transcripts, or join meetings.
  source: https://www.caretta.so/docs/zoom
- surface: webhooks
  claim: >-
    Per-endpoint signing secret shown once, rotatable, with immediate
    invalidation of the previous secret.
  source: https://www.caretta.so/docs/webhooks

evidence:
- {source: 'https://trust.caretta.so', http_status: 200, kind: trust-center, note: 'JS-rendered SPA; no readable content'}
- {source: 'https://www.caretta.so', http_status: 200, kind: marketing-claims, keywords: ['iso 27001', 'soc 2', 'gdpr', 'enterprise-grade encryption']}
- {source: 'https://www.caretta.so/.well-known/security.txt', http_status: 404, kind: negative-probe}
- {source: 'https://www.caretta.so/security', http_status: 404, kind: negative-probe}
fetched: '2026-08-13'