CarsXE · Trust Center
Carsxe Trust Center
Trust center
CarsXE maintains a public trust center documenting SOC 2 Type II and ISO 27001 compliance.
AutomotiveVehiclesVINVehicle DataLicense PlateOCRAutomobilesRecallsMarket ValueVehicle HistoryModel Context ProtocolAgents
Trust center: https://carsxe.com/trust
Certifications & Compliance
SOC 2 Type IIISO 27001
Source
Trust Center
generated: '2026-09-05'
method: searched
probe: true
source: https://carsxe.com/trust
url: https://carsxe.com/trust
http_status: 200
certifications:
- name: SOC 2 Type II
status: certified
auditor: GreenHat Assurance
opinion: clean
cadence: annual
criteria: [Security, Availability, Confidentiality]
report_access: available under NDA on request via the form on the trust page
- name: ISO 27001
status: in-progress
note: >-
The page labels ISO 27001 "In Progress" — CarsXE states it is working toward certification, not
that it holds one. Recorded as in-progress so this is never read as a held certification.
controls:
total: 75
domains:
infrastructure_security: 9
organizational_security: 32
product_security: 13
internal_security_procedures: 12
data_and_privacy: 9
encryption:
at_rest: AES-256
in_transit: TLS 1.3
key_management: cloud-native KMS with automatic rotation policies
backups: encrypted
other: [certificate transparency monitoring, forward secrecy]
availability:
uptime_sla: 99.9%
service_credits: true
status_page: https://carsxe.com/status
infrastructure:
provider: Google Cloud Platform
regions: multi-region, data primarily hosted in the United States
controls: [web application firewall, DDoS protection, network segmentation, RBAC, MFA, least privilege]
vulnerability_management:
stated: >-
"Regular penetration testing, automated vulnerability scanning, and a responsible disclosure
program."
disclosure_page: null
security_contact: null
note: >-
The trust page asserts a responsible disclosure program in prose, but CarsXE publishes no
disclosure page, no security.txt (404 on carsxe.com, api.carsxe.com and mcp.carsxe.com), no
security@ address and no bug-bounty listing. probe-security-programs.py returned vdp=none on
2026-09-05, so no VulnerabilityDisclosure or Security pointer is emitted — the program is
claimed but not reachable, which is a real and reportable gap.
resources:
- {title: "CarsXE - Letter of Engagement from Mycroft", format: PDF, access: request}
- {title: "CarsXE SOC 2 Type 2 Report - March 2026", format: PDF, access: request (NDA)}
evidence:
- source: https://carsxe.com/trust
keywords: [soc 2 type ii, iso 27001, trust center, aes-256, tls 1.3, 99.9% uptime sla, responsible disclosure]
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/carsxe-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.