Ceros · Trust Center
Ceros Trust Center
Trust center
Ceros maintains a public trust center covering its security and compliance posture.
Content ManagementInteractive ContentDigital ExperienceEmbedoEmbedCMS IntegrationMarketingDesignNo CodeContent DeliveryMedia and PublishingSDK
Certifications & Compliance
Source
Trust Center
generated: '2026-08-09'
method: probed
source: https://trust.ceros.com/
provider: Ceros
trust_center:
url: https://trust.ceros.com/
platform: Vanta
slug_id: 9ldxavzelo7uuybddceynn
title: Ceros Trust Center
tagline: >-
"Security is built into the fabric of our products, team, infrastructure, and processes, so
you can rest assured your data is safeguarded."
x-evidence:
fetched: '2026-08-09'
url: https://trust.ceros.com/
http_status: 200
content_type: text/html
bytes: 6622
certifications: []
certifications_note: >-
NONE RECORDED, DELIBERATELY. The trust centre is a client-side Vanta SPA: the served HTML is a
6,622-byte shell carrying only the title and description, and every /api/* path under
trust.ceros.com and app.vanta.com returns that same shell with a 200 rather than JSON — a
soft-404, not data. No certification, attestation or audit report name was readable, so none is
asserted here and no `Compliance` pointer is emitted in apis.yml. A trust centre that only
renders in a browser is not a machine-readable compliance posture.
control_probe:
- url: https://trust.ceros.com/api/trust-page
http_status: 200
bytes: 6402
verdict: SPA catch-all — identical shell, no JSON.
- url: https://app.vanta.com/api/trust-page/9ldxavzelo7uuybddceynn
http_status: 200
bytes: 29762
verdict: SPA catch-all.
- url: https://api.vanta.com/trust/9ldxavzelo7uuybddceynn
http_status: 401
readable_security_claims:
source: https://www.ceros.com/technical-faq-s/
claims:
- topic: TLS
claim: >-
"Secure TLS connections are used for all logged in sessions. We support secure connections
for published Experience content but do not force it."
- topic: SSO
claim: >-
"Ceros supports both password authentication and enterprise SSO using identity standards:
LDAP, SAML, and OAuth."
- topic: Access control
claim: Account Owner and Member roles, with project-level access restrictions available.
- topic: Hosting
claim: >-
Published experience content, media and assets served from S3 with CloudFront and Cloudflare
in front as CDNs; Admin and Studio served from Ceros-managed AWS EC2 instances.
note: >-
This readable page names no certification either — no SOC 2, ISO 27001, PCI, HIPAA, FedRAMP,
GDPR or CCPA claim appears on it.
vulnerability_disclosure:
published: false
probes:
- url: https://www.ceros.com/.well-known/security.txt
http_status: 404
- url: https://developers.ceros.com/.well-known/security.txt
http_status: 404
- url: https://rest.ceros.com/.well-known/security.txt
http_status: 404
- url: https://www.ceros.com/security/
http_status: 404
false_positive_avoided:
url: https://educate.ceros.com/.well-known/security.txt
http_status: 200
reason: >-
Served from a Ceros CNAME but it is Intercom's policy — Contact bugcrowd.com/intercom,
Canonical https://app.intercom.com/.well-known/security.txt. It is the help-centre vendor's
programme, not Ceros's, so it is NOT credited to Ceros and no `Security` pointer is emitted.
only_published_security_address:
value: mailto:domains@ceros.com
source: 'CAA record iodef for ceros.com'
note: A certificate-authority incident-reporting address, not a vulnerability disclosure contact.
remedy: >-
Publish /.well-known/security.txt on www.ceros.com and rest.ceros.com with a Contact and
Policy, per RFC 9116. Ceros already runs a Vanta trust centre — the disclosure channel is the
one thing it does not expose at a fetchable URL.