Ceros · Trust Center

Ceros Trust Center

Trust center

Ceros maintains a public trust center covering its security and compliance posture.

Content ManagementInteractive ContentDigital ExperienceEmbedoEmbedCMS IntegrationMarketingDesignNo CodeContent DeliveryMedia and PublishingSDK
Trust center:

Certifications & Compliance

Source

Trust Center

Raw ↑
generated: '2026-08-09'
method: probed
source: https://trust.ceros.com/
provider: Ceros
trust_center:
  url: https://trust.ceros.com/
  platform: Vanta
  slug_id: 9ldxavzelo7uuybddceynn
  title: Ceros Trust Center
  tagline: >-
    "Security is built into the fabric of our products, team, infrastructure, and processes, so
    you can rest assured your data is safeguarded."
  x-evidence:
    fetched: '2026-08-09'
    url: https://trust.ceros.com/
    http_status: 200
    content_type: text/html
    bytes: 6622
certifications: []
certifications_note: >-
  NONE RECORDED, DELIBERATELY. The trust centre is a client-side Vanta SPA: the served HTML is a
  6,622-byte shell carrying only the title and description, and every /api/* path under
  trust.ceros.com and app.vanta.com returns that same shell with a 200 rather than JSON — a
  soft-404, not data. No certification, attestation or audit report name was readable, so none is
  asserted here and no `Compliance` pointer is emitted in apis.yml. A trust centre that only
  renders in a browser is not a machine-readable compliance posture.
  control_probe:
  - url: https://trust.ceros.com/api/trust-page
    http_status: 200
    bytes: 6402
    verdict: SPA catch-all — identical shell, no JSON.
  - url: https://app.vanta.com/api/trust-page/9ldxavzelo7uuybddceynn
    http_status: 200
    bytes: 29762
    verdict: SPA catch-all.
  - url: https://api.vanta.com/trust/9ldxavzelo7uuybddceynn
    http_status: 401
readable_security_claims:
  source: https://www.ceros.com/technical-faq-s/
  claims:
  - topic: TLS
    claim: >-
      "Secure TLS connections are used for all logged in sessions. We support secure connections
      for published Experience content but do not force it."
  - topic: SSO
    claim: >-
      "Ceros supports both password authentication and enterprise SSO using identity standards:
      LDAP, SAML, and OAuth."
  - topic: Access control
    claim: Account Owner and Member roles, with project-level access restrictions available.
  - topic: Hosting
    claim: >-
      Published experience content, media and assets served from S3 with CloudFront and Cloudflare
      in front as CDNs; Admin and Studio served from Ceros-managed AWS EC2 instances.
  note: >-
    This readable page names no certification either — no SOC 2, ISO 27001, PCI, HIPAA, FedRAMP,
    GDPR or CCPA claim appears on it.
vulnerability_disclosure:
  published: false
  probes:
  - url: https://www.ceros.com/.well-known/security.txt
    http_status: 404
  - url: https://developers.ceros.com/.well-known/security.txt
    http_status: 404
  - url: https://rest.ceros.com/.well-known/security.txt
    http_status: 404
  - url: https://www.ceros.com/security/
    http_status: 404
  false_positive_avoided:
    url: https://educate.ceros.com/.well-known/security.txt
    http_status: 200
    reason: >-
      Served from a Ceros CNAME but it is Intercom's policy — Contact bugcrowd.com/intercom,
      Canonical https://app.intercom.com/.well-known/security.txt. It is the help-centre vendor's
      programme, not Ceros's, so it is NOT credited to Ceros and no `Security` pointer is emitted.
  only_published_security_address:
    value: mailto:domains@ceros.com
    source: 'CAA record iodef for ceros.com'
    note: A certificate-authority incident-reporting address, not a vulnerability disclosure contact.
  remedy: >-
    Publish /.well-known/security.txt on www.ceros.com and rest.ceros.com with a Contact and
    Policy, per RFC 9116. Ceros already runs a Vanta trust centre — the disclosure channel is the
    one thing it does not expose at a fetchable URL.