Env0 · Trust Center

Env0 Trust Center

Trust center

Env0 maintains a public trust center documenting SOC 2 Type II compliance.

FinOpsInfrastructure as CodeDevOpsCloudTerraformOpenTofuPlatform EngineeringCloud GovernanceDrift Detection
Trust center: https://docs.envzero.com/guides/overview/security-overview

Certifications & Compliance

SOC 2 Type II

Source

Trust Center

Raw ↑
generated: '2026-09-06'
method: searched
probe: true
url: https://docs.envzero.com/guides/overview/security-overview
note: >-
  env zero has NO dedicated trust centre. trust.env0.com and trust.envzero.com do not resolve;
  https://www.envzero.com/security and /trust both return 404. What it publishes instead is a
  single "Security overview" page inside the documentation, which does name a real attestation
  and describe the architecture. That page is recorded here as the compliance surface.
certifications:
- name: SOC 2 Type II
  scope: entire service offering
  latest_report_issued: '2025-11'
  self_serve: false
  availability: on request from your account manager
certifications_absent:
- ISO 27001
- ISO 27017
- ISO 27018
- PCI DSS
- HIPAA
- FedRAMP
- CSA STAR
- FIPS 140
security_posture:
  hosting: AWS
  edge: API Gateway + CloudFront + WAF
  account_isolation: multiple AWS accounts; separate development account
  internal_access: AWS SSO with MFA
  encryption_in_transit: HTTPS / SSH only
  encryption_at_rest: S3, RDS and DynamoDB encryption
  sensitive_variables: encrypted and unavailable in UI, logs or API - including to env zero staff
  deployment_isolation: single-use sandboxed Docker container per deployment, destroyed afterwards
  base_image: node alpine
  hybrid_option: self-hosted agent keeps secrets and IaC runs inside the customer's cloud account
  ip_allowlisting: per-organization IPv4/IPv6 allowlist over UI logins, API keys and the Agent API
  sso: SAML 2.0, Azure AD / Microsoft Entra ID, SCIM 2.0 provisioning
published_risk_register:
  present: true
  note: env zero publishes a "Possible Exploits" section naming risks it does NOT mitigate
  risks:
  - malicious code in a linked VCS repository exfiltrating data during PR plan operations
  - malicious third-party Terraform providers/modules reaching state files and sensitive variables
  - arbitrary code execution through custom flows, unvalidated and unblocked at deployment time
evidence:
- source: https://docs.envzero.com/guides/overview/security-overview
  status: 200
  fetched: '2026-09-06'
  keywords: [soc 2, soc 2 type ii, encryption, sandboxing, sso, scim, mfa]
- source: https://www.envzero.com/security
  status: 404
  fetched: '2026-09-06'
- source: https://www.envzero.com/trust
  status: 404
  fetched: '2026-09-06'
- source: https://trust.envzero.com/
  status: dns-nxdomain
  fetched: '2026-09-06'
vulnerability_disclosure:
  present: false
  note: >-
    No security.txt on any of the eight hosts probed, no responsible-disclosure page, no bug
    bounty programme on HackerOne, Bugcrowd or Intigriti, and no security@ address published.
    The only published contact is support@env0.com. This is a real gap and the cheapest one on
    this list for env zero to close - an RFC 9116 security.txt at
    https://www.envzero.com/.well-known/security.txt naming a contact and a policy URL.
  probed:
  - {url: 'https://www.envzero.com/.well-known/security.txt', status: 404}
  - {url: 'https://envzero.com/.well-known/security.txt', status: 404}
  - {url: 'https://www.env0.com/.well-known/security.txt', status: 404}
  - {url: 'https://api.env0.com/.well-known/security.txt', status: 403}
  - {url: 'https://docs.envzero.com/.well-known/security.txt', status: 404}
  checked: '2026-09-06'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/env0-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.