Env0 · Trust Center
Env0 Trust Center
Trust center
Env0 maintains a public trust center documenting SOC 2 Type II compliance.
FinOpsInfrastructure as CodeDevOpsCloudTerraformOpenTofuPlatform EngineeringCloud GovernanceDrift Detection
Certifications & Compliance
SOC 2 Type II
Source
Trust Center
generated: '2026-09-06'
method: searched
probe: true
url: https://docs.envzero.com/guides/overview/security-overview
note: >-
env zero has NO dedicated trust centre. trust.env0.com and trust.envzero.com do not resolve;
https://www.envzero.com/security and /trust both return 404. What it publishes instead is a
single "Security overview" page inside the documentation, which does name a real attestation
and describe the architecture. That page is recorded here as the compliance surface.
certifications:
- name: SOC 2 Type II
scope: entire service offering
latest_report_issued: '2025-11'
self_serve: false
availability: on request from your account manager
certifications_absent:
- ISO 27001
- ISO 27017
- ISO 27018
- PCI DSS
- HIPAA
- FedRAMP
- CSA STAR
- FIPS 140
security_posture:
hosting: AWS
edge: API Gateway + CloudFront + WAF
account_isolation: multiple AWS accounts; separate development account
internal_access: AWS SSO with MFA
encryption_in_transit: HTTPS / SSH only
encryption_at_rest: S3, RDS and DynamoDB encryption
sensitive_variables: encrypted and unavailable in UI, logs or API - including to env zero staff
deployment_isolation: single-use sandboxed Docker container per deployment, destroyed afterwards
base_image: node alpine
hybrid_option: self-hosted agent keeps secrets and IaC runs inside the customer's cloud account
ip_allowlisting: per-organization IPv4/IPv6 allowlist over UI logins, API keys and the Agent API
sso: SAML 2.0, Azure AD / Microsoft Entra ID, SCIM 2.0 provisioning
published_risk_register:
present: true
note: env zero publishes a "Possible Exploits" section naming risks it does NOT mitigate
risks:
- malicious code in a linked VCS repository exfiltrating data during PR plan operations
- malicious third-party Terraform providers/modules reaching state files and sensitive variables
- arbitrary code execution through custom flows, unvalidated and unblocked at deployment time
evidence:
- source: https://docs.envzero.com/guides/overview/security-overview
status: 200
fetched: '2026-09-06'
keywords: [soc 2, soc 2 type ii, encryption, sandboxing, sso, scim, mfa]
- source: https://www.envzero.com/security
status: 404
fetched: '2026-09-06'
- source: https://www.envzero.com/trust
status: 404
fetched: '2026-09-06'
- source: https://trust.envzero.com/
status: dns-nxdomain
fetched: '2026-09-06'
vulnerability_disclosure:
present: false
note: >-
No security.txt on any of the eight hosts probed, no responsible-disclosure page, no bug
bounty programme on HackerOne, Bugcrowd or Intigriti, and no security@ address published.
The only published contact is support@env0.com. This is a real gap and the cheapest one on
this list for env zero to close - an RFC 9116 security.txt at
https://www.envzero.com/.well-known/security.txt naming a contact and a policy URL.
probed:
- {url: 'https://www.envzero.com/.well-known/security.txt', status: 404}
- {url: 'https://envzero.com/.well-known/security.txt', status: 404}
- {url: 'https://www.env0.com/.well-known/security.txt', status: 404}
- {url: 'https://api.env0.com/.well-known/security.txt', status: 403}
- {url: 'https://docs.envzero.com/.well-known/security.txt', status: 404}
checked: '2026-09-06'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/env0-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.