Epsilon3 · Trust Center

Epsilon3 Trust Center

Trust center

Epsilon3 maintains a public trust center documenting SOC 2 Type II, FedRAMP High Authorization, NIST SP 800-171, DFARS 252.204-7012, CMMC, ITAR, and EAR compliance.

CompanyAerospaceSpaceDefenseManufacturingProceduresWorkflowsInventoryTelemetryTest ManagementProject ManagementMCP
Trust center: https://trust.epsilon3.io/

Certifications & Compliance

SOC 2 Type IIFedRAMP High AuthorizationNIST SP 800-171DFARS 252.204-7012CMMCITAREAR

Source

Trust Center

epsilon3-trust-center.yml Raw ↑
generated: '2026-08-12'
method: searched
probe: true
probe_note: >-
  0-working/probe-security-programs.py returned trust=none because trust.epsilon3.io is a
  Vanta-hosted single-page app - the served HTML is 7,201 bytes containing only the title
  "Epsilon3 Trust Center", with every certification rendered client-side, so the probe's
  keyword threshold could not be met. The trust center is nonetheless real and reachable
  (HTTP 200), and Epsilon3's own security page names the certifications server-side. This
  file is written from that server-side evidence, not from the JS-rendered page.
url: https://trust.epsilon3.io/
http_status: 200
provider: Vanta
content_rendering: client-side (JS); no certification text in the served HTML
source_page: https://www.epsilon3.io/security
certifications:
- SOC 2 Type II
- FedRAMP High Authorization
- NIST SP 800-171
- DFARS 252.204-7012
- CMMC
- ITAR
- EAR
controls:
- {control: encryption-in-transit, detail: TLS 1.3}
- {control: encryption-at-rest, detail: AES-256}
- {control: access-control, detail: Role-Based Access Control to restrict access to
    classified or sensitive data}
- {control: identity, detail: Single Sign-On (SSO) and Multi-Factor Authentication (MFA)}
- {control: auditability, detail: one-click audit bundle export for internal reviews and
    regulatory audits}
- {control: continuity, detail: dual-region clouds plus an offline mode}
hosting: AWS GovCloud
deployment_models:
- compliant cloud (AWS GovCloud, FedRAMP High)
- on-premises
- hybrid and international
- classified environments
ai_data_posture: >-
  AI features are opt-in and under user control; Epsilon3 states its contracts prevent
  customer data being used to train models.
evidence:
- {source: 'https://www.epsilon3.io/security', http_status: 200, keywords: [SOC 2 Type II,
      FedRAMP High, NIST 800-171, DFARS 252.204-7012, CMMC, ITAR, EAR, AWS GovCloud,
      TLS 1.3, AES-256, Vanta trust report]}
- {source: 'https://trust.epsilon3.io/', http_status: 200, keywords: [Epsilon3 Trust Center],
  note: title only - remainder is JS-rendered}
gaps:
- No public vulnerability disclosure or responsible disclosure policy. The strings
  "disclosure", "bug bounty", "security@" and "penetration" do not appear on
  www.epsilon3.io/security, no /.well-known/security.txt is served on any Epsilon3 host,
  and no HackerOne/Bugcrowd/Intigriti program was found. No Security pointer is claimed in
  apis.yml as a result.
- Certification reports themselves are behind the Vanta trust center, which requires
  interaction to reach; nothing is downloadable anonymously.
- ISO 27001 is not among the named certifications.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/epsilon3-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.