Fasten Health · Trust Center

Fasten Health Trust Center

Trust center

Fasten Health maintains a public trust center documenting SOC 2 and HIPAA compliance.

HealthcareFHIRPersonal Health RecordElectronic Medical RecordHealth Data InteroperabilityTEFCAEHI ExportPatient ConsentSelf-HostedOpen-SourceHL7Healthcare Connectivity
Trust center: https://trust.fastenhealth.com/

Certifications & Compliance

SOC 2HIPAA

Source

Trust Center

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
probe_result: >-
  0-working/probe-security-programs.py returned "trust=none" for this provider. That is a false
  negative caused by rendering, not an absence: trust.fastenhealth.com answers HTTP 200 with an
  814-byte single-page-app shell that loads its content from
  laika-app-prod.s3.amazonaws.com/static/trust-center/assets/index.js, so the keyword check found
  no trust/compliance terms in the served HTML. The certifications below are taken from the
  company's own marketing site, which states them in server-rendered text.
url: https://trust.fastenhealth.com/
platform: Laika / Thoropass Trust Center
http_status: 200
certifications:
  - SOC 2
  - HIPAA
commitments:
  - {name: CARIN Alliance Code of Conduct, role: Signatory}
  - {name: CMS Interoperability Framework, role: Pledged}
agreements:
  - {name: Business Associate Agreement (BAA), availability: Customers on upgraded plans}
  - {name: Service Level Agreement (SLA), availability: Customers on upgraded plans}
claims_verbatim:
  - "SOC2 & HIPAA-compliant — Enterprise-grade security"
  - "SOC2 Certified"
  - "Protected Health Information"
  - "Carin Alliance Code of Conduct Signatory"
evidence:
  - source: https://www.fastenhealth.com/
    http_status: 200
    kind: marketing-site-server-rendered-text
    keywords: [SOC2 Certified, HIPAA-compliant, Protected Health Information, Carin Alliance Code of Conduct Signatory]
  - source: https://www.fastenhealth.com/images/logos/thoropass-soc2.png
    kind: auditor-badge
    note: Thoropass SOC 2 badge referenced from the homepage.
  - source: https://trust.fastenhealth.com/
    http_status: 200
    kind: trust-center
    note: >-
      JS-rendered Laika trust center. Reachable but machine-unreadable — the certification detail,
      report request flow and subprocessor list are not in the served HTML.
  - source: https://docs.connect.fastenhealth.com/support
    http_status: 200
    kind: docs
    keywords: [Service Level Agreements, Business Associate Agreements]
policies:
  terms_of_service: https://policy.fastenhealth.com/terms.html
  privacy_policy: https://policy.fastenhealth.com/connect/privacy_policy.html
  policy_repo: https://github.com/fastenhealth/policy
gaps:
  - No security.txt on any host (RFC 9116).
  - No published vulnerability disclosure policy or bug bounty program found.
  - >-
    The trust center is a client-rendered SPA, so no certification, subprocessor or report metadata
    is machine-readable; an agent or crawler evaluating Fasten's compliance posture sees nothing.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/fasten-health-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.