Fasten Health · Trust Center
Fasten Health Trust Center
Trust center
Fasten Health maintains a public trust center documenting SOC 2 and HIPAA compliance.
HealthcareFHIRPersonal Health RecordElectronic Medical RecordHealth Data InteroperabilityTEFCAEHI ExportPatient ConsentSelf-HostedOpen-SourceHL7Healthcare Connectivity
Trust center: https://trust.fastenhealth.com/
Certifications & Compliance
SOC 2HIPAA
Source
Trust Center
generated: '2026-08-14'
method: searched
probe: true
probe_result: >-
0-working/probe-security-programs.py returned "trust=none" for this provider. That is a false
negative caused by rendering, not an absence: trust.fastenhealth.com answers HTTP 200 with an
814-byte single-page-app shell that loads its content from
laika-app-prod.s3.amazonaws.com/static/trust-center/assets/index.js, so the keyword check found
no trust/compliance terms in the served HTML. The certifications below are taken from the
company's own marketing site, which states them in server-rendered text.
url: https://trust.fastenhealth.com/
platform: Laika / Thoropass Trust Center
http_status: 200
certifications:
- SOC 2
- HIPAA
commitments:
- {name: CARIN Alliance Code of Conduct, role: Signatory}
- {name: CMS Interoperability Framework, role: Pledged}
agreements:
- {name: Business Associate Agreement (BAA), availability: Customers on upgraded plans}
- {name: Service Level Agreement (SLA), availability: Customers on upgraded plans}
claims_verbatim:
- "SOC2 & HIPAA-compliant — Enterprise-grade security"
- "SOC2 Certified"
- "Protected Health Information"
- "Carin Alliance Code of Conduct Signatory"
evidence:
- source: https://www.fastenhealth.com/
http_status: 200
kind: marketing-site-server-rendered-text
keywords: [SOC2 Certified, HIPAA-compliant, Protected Health Information, Carin Alliance Code of Conduct Signatory]
- source: https://www.fastenhealth.com/images/logos/thoropass-soc2.png
kind: auditor-badge
note: Thoropass SOC 2 badge referenced from the homepage.
- source: https://trust.fastenhealth.com/
http_status: 200
kind: trust-center
note: >-
JS-rendered Laika trust center. Reachable but machine-unreadable — the certification detail,
report request flow and subprocessor list are not in the served HTML.
- source: https://docs.connect.fastenhealth.com/support
http_status: 200
kind: docs
keywords: [Service Level Agreements, Business Associate Agreements]
policies:
terms_of_service: https://policy.fastenhealth.com/terms.html
privacy_policy: https://policy.fastenhealth.com/connect/privacy_policy.html
policy_repo: https://github.com/fastenhealth/policy
gaps:
- No security.txt on any host (RFC 9116).
- No published vulnerability disclosure policy or bug bounty program found.
- >-
The trust center is a client-rendered SPA, so no certification, subprocessor or report metadata
is machine-readable; an agent or crawler evaluating Fasten's compliance posture sees nothing.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/fasten-health-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.