Flagsmith · Trust Center

Flagsmith Trust Center

Trust center

Flagsmith runs a real, dedicated trust center on its own subdomain, built on Vanta. It is discoverable only if you already know the hostname: nothing on flagsmith.com under /security, /trust or /compliance resolves, and there is no security.txt on any host to point at it. That discoverability gap is the finding here — the programme exists and the front door is unsigned.

Flagsmith maintains a public trust center documenting read, note, and how_to_verify compliance.

Feature FlagsRemote ConfigRelease ManagementA/B TestingExperimentationSegmentationDeveloper ToolsDevOpsOpen SourceSoftware-as-a-ServiceMCPAgent Ready
Trust center: https://trust.flagsmith.com

Certifications & Compliance

readnotehow_to_verify

Source

Trust Center

Raw ↑
generated: '2026-09-17'
method: probed
source: https://trust.flagsmith.com
url: https://trust.flagsmith.com
platform: Vanta
http_status: 200
checked: '2026-09-17'
evidence:
- {url: 'https://trust.flagsmith.com', status: 200, content_type: 'text/html', observed: 'title "Flagsmith Trust Center"; Vanta-hosted (assets.vanta.com, app.vanta.com document links)'}
- {url: 'https://flagsmith.com/security', status: 404}
- {url: 'https://flagsmith.com/trust', status: 404}
- {url: 'https://www.flagsmith.com/compliance', status: 404}
- {url: 'https://flagsmith.com/.well-known/security.txt', status: 404}
description: >-
  Flagsmith runs a real, dedicated trust center on its own subdomain, built on Vanta. It is
  discoverable only if you already know the hostname: nothing on flagsmith.com under /security,
  /trust or /compliance resolves, and there is no security.txt on any host to point at it. That
  discoverability gap is the finding here — the programme exists and the front door is unsigned.
certifications:
  read: false
  note: >-
    NOT RECORDED. The certification list and evidence documents are rendered client-side by the Vanta
    application and gated behind a document request (app.vanta.com/doc?s=…), so no certification name
    was readable anonymously. Nothing is asserted here — no SOC 2, ISO 27001, HIPAA, PCI or FedRAMP
    claim is being made on Flagsmith's behalf from a page this probe could not read. Flagsmith's
    pricing page markets "Features for Maximum Security" and its llms.txt names banking, financial
    services and healthcare customers, but marketing copy is not a certification and is deliberately
    not promoted to one.
  how_to_verify: Open https://trust.flagsmith.com in a browser, or request documents through the Vanta portal.
documents_gated: true
subprocessors: null

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/flagsmith-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.