Freshpaint · Trust Center

Freshpaint Trust Center

Trust center

Freshpaint runs a real, self-service trust center at trust.freshpaint.io with named certifications, downloadable audit artifacts, and an enumerated control set. This is the strongest single piece of Freshpaint's public posture and the reason a Compliance pointer is wired — it is a published compliance program, not an inferred one.

Freshpaint maintains a public trust center documenting SOC 2 Type 2 and HIPAA compliance.

Customer Data PlatformEvent TrackingHealthcareHIPAAPrivacyAnalytics
Trust center: https://trust.freshpaint.io/

Certifications & Compliance

SOC 2 Type 2HIPAA

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://trust.freshpaint.io/
url: https://trust.freshpaint.io/
http_status: 200
fetched: '2026-08-13'
description: >-
  Freshpaint runs a real, self-service trust center at trust.freshpaint.io with
  named certifications, downloadable audit artifacts, and an enumerated control
  set. This is the strongest single piece of Freshpaint's public posture and
  the reason a Compliance pointer is wired — it is a published compliance
  program, not an inferred one.
certifications:
- SOC 2 Type 2
- HIPAA
in_progress:
- name: HITRUST r2
  note: >-
    The trust center states Freshpaint "is actively working toward HITRUST r2
    certification". Recorded as in-progress, not as a held certification.
documents:
- name: SOC 2 Report
- name: Pentest Report
- name: Security Prospectus
controls:
- Encryption at rest
- Encryption in transit
- Access log management
- Automated account management
- Virtual private cloud
- Traffic filtering
- Web application firewall
- Software development lifecycle
- Code analysis
- Endpoint detection and response
- Mobile device management
- Incident response
- Penetration testing
- Employee training
programs:
- name: Vulnerability Management Program
  description: >-
    Freshpaint maintains a vulnerability management program to identify,
    assess, remediate, verify, and report technical vulnerabilities.
  note: >-
    This is an INTERNAL vulnerability management program. It is not a public
    vulnerability disclosure program — see gaps below.
- name: Security Awareness Training Program
- name: Endpoint Security and Device Management Program
subprocessors:
  section_present: true
  list_captured: false
  note: A Subprocessors section is referenced on the trust center but no list was returned in the fetched content.
gaps:
- >-
  No vulnerability disclosure or bug bounty program is named anywhere on the
  trust center, and no security contact email is published. /.well-known/
  security.txt returns 404 on freshpaint.io, www.freshpaint.io and
  trust.freshpaint.io, and /security, /responsible-disclosure,
  /security/responsible-disclosure and /vulnerability-disclosure all return 404
  on www.freshpaint.io. A researcher who finds a bug in a HIPAA-scoped platform
  has no published route to report it. No Security or VulnerabilityDisclosure
  pointer is wired, because there is nothing to point at.
evidence:
- source: https://trust.freshpaint.io/
  http_status: 200
  fetched: '2026-08-13'
  keywords: [soc 2 type 2, hipaa, hitrust r2, trust center, pentest report, vulnerability management]
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/freshpaint-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.