HeartFlow · Trust Center

Heartflow Trust Center

Trust center

HeartFlow maintains a public trust center documenting SOC 2 Type 2, ISO/IEC 27001:2022, ISO 13485:2016, HITRUST, HIPAA, GDPR, and CCPA compliance.

CompanyHealthcareMedical ImagingArtificial IntelligenceCardiologyDiagnosticsMedical DevicesRadiologyClinical Decision SupportMachine Learning
Trust center: https://security.heartflow.com/

Certifications & Compliance

SOC 2 Type 2ISO/IEC 27001:2022ISO 13485:2016HITRUSTHIPAAGDPRCCPA

Source

Trust Center

heartflow-trust-center.yml Raw ↑
generated: '2026-08-22'
method: searched
probe: true
source: https://security.heartflow.com/
url: https://security.heartflow.com/
platform: SafeBase (Drata)
discovery: >-
  Linked from the site footer as "Heartflow Trust Center" at
  https://www.heartflow.com/heartflow-trust-center/, which 301s to
  https://security.heartflow.com/. The host sits behind a Cloudflare interactive
  challenge, so a plain curl gets 403; a browser user-agent renders the real page.
certifications:
- SOC 2 Type 2
- ISO/IEC 27001:2022
- ISO 13485:2016
- HITRUST
- HIPAA
- GDPR
- CCPA
programs:
  product_security:
  - Audit Logging
  - Multi-Factor Authentication
  - Role-Based Access Control
  data_security:
  - Access Monitoring
  - Data Backups
  - Encryption-at-rest
  application_security:
  - Application Penetration Testing
  - Secure Development Training
  - Software Bill of Materials (SBOM)
  ai_security:
  - AI Training Data and Bias
  - AI Security
  - AI Monitoring
  infrastructure:
  - Amazon Web Services
  - Business Continuity / Disaster Recovery
  - Capacity Planning & Management
  endpoint_security:
  - Anti-Malware
  - Disk Encryption
  - Mobile Device Management
  network_security:
  - Firewall
  - IDS/IPS
  - Network Penetration Testing
  corporate_security:
  - Asset Management Practices
  - Email Protection
  - Employee Handbook
gaps:
- >-
  No vulnerability disclosure or responsible-disclosure contact is published on the
  trust center, and no /.well-known/security.txt is served on any Heartflow host.
- >-
  No public subprocessor list is displayed; document access on SafeBase trust centers
  is normally NDA-gated.
evidence:
- source: https://security.heartflow.com/
  http_status: 403
  note: >-
    403 is a Cloudflare interactive challenge served to non-browser clients, not a
    dead page — the page renders for a browser user-agent. Certifications above were
    read from that rendered page.
- source: https://www.heartflow.com/about/
  http_status: 200
  note: >-
    Company About page carries the same certification badges — ISO 13485 / EN ISO
    13485, SOC 2 (AICPA), HITRUST, ISO 27001.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/heartflow-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.