HockeyStack · Trust Center
Hockeystack Trust Center
Trust center
HockeyStack maintains a public trust center documenting SOC 2 Type 2 compliance.
CompanyDataMarketing AnalyticsAttributionRevenue IntelligenceB2BAccount IntelligenceMCPAI Agents
Trust center: https://security.hockeystack.com/
Certifications & Compliance
SOC 2 Type 2
Source
Trust Center
generated: '2026-08-13'
method: searched
probe: true
url: https://security.hockeystack.com/
platform: Vanta Trust Center
summary: >-
HockeyStack runs a Vanta-powered Trust Center and states its certification in
plain text in its own product documentation. The prior round left certifications[]
empty because the Vanta SPA is not machine-extractable; this round sources the
certification from HockeyStack's own security documentation instead, which is a
first-party published statement.
certifications:
- name: SOC 2 Type 2
status: certified
evidence: >-
"HockeyStack has a SOC 2 Type 2 certification." — stated verbatim in the
provider's Security and Data Handling documentation.
source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
verified: '2026-08-13'
artifacts_available: >-
Full documentation, including penetration test reports and certificates, is
offered via the Trust Center (gated request flow).
certifications_not_claimed:
- ISO 27001
- PCI DSS
- HIPAA
- FedRAMP
- note: >-
None of these appear in the provider's security documentation. Absence recorded
deliberately — the Vanta SPA may display additional framework badges that could
not be read, so this is "not claimed in readable docs", not "does not hold".
security_program:
audits: internal and external audits
vulnerability_scanning:
tool: Qualys
cadence: continuous
retention: 6 months
security_monitoring:
tools:
- Datadog
- Sentry
log_retention: 1 year
penetration_testing: reports available via Trust Center
policy_reviews: annual review of data retention requirements
data_handling:
hosting:
- AWS
- MongoDB Atlas
data_residency: EU
on_premise: false
encryption_at_rest: true
encryption_in_transit: TLS 1.2 or higher
endpoint_controls:
- full disk encryption on employee devices
- 15-minute auto screen lock
- no removable media
access_control: >-
Confidential classification; role-restricted need-to-know access; documented
data-owner approval required for non-preapproved roles; no anonymous or
unauthenticated access to systems storing customer data; customer data never
used in non-production environments.
retention: lifetime of contract
deletion_after_termination: within 30 days
early_deletion: on verified request, confirmed in writing
subprocessor_sharing: >-
Limited to service delivery (AWS, MongoDB Atlas); transfers require written
management approval and a governing contract; vendors assessed under a
Third-Party Management Policy.
ai_data_commitments:
customer_data_used_for_training: false
scope: >-
Applies to HockeyStack and to all AI sub-processors powering Sales Agents.
Inputs and outputs sent to model providers are not retained for training.
contractual: true
contract_location: DPA
note: >-
A contractual no-training commitment extended to sub-processors is materially
stronger than the policy-page assurance most vendors in this category publish.
source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
incident_response:
documented: true
customer_notification: per contractual commitments and applicable law
forensic_retention: 1 year
trust_center_probe:
url: https://security.hockeystack.com/
http_status: 200
machine_readable: false
detail: >-
Vanta trust-report app; /api/trust-report also returns the SPA shell rather than
JSON, and api.vanta.com returns 401 without credentials. Framework badges are
rendered client-side and remain unextractable, which is why the certification
above is sourced from the docs instead.
checked: '2026-08-13'
evidence:
- source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
status: 200
provides: SOC 2 Type 2 claim, data residency, retention, AI training commitments
- source: https://security.hockeystack.com/
status: 200
provides: Trust Center existence and canonical URL
notes: >-
A `Compliance` pointer is now wired in apis.yml on the strength of the named,
first-party SOC 2 Type 2 statement. No `Security` (vulnerability disclosure)
pointer is wired — see security/ for that probe; HockeyStack publishes no
security.txt, no bug bounty and no disclosure policy.