HockeyStack · Trust Center

Hockeystack Trust Center

Trust center

HockeyStack maintains a public trust center documenting SOC 2 Type 2 compliance.

CompanyDataMarketing AnalyticsAttributionRevenue IntelligenceB2BAccount IntelligenceMCPAI Agents
Trust center: https://security.hockeystack.com/

Certifications & Compliance

SOC 2 Type 2

Source

Trust Center

hockeystack-trust-center.yml Raw ↑
generated: '2026-08-13'
method: searched
probe: true
url: https://security.hockeystack.com/
platform: Vanta Trust Center
summary: >-
  HockeyStack runs a Vanta-powered Trust Center and states its certification in
  plain text in its own product documentation. The prior round left certifications[]
  empty because the Vanta SPA is not machine-extractable; this round sources the
  certification from HockeyStack's own security documentation instead, which is a
  first-party published statement.
certifications:
- name: SOC 2 Type 2
  status: certified
  evidence: >-
    "HockeyStack has a SOC 2 Type 2 certification." — stated verbatim in the
    provider's Security and Data Handling documentation.
  source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
  verified: '2026-08-13'
  artifacts_available: >-
    Full documentation, including penetration test reports and certificates, is
    offered via the Trust Center (gated request flow).
certifications_not_claimed:
- ISO 27001
- PCI DSS
- HIPAA
- FedRAMP
- note: >-
    None of these appear in the provider's security documentation. Absence recorded
    deliberately — the Vanta SPA may display additional framework badges that could
    not be read, so this is "not claimed in readable docs", not "does not hold".
security_program:
  audits: internal and external audits
  vulnerability_scanning:
    tool: Qualys
    cadence: continuous
    retention: 6 months
  security_monitoring:
    tools:
    - Datadog
    - Sentry
    log_retention: 1 year
  penetration_testing: reports available via Trust Center
  policy_reviews: annual review of data retention requirements
data_handling:
  hosting:
  - AWS
  - MongoDB Atlas
  data_residency: EU
  on_premise: false
  encryption_at_rest: true
  encryption_in_transit: TLS 1.2 or higher
  endpoint_controls:
  - full disk encryption on employee devices
  - 15-minute auto screen lock
  - no removable media
  access_control: >-
    Confidential classification; role-restricted need-to-know access; documented
    data-owner approval required for non-preapproved roles; no anonymous or
    unauthenticated access to systems storing customer data; customer data never
    used in non-production environments.
  retention: lifetime of contract
  deletion_after_termination: within 30 days
  early_deletion: on verified request, confirmed in writing
  subprocessor_sharing: >-
    Limited to service delivery (AWS, MongoDB Atlas); transfers require written
    management approval and a governing contract; vendors assessed under a
    Third-Party Management Policy.
ai_data_commitments:
  customer_data_used_for_training: false
  scope: >-
    Applies to HockeyStack and to all AI sub-processors powering Sales Agents.
    Inputs and outputs sent to model providers are not retained for training.
  contractual: true
  contract_location: DPA
  note: >-
    A contractual no-training commitment extended to sub-processors is materially
    stronger than the policy-page assurance most vendors in this category publish.
  source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
incident_response:
  documented: true
  customer_notification: per contractual commitments and applicable law
  forensic_retention: 1 year
trust_center_probe:
  url: https://security.hockeystack.com/
  http_status: 200
  machine_readable: false
  detail: >-
    Vanta trust-report app; /api/trust-report also returns the SPA shell rather than
    JSON, and api.vanta.com returns 401 without credentials. Framework badges are
    rendered client-side and remain unextractable, which is why the certification
    above is sourced from the docs instead.
  checked: '2026-08-13'
evidence:
- source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
  status: 200
  provides: SOC 2 Type 2 claim, data residency, retention, AI training commitments
- source: https://security.hockeystack.com/
  status: 200
  provides: Trust Center existence and canonical URL
notes: >-
  A `Compliance` pointer is now wired in apis.yml on the strength of the named,
  first-party SOC 2 Type 2 statement. No `Security` (vulnerability disclosure)
  pointer is wired — see security/ for that probe; HockeyStack publishes no
  security.txt, no bug bounty and no disclosure policy.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hockeystack-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.