HockeyStack · Trust Center

Hockeystack Trust Center

Trust center

HockeyStack maintains a public trust center documenting SOC 2 Type 2 compliance.

CompanyDataMarketing AnalyticsAttributionRevenue IntelligenceB2BAccount IntelligenceMCPAI Agents
Trust center: https://security.hockeystack.com/

Certifications & Compliance

SOC 2 Type 2

Source

Trust Center

hockeystack-trust-center.yml Raw ↑
generated: '2026-08-13'
method: searched
probe: true
url: https://security.hockeystack.com/
platform: Vanta Trust Center
summary: >-
  HockeyStack runs a Vanta-powered Trust Center and states its certification in
  plain text in its own product documentation. The prior round left certifications[]
  empty because the Vanta SPA is not machine-extractable; this round sources the
  certification from HockeyStack's own security documentation instead, which is a
  first-party published statement.
certifications:
- name: SOC 2 Type 2
  status: certified
  evidence: >-
    "HockeyStack has a SOC 2 Type 2 certification." — stated verbatim in the
    provider's Security and Data Handling documentation.
  source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
  verified: '2026-08-13'
  artifacts_available: >-
    Full documentation, including penetration test reports and certificates, is
    offered via the Trust Center (gated request flow).
certifications_not_claimed:
- ISO 27001
- PCI DSS
- HIPAA
- FedRAMP
- note: >-
    None of these appear in the provider's security documentation. Absence recorded
    deliberately — the Vanta SPA may display additional framework badges that could
    not be read, so this is "not claimed in readable docs", not "does not hold".
security_program:
  audits: internal and external audits
  vulnerability_scanning:
    tool: Qualys
    cadence: continuous
    retention: 6 months
  security_monitoring:
    tools:
    - Datadog
    - Sentry
    log_retention: 1 year
  penetration_testing: reports available via Trust Center
  policy_reviews: annual review of data retention requirements
data_handling:
  hosting:
  - AWS
  - MongoDB Atlas
  data_residency: EU
  on_premise: false
  encryption_at_rest: true
  encryption_in_transit: TLS 1.2 or higher
  endpoint_controls:
  - full disk encryption on employee devices
  - 15-minute auto screen lock
  - no removable media
  access_control: >-
    Confidential classification; role-restricted need-to-know access; documented
    data-owner approval required for non-preapproved roles; no anonymous or
    unauthenticated access to systems storing customer data; customer data never
    used in non-production environments.
  retention: lifetime of contract
  deletion_after_termination: within 30 days
  early_deletion: on verified request, confirmed in writing
  subprocessor_sharing: >-
    Limited to service delivery (AWS, MongoDB Atlas); transfers require written
    management approval and a governing contract; vendors assessed under a
    Third-Party Management Policy.
ai_data_commitments:
  customer_data_used_for_training: false
  scope: >-
    Applies to HockeyStack and to all AI sub-processors powering Sales Agents.
    Inputs and outputs sent to model providers are not retained for training.
  contractual: true
  contract_location: DPA
  note: >-
    A contractual no-training commitment extended to sub-processors is materially
    stronger than the policy-page assurance most vendors in this category publish.
  source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
incident_response:
  documented: true
  customer_notification: per contractual commitments and applicable law
  forensic_retention: 1 year
trust_center_probe:
  url: https://security.hockeystack.com/
  http_status: 200
  machine_readable: false
  detail: >-
    Vanta trust-report app; /api/trust-report also returns the SPA shell rather than
    JSON, and api.vanta.com returns 401 without credentials. Framework badges are
    rendered client-side and remain unextractable, which is why the certification
    above is sourced from the docs instead.
  checked: '2026-08-13'
evidence:
- source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
  status: 200
  provides: SOC 2 Type 2 claim, data residency, retention, AI training commitments
- source: https://security.hockeystack.com/
  status: 200
  provides: Trust Center existence and canonical URL
notes: >-
  A `Compliance` pointer is now wired in apis.yml on the strength of the named,
  first-party SOC 2 Type 2 statement. No `Security` (vulnerability disclosure)
  pointer is wired — see security/ for that probe; HockeyStack publishes no
  security.txt, no bug bounty and no disclosure policy.