HockeyStack · Trust Center
Hockeystack Trust Center
Trust center
HockeyStack maintains a public trust center documenting SOC 2 Type 2 compliance.
CompanyDataMarketing AnalyticsAttributionRevenue IntelligenceB2BAccount IntelligenceMCPAI Agents
Trust center: https://security.hockeystack.com/
Certifications & Compliance
SOC 2 Type 2
Source
Trust Center
generated: '2026-08-13'
method: searched
probe: true
url: https://security.hockeystack.com/
platform: Vanta Trust Center
summary: >-
HockeyStack runs a Vanta-powered Trust Center and states its certification in
plain text in its own product documentation. The prior round left certifications[]
empty because the Vanta SPA is not machine-extractable; this round sources the
certification from HockeyStack's own security documentation instead, which is a
first-party published statement.
certifications:
- name: SOC 2 Type 2
status: certified
evidence: >-
"HockeyStack has a SOC 2 Type 2 certification." — stated verbatim in the
provider's Security and Data Handling documentation.
source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
verified: '2026-08-13'
artifacts_available: >-
Full documentation, including penetration test reports and certificates, is
offered via the Trust Center (gated request flow).
certifications_not_claimed:
- ISO 27001
- PCI DSS
- HIPAA
- FedRAMP
- note: >-
None of these appear in the provider's security documentation. Absence recorded
deliberately — the Vanta SPA may display additional framework badges that could
not be read, so this is "not claimed in readable docs", not "does not hold".
security_program:
audits: internal and external audits
vulnerability_scanning:
tool: Qualys
cadence: continuous
retention: 6 months
security_monitoring:
tools:
- Datadog
- Sentry
log_retention: 1 year
penetration_testing: reports available via Trust Center
policy_reviews: annual review of data retention requirements
data_handling:
hosting:
- AWS
- MongoDB Atlas
data_residency: EU
on_premise: false
encryption_at_rest: true
encryption_in_transit: TLS 1.2 or higher
endpoint_controls:
- full disk encryption on employee devices
- 15-minute auto screen lock
- no removable media
access_control: >-
Confidential classification; role-restricted need-to-know access; documented
data-owner approval required for non-preapproved roles; no anonymous or
unauthenticated access to systems storing customer data; customer data never
used in non-production environments.
retention: lifetime of contract
deletion_after_termination: within 30 days
early_deletion: on verified request, confirmed in writing
subprocessor_sharing: >-
Limited to service delivery (AWS, MongoDB Atlas); transfers require written
management approval and a governing contract; vendors assessed under a
Third-Party Management Policy.
ai_data_commitments:
customer_data_used_for_training: false
scope: >-
Applies to HockeyStack and to all AI sub-processors powering Sales Agents.
Inputs and outputs sent to model providers are not retained for training.
contractual: true
contract_location: DPA
note: >-
A contractual no-training commitment extended to sub-processors is materially
stronger than the policy-page assurance most vendors in this category publish.
source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
incident_response:
documented: true
customer_notification: per contractual commitments and applicable law
forensic_retention: 1 year
trust_center_probe:
url: https://security.hockeystack.com/
http_status: 200
machine_readable: false
detail: >-
Vanta trust-report app; /api/trust-report also returns the SPA shell rather than
JSON, and api.vanta.com returns 401 without credentials. Framework badges are
rendered client-side and remain unextractable, which is why the certification
above is sourced from the docs instead.
checked: '2026-08-13'
evidence:
- source: https://agents-docs.hockeystack.com/sales-agents/security-and-data.md
status: 200
provides: SOC 2 Type 2 claim, data residency, retention, AI training commitments
- source: https://security.hockeystack.com/
status: 200
provides: Trust Center existence and canonical URL
notes: >-
A `Compliance` pointer is now wired in apis.yml on the strength of the named,
first-party SOC 2 Type 2 statement. No `Security` (vulnerability disclosure)
pointer is wired — see security/ for that probe; HockeyStack publishes no
security.txt, no bug bounty and no disclosure policy.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hockeystack-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.