LeanTaaS · Trust Center

Leantaas Trust Center

Trust center

LeanTaaS publishes a Vanta-hosted Trust Center at https://trust.leantaas.com/ covering its healthcare security and privacy posture. The page is a JavaScript-rendered single-page application whose control, document and subprocessor data is served from a signed-query GraphQL endpoint, so the automated trust-center probe recorded no keyword hit (the served HTML shell contains only metadata). The certifications below are NOT read from that shell — they are taken from Vanta's own published LeanTaaS customer story, which is a first-party statement by LeanTaaS's Director of Security & Compliance. Individual audit reports are gated behind the Trust Center's access/NDA flow and were not retrieved.

LeanTaaS maintains a public trust center documenting HITRUST CSF, SOC 2, and HIPAA compliance.

CompanyHealthcareHealth SystemsHospital OperationsCapacity ManagementArtificial IntelligenceMachine LearningPredictive AnalyticsSchedulingSaaS
Trust center: https://trust.leantaas.com/

Certifications & Compliance

HITRUST CSFSOC 2HIPAA

Source

Trust Center

leantaas-trust-center.yml Raw ↑
generated: '2026-07-19'
method: searched
probe: false
url: https://trust.leantaas.com/
platform: Vanta
status: 200
description: >-
  LeanTaaS publishes a Vanta-hosted Trust Center at https://trust.leantaas.com/
  covering its healthcare security and privacy posture. The page is a
  JavaScript-rendered single-page application whose control, document and
  subprocessor data is served from a signed-query GraphQL endpoint, so the
  automated trust-center probe recorded no keyword hit (the served HTML shell
  contains only metadata). The certifications below are NOT read from that
  shell — they are taken from Vanta's own published LeanTaaS customer story,
  which is a first-party statement by LeanTaaS's Director of Security &
  Compliance. Individual audit reports are gated behind the Trust Center's
  access/NDA flow and were not retrieved.
certifications:
  - name: HITRUST CSF
    version: r2
    evidence: >-
      "In Vanta, LeanTaaS implemented HITRUST r2 alongside HIPAA and SOC 2."
      (vanta.com/customers/leantaas)
  - name: SOC 2
    evidence: >-
      Named alongside HITRUST r2 and HIPAA as a framework LeanTaaS implemented
      in Vanta (vanta.com/customers/leantaas). Report type (Type I vs Type II)
      is not stated in the public source and is deliberately not asserted here.
  - name: HIPAA
    evidence: >-
      Named alongside HITRUST r2 and SOC 2 (vanta.com/customers/leantaas).
      LeanTaaS processes PHI on behalf of US hospitals and health systems.
programs:
  - name: Vendor Risk Management
    evidence: Listed in the Vanta customer story solution section.
  - name: Questionnaire Automation
    evidence: Listed in the Vanta customer story solution section.
  - name: US state privacy laws
    evidence: Listed in the Vanta customer story solution section.
contacts:
  - role: Director of Security & Compliance
    name: Bill Murphy
    source: https://www.vanta.com/customers/leantaas
report_access: >-
  Audit reports and security documentation are requested through the Trust
  Center access flow at https://trust.leantaas.com/ (Vanta gated documents).
  No report was downloadable anonymously at probe time.
docs:
  - https://trust.leantaas.com/
  - https://trust.leantaas.com/resources
evidence:
  - source: https://trust.leantaas.com/
    status: 200
    observed: >-
      Vanta trust-report SPA (slug 1tufob75d3j26ruz2igk1); certification names
      not present in server-rendered HTML.
  - source: https://www.vanta.com/customers/leantaas
    status: 200
    keywords: [hitrust r2, hipaa, soc 2]
notes: >-
  No /.well-known/security.txt on leantaas.com (404) and no public bug bounty
  or vulnerability-disclosure page was found, so no VulnerabilityDisclosure
  artifact is emitted this round.