Mantra Health · Trust Center

Mantra Health Trust Center

Trust center

Mantra Health maintains a public trust center documenting HIPAA, SOC 2, SOC 1, and TX-RAMP compliance.

CompanyHealthcareMental HealthTelehealthHigher EducationDigital HealthPatient EngagementHIPAAGraphQL
Trust center:

Certifications & Compliance

HIPAASOC 2SOC 1TX-RAMP

Source

Trust Center

mantra-health-trust-center.yml Raw ↑
generated: '2026-08-25'
method: searched
source: https://mantrahealth.com/security-and-privacy/
name: Mantra Health security and compliance
note: >-
  Mantra Health does not run a trust center in the modern sense — there is no trust.mantrahealth.com,
  no Vanta/Drata/SafeBase portal, and no document request flow. What it publishes is a single
  marketing-site page, "Security and Privacy at Mantra Health", naming three compliance frameworks in
  prose. That page is the whole of the public posture, and it is recorded here verbatim. The
  automated probe (probe-security-programs.py) missed it because the page sits at
  /security-and-privacy/ rather than any of the conventional /trust, /security, /compliance paths;
  /security does 302 to it, which is how it was found.
trust_center:
  present: partial
  url: https://mantrahealth.com/security-and-privacy/
  http_status: 200
  type: marketing-page
  portal: false
  document_request_flow: false
  document_request_note: >-
    No mechanism to request a SOC report, questionnaire response or subprocessor list. The page's only
    call to action is the generic "Get in Touch" sales form at https://mantrahealth.com/get-in-touch/.
  subprocessors_published: false
  pen_test_published: false
  uptime_sla_published: false
certifications:
- name: HIPAA
  status: self-attested
  evidence_quote: >-
    "We adhere to the national standard for handling Protected Health Information (PHI) related to
    student health records, medical research collaborations, and other university-related healthcare
    data."
  certificate_published: false
  date: null
- name: SOC 2
  status: claimed-audited
  evidence_quote: >-
    "Mantra has undergone a rigorous external audit, in which our security, availability, processing
    integrity, confidentiality, and privacy controls have been assessed and approved."
  certificate_published: false
  auditor: null
  report_type: null
  report_type_note: The page does not state whether the report is Type I or Type II, nor its period.
  date: null
- name: SOC 1
  status: claimed-audited
  evidence_quote: '"SOC-I & SOC-II" (page heading)'
  certificate_published: false
  date: null
- name: TX-RAMP
  status: claimed-aligned
  evidence_quote: >-
    "We're proactively committed to aligning with state-specific security requirements, including the
    TX RMP security framework which is mandated for higher education institutions and state agencies
    in Texas."
  certificate_published: false
  note: >-
    Stated as alignment/commitment, not as a granted certification at a level. No TX-RAMP
    certification number or status is published.
  date: null
not_claimed:
- name: ISO 27001
  note: Not mentioned anywhere on the page or site.
- name: HITRUST CSF
  note: >-
    Not mentioned. Notable only because HITRUST is the common companion certification for a HIPAA
    covered entity or business associate at this size; its absence is recorded, not judged.
- name: FERPA
  note: >-
    Not mentioned, despite student education records being squarely in scope for a vendor to colleges
    and universities.
- name: FedRAMP
  note: Not mentioned.
- name: PCI DSS
  note: Not mentioned; no evidence Mantra handles cardholder data (it bills institutions, not students).
observed_technical_posture:
  note: >-
    Independently probed, and corroborating the compliance claims: api.mantrahealth.com returns HSTS
    (max-age 31536000, includeSubDomains), a restrictive Content-Security-Policy, X-Frame-Options
    DENY, X-Content-Type-Options nosniff, X-XSS-Protection, X-Download-Options and
    Surrogate-Control no-store. The registrable domain publishes SPF and a DMARC policy of p=reject.
    DNSSEC is not enabled and no CAA record is published. See
    security/mantra-health-domain-security.yml.
  cross_ref: security/mantra-health-domain-security.yml
evidence:
- url: https://mantrahealth.com/security-and-privacy/
  status: 200
- url: https://mantrahealth.com/security
  status: 200
  note: 302 to /security-and-privacy/.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/mantra-health-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.