Mosaic Tech · Trust Center
Mosaic Tech Trust Center
Trust center
Mosaic Tech maintains a public trust center documenting SOC 2 Type II compliance.
Financial PlanningFP&AStrategic FinanceBusiness IntelligenceAnalyticsSoftware-as-a-ServiceAcquired
Trust center: https://trust.mosaic.tech/
Certifications & Compliance
SOC 2 Type II
Source
Trust Center
generated: '2026-08-26'
method: searched
probe: true
source: https://trust.mosaic.tech/
url: https://trust.mosaic.tech/
title: Mosaic.tech Trust Center
platform: Conveyor
http_status: 200
note: >-
The Trust Center is the one Mosaic-branded public surface still standing after the HiBob
acquisition. trust.mosaic.tech resolves independently (it does NOT redirect to hibob.com, unlike
every other mosaic.tech path) and still serves Mosaic-named documents. Content read verbatim from
the live page on 2026-08-26.
certifications:
- name: SOC 2 Type II
status: held
badge: true
auditor: Sensiba San Filippo, LLP (SSF)
evidence: >-
"SOC 2 Type II" badge on the Trust Center; announcement dated 2023-03-21 "Mosaic Completes 2023
SOC 2 Type II Audit" stating the report "didn't have any noted exceptions and therefore was
issued with a 'clean' audit opinion"; featured document "Mosaic Finance SOC2 Type II Report 2025".
documents:
count: 3
featured:
- name: Mosaic Finance SOC2 Type II Report 2025
access: gated
- name: Mosaic Data Processing Addendum (DPA)
access: gated
- name: Mosaic 2024 Penetration Test
access: gated
note: >-
Documents are listed publicly but require a "Get Access" request through Conveyor; the documents
themselves were not fetched and are not reproduced here.
knowledge_base:
faq_count: 167
categories:
- {name: Overview, answers: 7}
- {name: Access Management, answers: 13}
- {name: Application and Data Security, answers: 41}
- {name: Cloud Security, answers: 25}
- {name: Continuity and Disaster Recovery, answers: 7}
- {name: Device Management, answers: 21}
- {name: Incident Management, answers: 23}
- {name: Personnel Security, answers: 24}
- {name: Privacy, answers: 14}
- {name: Risk and Vulnerability Management, answers: 35}
- {name: Security Governance, answers: 47}
- {name: Vendor Management, answers: 9}
summary_claims:
- One or more annual third-party audit(s)
- Has a formal mobile device management (MDM) program
- Annual third-party penetration testing
- Has a disaster recovery plan
- Will enter into a DPA
- Has a status page
security_contact:
named_role: Lead Security Engineer (Josh Sussman, per the Trust Center philosophy section)
email: null
note: No security contact address, vulnerability disclosure policy, or bug-bounty program is published.
staleness:
note: >-
The Trust Center carries un-refreshed content from the pre-acquisition era — a "Coming Soon"
block still advertising "Next Penetration Test: Q4'23" and "Next Security Awareness & Training:
Q3'23". The featured SOC 2 report is dated 2025, so the page is partially maintained, but the
forward-looking section has not been updated in roughly three years.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/mosaic-tech-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.