OncoLens · Trust Center

Oncolens Trust Center

Trust center

OncoLens operates a real, publicly reachable SafeBase trust center on its own domain. It is the single most substantive machine-adjacent artifact the company publishes — 30+ security controls marked at full maturity, SOC 2 and HIPAA compliance entries, and gated report downloads. It carries no API, developer, or interoperability content.

OncoLens maintains a public trust center documenting SOC 2, HIPAA, SOC 3, ISO 27001, HITRUST, PCI DSS, and FedRAMP compliance.

CompanyHealthcareOncologyCancer CareClinical TrialsHealth DataReal-World DataArtificial IntelligenceAnalyticsClinical WorkflowCancer RegistryLife SciencesSoftware-as-a-Service
Trust center: https://trust.oncolens.com/

Certifications & Compliance

SOC 2HIPAASOC 3ISO 27001HITRUSTPCI DSSFedRAMP

Source

Trust Center

oncolens-trust-center.yml Raw ↑
generated: '2026-08-26'
method: searched
probe: true
source: https://trust.oncolens.com/
url: https://trust.oncolens.com/
name: OncoLens Trust Center
description: >-
  OncoLens operates a real, publicly reachable SafeBase trust center on its own domain. It is
  the single most substantive machine-adjacent artifact the company publishes — 30+ security
  controls marked at full maturity, SOC 2 and HIPAA compliance entries, and gated report
  downloads. It carries no API, developer, or interoperability content.
platform: SafeBase
platform_evidence: 'DNS CNAME: trust.oncolens.com -> oncolens.portals.safebase.io'
plan: free
custom_domain: trust.oncolens.com
primary_domain: oncolens.com
evidence:
- source: https://trust.oncolens.com/
  http_status: 200
  content_type: text/html
  bytes: 236247
  method: >-
    Read from the embedded __NEXT_DATA__ payload on the rendered page. NOTE for re-runs: a
    curl request sending a full desktop-browser User-Agent is answered with a Cloudflare
    interactive challenge (HTTP 403, "Just a moment..."); a plain library User-Agent is
    served the page (HTTP 200). The 403 is a bot-fingerprint edge policy, not an access wall.
  keywords: [soc 2, hipaa, trust center, safebase]
certifications:
- name: SOC 2
  status: published
  maturity: full
  report_available: true
  report_access: gated
  report_note: >-
    A "SOC 2 Report" document entry is enabled and carries attached files, but the files are
    not shared publicly (isShared false) — access is request/NDA gated through SafeBase.
    Report type (Type I vs Type II), auditor and period are not disclosed anonymously.
- name: HIPAA
  status: published
  maturity: full
  report_available: false
  report_note: >-
    The HIPAA compliance entry is enabled; the separate "HIPAA Report" document entry is
    NOT enabled on this trust center.
- name: SOC 3
  status: not-published
  note: The "SOC 3 Report" item exists in the SafeBase template but is disabled.
- name: ISO 27001
  status: not-published
- name: HITRUST
  status: not-published
  note: >-
    Notable for a US oncology data platform — HITRUST CSF is the certification most often
    requested of healthcare vendors handling PHI, and it is absent.
- name: PCI DSS
  status: not-published
  note: Not applicable; OncoLens is not a payment surface.
- name: FedRAMP
  status: not-published
security_program:
  penetration_testing:
    published: true
    maturity: full
    report_access: gated
  controls_published: 38
  controls_at_full_maturity: 33
  controls:
  - Access Monitoring
  - BC/DR
  - Cloud Workload Protection
  - Code of Ethics
  - Critical Dependence
  - Cyber Insurance
  - DNS Filtering
  - Data Access Level
  - Data Backups
  - Data Erasure
  - Data Loss Prevention
  - Data Privacy Officer
  - Disk Encryption
  - Effective Board Oversight
  - Employee Privacy Training
  - Encryption-at-rest
  - Encryption-in-transit
  - Endpoint Detection & Response
  - Hosting
  - Impact Level
  - Infrastructure Security
  - Pentest Report
  - Physical Security
  - Secure Development Training
  - Security Information and Event Management
  - Separate Production Environment
  - Software Bill of Materials (SBOM)
  - Software Development Lifecycle
  - Third Party Dependence
  - Threat Detection
  - Virtual Private Cloud
  - Vulnerability & Patch Management
  - Web Application Firewall
  - Zero Trust
  subprocessors_published: true
gaps:
- >-
  securityMailbox is null on the SafeBase org record, and no security.txt is served on any
  OncoLens host — there is no published vulnerability-disclosure contact or policy despite a
  full pentest program being advertised.
- >-
  The trust center's own "Terms of Service" and "Privacy Policy" document slots are disabled,
  and no terms-of-service page exists on www.oncolens.com (probed /terms/, /terms-of-use/,
  /terms-of-service/, /terms-and-conditions/ — all 404).
- >-
  No API, integration, or interoperability content appears anywhere in the trust center.
checked: '2026-08-26'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/oncolens-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.