Osano · Trust Center
Osano Trust Center
Trust center
Osano maintains a public trust center documenting SOC 2 and Enterprise audit package compliance.
CompanyData PrivacyConsent ManagementComplianceGDPRCCPACookie ConsentSubject RightsData MappingVendor RiskPrivacy AssessmentsGovernance Risk Compliance
Certifications & Compliance
SOC 2Enterprise audit package
Source
Trust Center
generated: '2026-08-26'
method: searched
source: https://trust.osano.com/ and https://www.osano.com/faq
evidence:
- url: https://trust.osano.com/
status: 200
detail: >-
Vanta-hosted trust center, canonical https://trust.osano.com, title "Osano Trust Center",
description "At Osano, we take your privacy seriously. This Trust Center is designed to share
information that enables you to get information about how we handle data and how we will work
with you." Listed in Osano's own llms.txt under Optional.
- url: https://trust.osano.com/subprocessors
status: 200
- url: https://www.osano.com/faq
status: 200
trust_center:
url: https://trust.osano.com/
platform: Vanta
machine_readable: false
note: >-
The trust center is a client-rendered Vanta application; the certification list, document
requests and subprocessor table are fetched by JavaScript, so no certification names could be
read from the served HTML. The certification claims below are quoted from Osano's OWN FAQ page,
which does serve them as text. Nothing here is inferred from the Vanta shell.
certifications:
- name: SOC 2
status: maintained
evidence_verbatim: >-
"Osano maintains an always current SOC2 report which is available upon request to customers on
any paid plan."
source: https://www.osano.com/faq
public_report: false
note: Report is gated behind a paid-customer request; type (I/II) is not stated on the public page.
- name: Enterprise audit package
status: available-on-request
evidence_verbatim: >-
"If you are a current or prospective Enterprise customer, Osano can provide a full suite of
third-party audits, policies, documentation, code security reports, code coverage reports, and
architectural walkthroughs for your security team assessments."
source: https://www.osano.com/faq
security_practices:
- practice: vulnerability-scanning
evidence_verbatim: 'Osano infrastructure and systems are tested for vulnerabilities nightly'
source: https://www.osano.com/faq
- practice: penetration-testing
evidence_verbatim: 'are routinely penetration tested'
source: https://www.osano.com/faq
- practice: encryption
evidence_verbatim: >-
"all data is transferred (in transit) and stored (at rest) using modern encryption protocols such
as TLS1.3 and AES 256 respectively"
source: https://www.osano.com/faq
- practice: per-customer-key-separation
evidence_verbatim: >-
"Personal data is encrypted using an encryption key which is unique to each customer. Most data
is stored using a per customer salt and SHA-512 hashing."
source: https://www.osano.com/faq
- practice: eu-data-residency
evidence_verbatim: >-
"Osano stores de-identified data in our Dublin, Ireland data center and does not store
identifiable information about your visitors, nor do we transfer personal data outside of the
European Economic Area."
source: https://www.osano.com/faq
corporate_status:
- 'Certified B Corporation (per Osano llms.txt and www.osano.com/company/about)'
- 'Public Benefit Corporation — the GitHub organization is registered as "Osano, Inc., A Public Benefit Corporation"'
not_found:
iso_27001: Not named on any public Osano page reached in this pass.
pci_dss: Not named.
hipaa: Not named.
fedramp: Not named.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/osano-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.