Sift Stack · Trust Center

Sift Stack Trust Center

Trust center

Sift Stack maintains a public trust center documenting SOC 2 Type II, NIST SP 800-171, ITAR, FedRAMP, and CMMC Level 2 compliance.

ObservabilityTelemetryAerospaceDefenseRoboticsTime SeriesSensor DatagRPCData IngestionAnomaly DetectionManufacturingEnergyAutonomous VehiclesMachine DataAgent Ready
Trust center: https://www.siftstack.com/trust-and-security

Certifications & Compliance

SOC 2 Type IINIST SP 800-171ITARFedRAMPCMMC Level 2

Source

Trust Center

Raw ↑
generated: '2026-08-27'
method: searched
source: >-
  https://www.siftstack.com/trust-and-security (HTTP 200) and https://www.siftstack.com/fedramp (HTTP 200),
  read 2026-08-27; https://trust.siftstack.com did not resolve (curl exit 6, DNS failure).
name: Sift trust and security
published: true
url: https://www.siftstack.com/trust-and-security
dedicated_portal: false
portal_note: >-
  There is a trust PAGE but not a trust PORTAL — trust.siftstack.com does not resolve, and evidence
  documents are not self-serve. Sift names Vanta as its compliance-monitoring vendor and states detailed
  reports are available through the Vanta portal, which means an NDA/request step stands between a buyer and
  the artifacts.
certifications:
- {name: SOC 2 Type II, status: certified}
- {name: NIST SP 800-171, status: 'meets all 110 controls'}
- {name: ITAR, status: compliant / registered}
- {name: FedRAMP, status: 'meets FedRAMP security requirements (no authorization ID published)', page: https://www.siftstack.com/fedramp}
- {name: CMMC Level 2, status: 'path to certification — not certified'}
controls:
- Encryption of sensitive data at rest and in transit
- Regular penetration testing
- Multi-factor authentication and encrypted connections
- Role-based access control, fine-grained access policies and audit logging (Sift Governance)
data_residency:
- {name: AWS GovCloud (US), note: 'Isolated environment for sensitive and regulated data; the OpenAPI declares a matching server https://gov.api.siftstack.com labelled "Gov".'}
- {name: On-premises}
- {name: Airgapped}
- {name: Private cloud}
subprocessors_published: false
documents_self_serve: false
note: >-
  Read alongside conformance/sift-stack-conformance.yml, which carries the per-claim evidence quotations,
  and security/sift-stack-vulnerability-disclosure.yml, which records the one gap in this posture.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/sift-stack-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.