Simetrik · Trust Center

Simetrik Trust Center

Trust center

Simetrik maintains a public trust center documenting ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27018, SOC 1 Type 2, SOC 2 Type 2, SOC 3, and PCI DSS compliance.

CompanyReconciliationFinancial OperationsPaymentsAccountingFintechFinancial CloseData IntegrationAgentsMCPLatin America
Trust center:

Certifications & Compliance

ISO/IEC 27001ISO/IEC 27701ISO/IEC 27018SOC 1 Type 2SOC 2 Type 2SOC 3PCI DSS

Source

Trust Center

simetrik-trust-center.yml Raw ↑
generated: '2026-08-27'
method: searched
source: >-
  https://trust.simetrik.com/ (HTTP 200), https://simetrik.com/security/ (HTTP 200),
  https://simetrik.com/information-security-privacy-policy/ (HTTP 200),
  https://simetrik.com/data-privacy-treatment-policy/ (HTTP 200), https://docs.simetrik.com/mcp/data-handling,
  and a DNS lookup of trust.simetrik.com, 2026-08-27.
note: >-
  probe-security-programs.py returned trust=none for this provider. That was a false negative: the
  trust center is served from a CNAME subdomain (trust.simetrik.com ->
  667b5a6ebb4f7b57d3197659.cname.vantatrust.com) whose body is a JavaScript shell, so an automated
  content probe finds no certification strings. The certifications below are read from Simetrik's own
  first-party security page, which names them in prose, not from the trust center itself.
trust_center:
  published: true
  url: https://trust.simetrik.com/
  http_status: 200
  title: Simetrik Trust Center
  provider: Vanta
  provider_evidence: trust.simetrik.com is a CNAME to 667b5a6ebb4f7b57d3197659.cname.vantatrust.com
  content_readable: false
  content_note: >-
    The page returns a 7 KB HTML shell and renders its content client-side, so the certification list,
    document requests and subprocessor inventory are not machine-readable from the served body. Access
    to actual audit reports is the usual Vanta gated flow (request + NDA), not an open download.
  linked_from: Site header and footer navigation on simetrik.com, labelled "Trust Center".
certifications:
- name: ISO/IEC 27001
  domain: Information security management
  status: claimed
- name: ISO/IEC 27701
  domain: Privacy information management
  status: claimed
- name: ISO/IEC 27018
  domain: Protection of PII in public clouds
  status: claimed
- name: SOC 1 Type 2
  domain: Controls relevant to financial reporting
  status: claimed
- name: SOC 2 Type 2
  domain: Security, availability, confidentiality and privacy
  status: claimed
- name: SOC 3
  domain: General-use report
  status: claimed
- name: PCI DSS
  domain: Payment card data handling
  status: claimed
certification_evidence: >-
  All seven are named verbatim in the Compliance FAQ on https://simetrik.com/security/. `status:
  claimed` throughout because no certificate number, auditor name, report date or scope statement is
  published on any public page - the evidence sits behind the trust center. This is normal for the
  category and is recorded as a provenance fact, not a doubt about the certifications.
published_policies:
- name: Information Security & Privacy Policy
  url: https://simetrik.com/information-security-privacy-policy/
  http_status: 200
  covers: >-
    Risk-based protection of information assets, the confidentiality/integrity/availability
    principles, shared-responsibility culture, training and awareness, and internal incident reporting
    by employees, contractors and third parties.
- name: Data Treatment Policy
  url: https://simetrik.com/data-privacy-treatment-policy/
  http_status: 200
- name: Privacy Notice
  url: https://simetrik.com/privacy-notice/
  http_status: 200
- name: Cookie Policy
  url: https://simetrik.com/cookie-policy/
- name: Code of Ethics (employees)
  url: https://simetrik.com/legal/code-of-ethics-employees/
- name: Code of Ethics (third parties)
  url: https://simetrik.com/legal/code-of-ethics-third-parties/
technical_controls_published:
- Encryption in transit on all external and internal communications.
- Encryption at rest for all stored data.
- Least-privilege access.
- Defence in depth.
- >-
  PAN truncation at the agent boundary - the MCP server sends only the first six and last four digits
  of a card number, matching the masking the web app shows on screen.
- Every MCP call is authenticated, authorized and logged, acting as the signed-in user.
vulnerability_disclosure:
  published: false
  security_txt: false
  security_txt_note: >-
    /.well-known/security.txt returns 403 on simetrik.com, 404 on docs.simetrik.com and
    mcp.us.simetrik.com, and a shell-installer body on cli.simetrik.com. No RFC 9116 file is served on
    any host.
  bug_bounty: false
  bug_bounty_note: hackerone.com/simetrik and bugcrowd.com/simetrik both return 404.
  disclosure_page: false
  security_contact: null
  note: >-
    HONEST GAP. Simetrik publishes a formal information security policy and a full certification set,
    but no external vulnerability disclosure path - no security.txt, no /security/disclosure page, no
    published security@ address, no bug bounty. The incident reporting described in the policy is
    internal, aimed at employees, contractors and third parties, not at outside researchers. For a
    platform holding reconciliation data for banks, PSPs, issuers and acquirers, a served
    /.well-known/security.txt would be the single cheapest fix available.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/simetrik-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.