Simetrik · Trust Center
Simetrik Trust Center
Trust center
Simetrik maintains a public trust center documenting ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27018, SOC 1 Type 2, SOC 2 Type 2, SOC 3, and PCI DSS compliance.
CompanyReconciliationFinancial OperationsPaymentsAccountingFintechFinancial CloseData IntegrationAgentsMCPLatin America
Certifications & Compliance
ISO/IEC 27001ISO/IEC 27701ISO/IEC 27018SOC 1 Type 2SOC 2 Type 2SOC 3PCI DSS
Source
Trust Center
generated: '2026-08-27'
method: searched
source: >-
https://trust.simetrik.com/ (HTTP 200), https://simetrik.com/security/ (HTTP 200),
https://simetrik.com/information-security-privacy-policy/ (HTTP 200),
https://simetrik.com/data-privacy-treatment-policy/ (HTTP 200), https://docs.simetrik.com/mcp/data-handling,
and a DNS lookup of trust.simetrik.com, 2026-08-27.
note: >-
probe-security-programs.py returned trust=none for this provider. That was a false negative: the
trust center is served from a CNAME subdomain (trust.simetrik.com ->
667b5a6ebb4f7b57d3197659.cname.vantatrust.com) whose body is a JavaScript shell, so an automated
content probe finds no certification strings. The certifications below are read from Simetrik's own
first-party security page, which names them in prose, not from the trust center itself.
trust_center:
published: true
url: https://trust.simetrik.com/
http_status: 200
title: Simetrik Trust Center
provider: Vanta
provider_evidence: trust.simetrik.com is a CNAME to 667b5a6ebb4f7b57d3197659.cname.vantatrust.com
content_readable: false
content_note: >-
The page returns a 7 KB HTML shell and renders its content client-side, so the certification list,
document requests and subprocessor inventory are not machine-readable from the served body. Access
to actual audit reports is the usual Vanta gated flow (request + NDA), not an open download.
linked_from: Site header and footer navigation on simetrik.com, labelled "Trust Center".
certifications:
- name: ISO/IEC 27001
domain: Information security management
status: claimed
- name: ISO/IEC 27701
domain: Privacy information management
status: claimed
- name: ISO/IEC 27018
domain: Protection of PII in public clouds
status: claimed
- name: SOC 1 Type 2
domain: Controls relevant to financial reporting
status: claimed
- name: SOC 2 Type 2
domain: Security, availability, confidentiality and privacy
status: claimed
- name: SOC 3
domain: General-use report
status: claimed
- name: PCI DSS
domain: Payment card data handling
status: claimed
certification_evidence: >-
All seven are named verbatim in the Compliance FAQ on https://simetrik.com/security/. `status:
claimed` throughout because no certificate number, auditor name, report date or scope statement is
published on any public page - the evidence sits behind the trust center. This is normal for the
category and is recorded as a provenance fact, not a doubt about the certifications.
published_policies:
- name: Information Security & Privacy Policy
url: https://simetrik.com/information-security-privacy-policy/
http_status: 200
covers: >-
Risk-based protection of information assets, the confidentiality/integrity/availability
principles, shared-responsibility culture, training and awareness, and internal incident reporting
by employees, contractors and third parties.
- name: Data Treatment Policy
url: https://simetrik.com/data-privacy-treatment-policy/
http_status: 200
- name: Privacy Notice
url: https://simetrik.com/privacy-notice/
http_status: 200
- name: Cookie Policy
url: https://simetrik.com/cookie-policy/
- name: Code of Ethics (employees)
url: https://simetrik.com/legal/code-of-ethics-employees/
- name: Code of Ethics (third parties)
url: https://simetrik.com/legal/code-of-ethics-third-parties/
technical_controls_published:
- Encryption in transit on all external and internal communications.
- Encryption at rest for all stored data.
- Least-privilege access.
- Defence in depth.
- >-
PAN truncation at the agent boundary - the MCP server sends only the first six and last four digits
of a card number, matching the masking the web app shows on screen.
- Every MCP call is authenticated, authorized and logged, acting as the signed-in user.
vulnerability_disclosure:
published: false
security_txt: false
security_txt_note: >-
/.well-known/security.txt returns 403 on simetrik.com, 404 on docs.simetrik.com and
mcp.us.simetrik.com, and a shell-installer body on cli.simetrik.com. No RFC 9116 file is served on
any host.
bug_bounty: false
bug_bounty_note: hackerone.com/simetrik and bugcrowd.com/simetrik both return 404.
disclosure_page: false
security_contact: null
note: >-
HONEST GAP. Simetrik publishes a formal information security policy and a full certification set,
but no external vulnerability disclosure path - no security.txt, no /security/disclosure page, no
published security@ address, no bug bounty. The incident reporting described in the policy is
internal, aimed at employees, contractors and third parties, not at outside researchers. For a
platform holding reconciliation data for banks, PSPs, issuers and acquirers, a served
/.well-known/security.txt would be the single cheapest fix available.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/simetrik-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.