Storylane · Trust Center

Storylane Trust Center

Trust center

Storylane operates a public Trust Center hosted on Sprinto at trust.storylane.io, carrying a SOC 2 Type 2 report, a penetration test report, an EU/UK Data Processing Agreement, a subprocessor list and a live control register. It is the company's only structured security-and-compliance surface — there is no security.txt and no vulnerability disclosure program anywhere on the estate.

Storylane maintains a public trust center documenting SOC 2 Type 2 and GDPR compliance.

Interactive DemosProduct WalkthroughsSales EnablementMarketingDemo AnalyticsDemo AutomationBuyer HubSalesMCPAgent ToolsWebhookEmbedsoEmbedDemo Automation Platform
Trust center: https://trust.storylane.io/

Certifications & Compliance

SOC 2 Type 2GDPR

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://trust.storylane.io/
url: https://trust.storylane.io/
description: >
  Storylane operates a public Trust Center hosted on Sprinto at
  trust.storylane.io, carrying a SOC 2 Type 2 report, a penetration test report,
  an EU/UK Data Processing Agreement, a subprocessor list and a live control
  register. It is the company's only structured security-and-compliance surface —
  there is no security.txt and no vulnerability disclosure program anywhere on
  the estate.
platform: Sprinto
verified: probed
http_status: 200
probe_note: >
  IMPORTANT PROBE CAVEAT. trust.storylane.io sits behind CloudFront with a WAF
  rule that returns HTTP 403 "Request blocked" to non-browser user agents. A
  default curl request reports 403; the same URL returns 200 with a browser
  User-Agent. Any automated check that does not set a browser UA will record this
  live trust center as unavailable.
certifications:
  - name: SOC 2 Type 2
    year: '2026'
    document: Storylane Inc - SOC 2 Type 2 - Final Report.pdf
    access: gated (request via the Trust Center, NDA flow)
    evidence: SOC 2 framework badge and the named final report listed on trust.storylane.io
  - name: GDPR
    document: EU and UK Personal Data Processing Agreement 1.2.5.5.pdf
    access: published on the Trust Center
    evidence: >
      "Storylane is GDPR compliant and our DPA is available in the Storylane
      Trust Center" — https://docs.storylane.io/trust-and-security/gdpr-compliance
documents_listed:
  - name: Storylane Inc - SOC 2 Type 2 - Final Report.pdf
    type: audit report
  - name: Storylane INC Security-Scan-Report.pdf
    type: penetration / security scan report
  - name: EU and UK Personal Data Processing Agreement 1.2.5.5.pdf
    type: data processing agreement
  - name: Subprocessor list
    type: subprocessors
controls_published:
  note: >
    The Sprinto trust center exposes a live control register with per-control
    pass state. Controls observed by name include:
  observed:
    - Vulnerability Remediation Process
    - Centralized Management of Flaw Remediation Processes
    - Application security practices (unauthorized access and modification)
not_found:
  - name: ISO 27001
    checked: true
    result: not listed
  - name: HIPAA
    checked: true
    result: not listed
  - name: PCI DSS
    checked: true
    result: not listed
  - name: FedRAMP
    checked: true
    result: not listed
related:
  gdpr_docs: https://docs.storylane.io/trust-and-security/gdpr-compliance
  sso_docs: https://docs.storylane.io/trust-and-security/sso
  privacy_contact: privacy@storylane.io
  domain_security: security/storylane-domain-security.yml
gaps:
  - No security.txt on any host (RFC 9116 absent).
  - No vulnerability disclosure or bug bounty program (HackerOne 404, Bugcrowd 404, no disclosure page).
  - No published security contact address; support@storylane.io and privacy@storylane.io are the only channels.
  - The SOC 2 report is gated behind a request flow rather than summarized publicly.
evidence:
  - source: https://trust.storylane.io/
    http_status: 200
    user_agent: browser
    keywords:
      - SOC 2 Type 2
      - SOC 2 - 2026
      - GDPR
      - Subprocessor
      - Pentest
      - DPA
      - Vulnerability Remediation Process
  - source: https://trust.storylane.io/
    http_status: 403
    user_agent: default (curl)
    note: CloudFront WAF blocks non-browser agents

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/storylane-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.