TypeSafe AI · Trust Center

Typesafe Ai Trust Center

Trust center

TypeSafe AI maintains a public trust center documenting observed, observed_note, and how_to_close compliance.

Artificial IntelligenceMachine LearningClassificationContent ModerationDecision SupportStructured OutputsInferenceLLM AlternativeAgent SkillsMCPAgent-NativeDeveloper ToolsA2A
Trust center: https://trust.typesafe.ai/

Certifications & Compliance

observedobserved_notehow_to_close

Source

Trust Center

Raw ↑
generated: '2026-09-19'
method: probed
source: https://trust.typesafe.ai/
checked: '2026-09-19'
summary: >-
  TypeSafe runs a Vanta-hosted trust center at trust.typesafe.ai. It exists and it is the
  authoritative location the Data Processing Agreement points at for the subprocessor list. Its
  CONTENT could not be read: the page is a client-rendered Vanta application whose data API
  (https://trust.typesafe.ai/graphql) rejects unsigned requests with "Missing `signature` or
  `signedAt`". No certification is recorded here because none was observed.
present: true
url: https://trust.typesafe.ai/
platform: Vanta
platform_evidence:
  - The served HTML loads only assets.vanta.com bundles (index-trust-report-*.js, alpaca-*.css).
  - 'Vanta slug id on the <head> element: fa36t9a4dulcnactq79ryr.'
  - 'Page <title>: "Typesafe.ai Trust Center"; canonical https://trust.typesafe.ai.'
machine_readable: false
machine_readable_note: >-
  The trust report renders client-side. Probed https://trust.typesafe.ai/graphql (400, "Missing
  `signature` or `signedAt`"), https://api.vanta.com/graphql (410, retired in favour of the Vanta
  REST API) and https://trust.typesafe.ai/api/graphql (404). Nothing on this host is fetchable by a
  crawler or an agent.
certifications:
  observed: []
  observed_note: >-
    DELIBERATELY EMPTY. A Vanta trust center usually lists SOC 2 / ISO 27001 status, but none was
    visible in served HTML and the data API is signature-gated, so recording one would be a guess.
    No `Compliance` pointer is emitted in apis.yml on the strength of an unreadable page — the
    compliance_published check must read a genuine unknown here rather than credit an assumption.
  how_to_close: >-
    If TypeSafe (or a reader) can name the certifications the portal lists, this file and a
    `Compliance` pointer can be filled in the same pass. Corrections are free — see README.
sections_referenced_by_legal_documents:
  - url: https://trust.typesafe.ai/subprocessors
    named_by: 'Data Processing Agreement §3.1 (Authorization)'
    quote: >-
      "Customer provides general authorization for Typesafe to engage the following subprocessors as
      described in https://trust.typesafe.ai/subprocessors"
    probed: {url: 'https://trust.typesafe.ai/subprocessors', status: 200}
    readable: false
    readable_note: >-
      Returns the same 6,914-byte Vanta shell as every other path on this host, so the subprocessor
      table itself was NOT observed. The DPA clause is the substance; the table is not machine-readable.
evidence:
- url: https://trust.typesafe.ai/
  status: 200
  content_type: text/html
  bytes: 6914
- url: https://trust.typesafe.ai/subprocessors
  status: 200
  bytes: 6914
- url: https://trust.typesafe.ai/graphql
  status: 400
  body: '{"data":null,"errors":[{"message":"Missing `signature` or `signedAt`", ... }]}'
- url: https://typesafe.ai/trust
  status: 404
cross_links:
  vulnerability_disclosure: security/typesafe-ai-vulnerability-disclosure.yml
  regulatory: regulatory/typesafe-ai-regulatory-posture.yml
  conformance: conformance/typesafe-ai-conformance.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/typesafe-ai-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.