Wealth-X · Trust Center

Wealth X Trust Center

Trust center

Wealth-X publishes no security or trust page of its own, and probe-security-programs.py found no security.txt, bug bounty, or trust center on any wealthx.com host. Its parent Altrata publishes a named compliance posture on "Altrata's Privacy Promise", and the llms.txt served from Wealth-X's own domain (https://wealthx.com/llms.txt) states plainly that "Altrata is a subsidiary of Delinian and is SOC 2 certified."

Wealth-X maintains a public trust center documenting SOC 2 and CCPA Validation compliance.

CompanyWealth IntelligenceDataUHNWProspectingFinancial-ServicesCRMPeople DataAltrataGraphQLMCPWealth Screening
Trust center:

Certifications & Compliance

SOC 2CCPA Validation

Source

Trust Center

Raw ↑
generated: '2026-08-14'
method: searched
source: https://altrata.com/altratas-privacy-promise
description: >-
  Wealth-X publishes no security or trust page of its own, and
  probe-security-programs.py found no security.txt, bug bounty, or trust center
  on any wealthx.com host. Its parent Altrata publishes a named compliance
  posture on "Altrata's Privacy Promise", and the llms.txt served from
  Wealth-X's own domain (https://wealthx.com/llms.txt) states plainly that
  "Altrata is a subsidiary of Delinian and is SOC 2 certified."
trust_center_url: https://altrata.com/altratas-privacy-promise
public_portal: false
portal_note: >-
  There is no self-serve trust portal (no Vanta/Drata/SafeBase instance;
  trust.altrata.com does not resolve). Audit reports are gated: "we ... make our
  audit reports – along with our full collection of security documentation –
  available to clients and prospects upon request."
certifications:
  - name: SOC 2
    type: attestation
    status: claimed
    verified_by_us: false
    evidence: >-
      "We regularly invest in independent auditors to assess our security
      environment as part of our SOC2 attestation." and "On an annual basis, an
      independent expert third party auditor assesses our security environment
      in detail as part of our commitments to maintain our SOC2 attestation.
      Please contact a member of our commercial team for a copy of our SOC-2
      report."
    source: https://altrata.com/altratas-privacy-promise
    report_access: on request via the Altrata commercial team
  - name: CCPA Validation
    type: independent validation
    status: achieved
    verified_by_us: false
    evidence: >-
      "Altrata has achieved independent CCPA Validation confirming that our
      privacy practices meet established CCPA Controls. Following a detailed
      assessment and evidence review..." A downloadable "Altrata Inc. CCPA
      Validation Findings Letter" is published on the page.
    source: https://altrata.com/altratas-privacy-promise
regulatory_compliance:
  - regime: GDPR
    posture: >-
      Data controller relying on legitimate interests as its Article 6(1) lawful
      basis, with documented Legitimate Interest Assessments and Standard
      Contractual Clauses where applicable.
    source: https://altrata.com/altratas-privacy-promise
  - regime: CCPA / CPRA
    posture: >-
      Compliant, with a published "Do Not Sell" rights process and independent
      CCPA Validation.
    source: https://altrata.com/altratas-privacy-promise
  - regime: China PIPL
    posture: Named as a standard Altrata states it is compliant with.
    source: https://altrata.com/altratas-privacy-promise
  - regime: US state data broker registration
    posture: >-
      Altrata holds current data broker registrations in California, Oregon,
      Texas and Vermont — material for a provider whose product is third-party
      personal data on private individuals.
    source: https://altrata.com/altratas-privacy-promise
security_practices:
  - practice: Independent annual third-party security assessment
    source: https://altrata.com/altratas-privacy-promise
  - practice: Continuous penetration testing
    source: https://altrata.com/altratas-privacy-promise
  - practice: Patch and vulnerability management process
    source: https://altrata.com/altratas-privacy-promise
  - practice: Documented data deletion policy
    source: https://altrata.com/altratas-privacy-promise
  - practice: Security-by-design process and personnel security training
    source: https://altrata.com/altratas-privacy-promise
gaps:
  - No published security.txt on wealthx.com, connect.wealthx.com or altrata.com (all 404).
  - No vulnerability disclosure policy or bug bounty program found.
  - No self-serve trust portal; every artifact is gated behind a sales conversation.
  - No compliance page on wealthx.com itself — the entire posture is published under the parent brand.
evidence:
  - url: https://altrata.com/altratas-privacy-promise
    status: 200
  - url: https://wealthx.com/llms.txt
    status: 200
    note: '"Altrata is a subsidiary of Delinian and is SOC 2 certified." — served from Wealth-X''s own domain.'
  - url: https://altrata.com/.well-known/security.txt
    status: 404
  - url: https://wealthx.com/.well-known/security.txt
    status: 404
  - url: https://trust.altrata.com/
    status: 0
    note: Host does not resolve.
  - url: https://altrata.com/compliance
    status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/wealth-x-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.