Wellfound · Trust Center
Wellfound Trust Center
Trust center
Wellfound maintains a public trust center documenting SOC 2 compliance.
RecruitingHiringTalentHuman ResourcesApplicant TrackingJob BoardStartupsMCPagent-nativeOAuthAI Sourcing
Certifications & Compliance
SOC 2
Source
Trust Center
generated: '2026-09-04'
method: searched
source: >-
https://trust.wellfound.ai/ (200) and
https://help.wellfound.com/article/1213-wellfound-ai-ats-connection-what-we-access-why-we-need-it-and-what-we-do-with-your-data
(200)
trust_center:
url: https://trust.wellfound.ai/
http_status: 200
title: Wellfound Trust Center
platform: Vanta
platform_evidence: >-
The page is served from Vanta's trust-center product - assets load from
assets.vanta.com, the document carries data-slugid="kwb5hos99yzvm26qd1ykhz" and the
og:image resolves to https://app.vanta.com/doc?s=wwsuwhttugmuxiis1iz8j4.
domain_note: >-
The trust center lives on wellfound.ai, not wellfound.com. This is Wellfound's own second
brand - wellfound.ai / cloud.wellfound.com both redirect into reach.wellfound.com, the
Wellfound Reach application - and the trust center is linked from Wellfound's own help
center, so the different domain is confirmed first-party rather than a third party's page.
readable_by_machine: false
readable_note: >-
The page renders entirely client-side; every /.well-known/* path on the host returns the
same 5,436-byte HTML shell. Certifications, subprocessors and report metadata are behind
the JS render and, in Vanta's product, usually behind an NDA request as well, so the
document list could not be enumerated by probe.
certifications:
- name: SOC 2
status: claimed
verified_by_probe: false
evidence: >-
"Both Wellfound and Merge (our ATS integration provider) are SOC 2 compliant." -
https://help.wellfound.com/article/1213-wellfound-ai-ats-connection-what-we-access-why-we-need-it-and-what-we-do-with-your-data
type: not stated (Type I vs Type II not published)
period: not stated
subprocessors:
- name: Merge
role: ATS integration provider (unified API broker for Greenhouse, Lever, Ashby, Workable,
Gem and others)
url: https://www.merge.dev/
security_page: https://www.merge.dev/security
soc2_claimed: true
evidence: same help-center article; Wellfound names Merge as a subprocessor in its own words
("subprocessors such as Merge").
- name: Atlassian Statuspage
role: status page (status.wellfound.com)
evidence: page footer "Powered by Atlassian Statuspage"; the host serves Atlassian's own
security.txt.
- name: Vanta
role: trust center hosting (trust.wellfound.ai)
- name: Cloudflare
role: CDN, WAF and bot mitigation in front of every Wellfound host probed
- name: SendGrid
role: transactional email (named as a monitored component on status.wellfound.com)
- name: Iterable
role: marketing/lifecycle email (named as a monitored component on status.wellfound.com)
- name: AWS
role: hosting, us-west-2 (named as monitored components on status.wellfound.com)
security_contact:
email: security@wellfound.com
source: https://wellfound.com/.well-known/security.txt
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/wellfound-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.