generated: '2026-09-05' method: searched source: https://trust.opus.com/ url: https://trust.opus.com/ name: Opus Trust Center platform: Vanta (EU tenant) x-evidence: fetched: '2026-09-05' url: https://trust.opus.com/ http_status: 200 content_type: text/html title: Opus Trust Center meta_description: Trust, Security, Compliance, Automation vanta_document_reference: https://app.eu.vanta.com/doc?s=ftiu9wqamqqyrz2eo2n2 note: >- A live, first-party trust center exists and is hosted on Vanta's EU tenant under AAICO's own opus.com domain. The page body is fully client-rendered — the served HTML is a 5.5KB Vanta bootstrap shell — so the certification list, subprocessors and controls cannot be read without executing JavaScript, and the backing data endpoints return the same shell rather than JSON. The certifications recorded below were therefore read from AAICO's own enterprise page, which names them in plain text, NOT scraped from the trust center. certifications: - name: SOC 2 Type II source: https://www.opus.com/enterprise - name: ISO 27001 source: https://www.opus.com/enterprise - name: ISO 42001 source: https://www.opus.com/enterprise - name: HIPAA source: https://www.opus.com/enterprise - name: GDPR source: https://www.opus.com/enterprise - name: EU AI Act source: https://www.opus.com/enterprise documents: - name: Opus Data Processing Agreement url: https://www.opus.com/legal-docs/Opus-DPA.pdf status: 200 - name: Opus Support Service Standards url: https://www.opus.com/legal-docs/Opus-Support-Service-Standards.pdf status: 200 report_access: gated — audit reports are requested through the Vanta trust center, not downloadable anonymously gaps: - Trust center content is JS-only; no machine-readable certification list is served. - No security.txt on any host, so there is no RFC 9116 route to a security contact.