generated: '2026-08-06' method: probed probe: true url: https://trust.altoira.com/ title: Alto Trust Center platform: Vanta certifications: [] certifications_readable: false detail: >- Alto publishes a trust center at trust.altoira.com. It is verified live: the host CNAMEs to Vanta (68cc37f32db8854ae217e531.cname.vantatrust.com), returns HTTP 200, and the served HTML carries Alto Trust Center, a canonical link to https://trust.altoira.com, and og:description "The secure self-directed IRA platform for all your alternatives". The page body is a client-rendered Vanta single-page application — the 6.6KB HTML shell contains no certification names — and Vanta's backing API (api.vanta.com/v1/trust-pages) returns 401 to an anonymous caller. Requests to trust.altoira.com under any guessed API path return the SPA shell with a 200 (soft-404), which is not evidence of an endpoint. Consequence: API Evangelist can confirm the trust center EXISTS but cannot read any named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) from it without a browser. No certification is therefore asserted, and no `Compliance` pointer is wired in apis.yml. A grep of altoira.com's homepage, about, FAQ, legal, contact and Alto Trust Company pages found no named certification either. This is a provider-fixable gap: serving the certification list as static HTML or exposing an anonymous JSON view would make Alto's compliance posture machine-readable. evidence: - source: https://trust.altoira.com/ http_status: 200 content_type: text/html keywords: - Alto Trust Center - Trust, Security, Compliance, Automation note: JS-rendered Vanta SPA; certification names not present in the served HTML. - source: https://api.vanta.com/v1/trust-pages/pgbmbtllndywbuh6bxxjo http_status: 401 note: Vanta trust-page data API rejects anonymous requests. - source: dig trust.altoira.com result: 68cc37f32db8854ae217e531.cname.vantatrust.com x-evidence: fetched: '2026-08-06' url: https://trust.altoira.com/ http_status: 200