generated: '2026-09-11' method: searched probe: true source: https://anchor-x402.com/trust/ url: https://anchor-x402.com/trust/ http_status: 200 trust_center_present: true certifications: [] certification_count: 0 certifications_explicitly_disclaimed: - SOC 2 - ISO 27001 - PCI DSS - HIPAA - GDPR DPA x-correction: >- 0-working/probe-security-programs.py wrote this file on 2026-09-11 with certifications [SOC 2, ISO 27001, HIPAA, GDPR] from a bare keyword match on the trust-portal page. Every one of those matches is a NEGATION. The page's own words are "We do not hold SOC 2, ISO 27001, or PCI certifications" and "No SOC 2 / ISO 27001 / PCI / HIPAA certification. Roadmap items, not blockers for the commodity tier." The list was corrected to empty by hand and no Compliance pointer was emitted. A scorer reading the generated file would have credited this provider with four certifications it goes out of its way to say it does not hold. posture: >- The trust portal is unusually substantial for an uncertified provider and is built around an explicit argument: publish the reasoning instead of the certificates. It carries six documents totalling roughly 22,000 words - a STRIDE-lite per-service threat model, a pre-filled SIG-Lite vendor security questionnaire, a code-level self-audit guide mapping 15 compliance concerns to file and line ranges in the MIT-licensed source, a regulated-deployment guide covering trust boundaries and AWS compliance inheritance, an on-chain verifiability primer with live mainnet hashes, and observability docs. documents: - name: Threat model url: https://anchor-x402.com/trust/threat-model.html status: 200 form: STRIDE-lite per-service enumeration with mitigations and residual risk approx_words: 5400 - name: Security questionnaire url: https://anchor-x402.com/trust/security-questionnaire.html status: 200 form: Pre-filled SIG-Lite-style vendor security response across 11 sections approx_words: 4300 - name: Self-audit guide url: https://anchor-x402.com/trust/self-audit.html form: 15 compliance concerns mapped to specific files and line ranges in the codebase approx_words: 4600 - name: Regulated deployment guide url: https://anchor-x402.com/trust/regulated-deployment.html form: Trust boundaries, AWS compliance inheritance, customer-side responsibilities approx_words: 5300 - name: On-chain verifiability url: https://anchor-x402.com/trust/on-chain-verifiability status: 200 form: The cryptographic primitive and how a customer verifies anchors without contacting the service approx_words: 1800 - name: Observability url: https://anchor-x402.com/trust/observability.html form: CloudWatch dashboard and status-page setup, what to expose, what consumers should monitor approx_words: 1000 compensating_controls_claimed: - MIT-licensed open-source codebase, auditable line by line - On-chain verifiability - anchors are readable from Base and Solana mainnet independently of the service - Deliberately stateless architecture with no per-customer PII at rest - Compliance inheritance from AWS infrastructure (Lambda, Secrets Manager, CloudWatch) disclosed_gaps: - No SOC 2, ISO 27001, PCI-DSS, HIPAA certification - stated as roadmap items, not blockers for the commodity tier - No cyber liability or tech E&O insurance - to be obtained when first contractually required - No formal written incident-response runbook - a disclosure email exists, the runbook is on the roadmap - No DPA template at the commodity tier scope_limitation_published: >- The threat model covers thirteen trust-relevant endpoints. The five LLM content endpoints (roast, oracle, tldr, aura, grade) are documented as explicitly out of scope - freeform text in, generated content out, no wallet-risk verdict and no compliance evidence. institutional_tier: status: available on request price: USD 499-5,000+/mo inclusions: - per-tenant authentication - signed MSA/DPA/SLA - WORM evidence vault on S3 Object Lock - GDPR Article 17 erasure reconciled with AML retention contact: hello@anchor-x402.com status_page: https://anchor-x402.betteruptime.com