generated: '2026-08-06'
method: probed
probe: true
url: https://trust.atera.com/
platform: Vanta Trust Center (EU tenant — app.eu.vanta.com)
verified: true
machine_readable: false
notes: >-
trust.atera.com resolves and returns HTTP 200 with
Atera Trust Center
and a canonical link to itself, served as a Vanta-hosted single-page app. The page
content — the certification list, subprocessors and document requests — is rendered
client-side from a GraphQL endpoint that rejects unsigned requests
("Missing `signature` or `signedAt`", HTTP 400), so the certification roster could
NOT be read anonymously. Only certifications with an independent first-party source
are recorded as verified below; the rest are deliberately left unasserted rather than
copied from secondhand summaries.
certifications_verified:
- name: SOC 2 Type 2
source: https://community.atera.com/discussion/335/were-officially-soc-2-type-2-certified
source_type: Atera admin announcement on Atera's own community
announced: '2024-01'
certifications_unverified:
note: >-
Third-party summaries of trust.atera.com list ISO/IEC 27001, 27017, 27018, 27032 and
42001, HIPAA, GDPR and CCPA alongside SOC 2 Type 2. These could not be confirmed
against a page this pipeline could actually read, so they are recorded as unverified
rather than claimed.
subprocessors:
url: https://trust.atera.com/subprocessors
status: 200
readable: false
note: SPA route; returns the same client-rendered shell.
evidence:
- {source: 'https://trust.atera.com/', http_status: 200, title: 'Atera Trust Center', vendor: vanta, fetched: '2026-08-06'}
- {source: 'https://trust.atera.com/graphql', http_status: 400, error: 'Missing `signature` or `signedAt`', fetched: '2026-08-06'}
- {source: 'https://community.atera.com/discussion/335/were-officially-soc-2-type-2-certified', http_status: 200, fetched: '2026-08-06'}
gaps:
- >-
The trust center is not machine-readable: no JSON, no feed, and a request-signed
GraphQL API. An agent evaluating Atera's compliance posture cannot read it.
- No /.well-known/security.txt on any Atera host (see well-known/atera-well-known.yml).
- No published vulnerability disclosure policy or bug bounty program was found.