generated: '2026-08-15' method: searched probe: true source: https://trust.joincandidhealth.com/ name: Candid Health Trust Center description: >- Candid Health operates a Drata-hosted trust center at trust.joincandidhealth.com. It is provisioned and live but sits behind a Cloudflare bot challenge, so its contents could not be read anonymously — the certifications recorded below come from Candid's own newsroom posts, each naming the report, the period and the auditing firm, not from the trust page itself. url: https://trust.joincandidhealth.com/ platform: Drata platform_evidence: 'DNS: trust.joincandidhealth.com CNAME trust.cname.drata.com' readable_anonymously: false certifications: - name: SOC 2 Type 2 criteria: [Security, Availability, Confidentiality] period: 2025-01-15 to 2025-04-15 opinion: unqualified auditor: AssurancePoint, LLC source: https://candidhealth.com/blog/candid-health-successfully-completed-type-2-soc-2-examination-with-an-unqualified-opinion - name: SOC 2 Type 1 opinion: unqualified auditor: AssurancePoint, LLC source: https://candidhealth.com/blog/candid-health-successfully-completed-type-1-soc-2-examination-with-an-unqualified-opinion - name: SOC 1 Type 1 as_of: '2025-12-31' opinion: clean auditor: AssurancePoint, LLC scope: >- Claims and Payment Interface Processing, Invalid Claims and Interface Error Handling, Account Balances, Billing, Data Communications, Logical Access, Change Management. source: https://candidhealth.com/blog/candid-health-achieves-type-1-soc-1-certification-with-clean-auditor-opinion - name: HIPAA (Business Associate) basis: contractual — BAAs with customers; PHI prohibited in the Sandbox environment source: https://candidhealth.com/privacy-policy not_claimed: - ISO 27001 - HITRUST CSF - PCI DSS - FedRAMP report_access: self_serve_download: unknown note: >- Drata trust centers normally gate SOC reports behind an NDA click-through. Whether Candid's does could not be established without passing the bot challenge. x-evidence: - url: https://trust.joincandidhealth.com/ http_status: 403 detail: >- Cloudflare managed challenge (cf-mitigated: challenge, server: cloudflare). The host resolves, serves TLS with HSTS preload, and CNAMEs to trust.cname.drata.com — so the trust center exists and is provisioned; it is simply not machine-readable. - url: https://candidhealth.com/blog/candid-health-successfully-completed-type-2-soc-2-examination-with-an-unqualified-opinion http_status: 200 - url: https://candidhealth.com/blog/candid-health-achieves-type-1-soc-1-certification-with-clean-auditor-opinion http_status: 200 - dns: trust.joincandidhealth.com record: CNAME value: trust.cname.drata.com notes: - >- The trust center is on joincandidhealth.com while the marketing site and the audit announcements are on candidhealth.com. Both domains belong to Candid Health — the newer candidhealth.com Nuxt site links to app.joincandidhealth.com and the older joincandidhealth.com Webflow site links to candidhealth.com — but a buyer following the newer brand domain will not find the trust center, because nothing on candidhealth.com links to it. - >- No vulnerability disclosure program, bug bounty, or security.txt was found on any host, so no VulnerabilityDisclosure artifact is written and no Security pointer is emitted. For a HIPAA business associate handling PHI at this scale, a published disclosure channel is the most obvious missing piece of the security posture.