generated: '2026-08-09' method: probed source: https://trust.ceros.com/ provider: Ceros trust_center: url: https://trust.ceros.com/ platform: Vanta slug_id: 9ldxavzelo7uuybddceynn title: Ceros Trust Center tagline: >- "Security is built into the fabric of our products, team, infrastructure, and processes, so you can rest assured your data is safeguarded." x-evidence: fetched: '2026-08-09' url: https://trust.ceros.com/ http_status: 200 content_type: text/html bytes: 6622 certifications: [] certifications_note: >- NONE RECORDED, DELIBERATELY. The trust centre is a client-side Vanta SPA: the served HTML is a 6,622-byte shell carrying only the title and description, and every /api/* path under trust.ceros.com and app.vanta.com returns that same shell with a 200 rather than JSON — a soft-404, not data. No certification, attestation or audit report name was readable, so none is asserted here and no `Compliance` pointer is emitted in apis.yml. A trust centre that only renders in a browser is not a machine-readable compliance posture. control_probe: - url: https://trust.ceros.com/api/trust-page http_status: 200 bytes: 6402 verdict: SPA catch-all — identical shell, no JSON. - url: https://app.vanta.com/api/trust-page/9ldxavzelo7uuybddceynn http_status: 200 bytes: 29762 verdict: SPA catch-all. - url: https://api.vanta.com/trust/9ldxavzelo7uuybddceynn http_status: 401 readable_security_claims: source: https://www.ceros.com/technical-faq-s/ claims: - topic: TLS claim: >- "Secure TLS connections are used for all logged in sessions. We support secure connections for published Experience content but do not force it." - topic: SSO claim: >- "Ceros supports both password authentication and enterprise SSO using identity standards: LDAP, SAML, and OAuth." - topic: Access control claim: Account Owner and Member roles, with project-level access restrictions available. - topic: Hosting claim: >- Published experience content, media and assets served from S3 with CloudFront and Cloudflare in front as CDNs; Admin and Studio served from Ceros-managed AWS EC2 instances. note: >- This readable page names no certification either — no SOC 2, ISO 27001, PCI, HIPAA, FedRAMP, GDPR or CCPA claim appears on it. vulnerability_disclosure: published: false probes: - url: https://www.ceros.com/.well-known/security.txt http_status: 404 - url: https://developers.ceros.com/.well-known/security.txt http_status: 404 - url: https://rest.ceros.com/.well-known/security.txt http_status: 404 - url: https://www.ceros.com/security/ http_status: 404 false_positive_avoided: url: https://educate.ceros.com/.well-known/security.txt http_status: 200 reason: >- Served from a Ceros CNAME but it is Intercom's policy — Contact bugcrowd.com/intercom, Canonical https://app.intercom.com/.well-known/security.txt. It is the help-centre vendor's programme, not Ceros's, so it is NOT credited to Ceros and no `Security` pointer is emitted. only_published_security_address: value: mailto:domains@ceros.com source: 'CAA record iodef for ceros.com' note: A certificate-authority incident-reporting address, not a vulnerability disclosure contact. remedy: >- Publish /.well-known/security.txt on www.ceros.com and rest.ceros.com with a Contact and Policy, per RFC 9116. Ceros already runs a Vanta trust centre — the disclosure channel is the one thing it does not expose at a fetchable URL.