generated: '2026-08-13' method: probed probe: true url: https://trust.chartbeat.com/ platform: Vanta Trust Center certifications: [] certifications_readable: false evidence: - source: https://trust.chartbeat.com/ http_status: 200 content_type: text/html signals: - 'Chartbeat Trust Center' - 'canonical: https://trust.chartbeat.com' - 'served by assets.vanta.com (Vanta trust-report bundle)' - 'data-slugid: lb7r37f2uhw2d0yatm89q4' - source: https://trust.chartbeat.com/graphql http_status: 400 note: >- The trust center renders entirely client-side from a signed GraphQL call. Anonymous POSTs are rejected with "Missing `signature` or `signedAt`", so the certification list, sub-processor list and document set are NOT machine-readable without a browser session. notes: - >- Chartbeat DOES operate a trust center at trust.chartbeat.com — the host resolves, returns 200 and is a genuine Vanta-hosted trust report page. That is the verified finding recorded here. - >- NO named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) could be read from any public Chartbeat surface. The trust center is JS-rendered and its data API requires a signed request; chartbeat.com/security/, /security-policy/ and /gdpr/ all return 404. certifications is therefore an honest empty list, not an assertion that Chartbeat holds none. - >- Because no certification could be evidenced, this file deliberately does NOT carry a Compliance claim. Only GDPR and CCPA are named in Chartbeat's own text, and only in the privacy policy — see conformance/. related: privacy_policy: https://chartbeat.com/privacy/ privacy_contact: privacy@chartbeat.com api_terms: https://chartbeat.com/apiterms/ vulnerability_disclosure: none-found