generated: '2026-08-14' method: searched source: https://comulate.com/security standards: - id: soc2-type-ii conforms: true evidence: >- Security page states "Our Information Security Program follows the criteria set forth by the SOC 2 Framework" and displays a SOC 2 Type II badge. - id: soc1-type-ii conforms: true evidence: SOC 1 Type II logo displayed on the security page - id: tls-in-transit conforms: true evidence: >- Security page states "Our applications encrypt in transit with TLS/SSL only"; probed independently — comulate.com, app.comulate.com and api.comulate.com all negotiate TLSv1.3 and all send HSTS. - id: annual-penetration-test conforms: true evidence: >- Security page states "We perform an independent third-party penetration at least annually to ensure that the security posture of our services is uncompromised." - id: iso27001 conforms: false - id: hipaa conforms: false - id: pci-dss conforms: false - id: fedramp conforms: false compliance_program: soc2: true soc1: true iso27001: false hipaa: false pci_dss: false fedramp: false gdpr_claimed: false notes: >- Derived from published security-page claims plus independent TLS/DNS probes only. No OpenAPI is available to assert cross-cutting API standards (oauth2/oidc/rfc9457/ pagination/idempotency); those are UNKNOWN, not false, and are deliberately omitted rather than recorded as non-conformant. The one API-layer fact observable from outside is that api.comulate.com returns a bare HTTP 401 with the plain-text body "Unauthorized" and no WWW-Authenticate challenge — so it is not an RFC 9457 problem+json error surface and not an OAuth-discoverable resource server, but that is a single gated endpoint, not a measured contract.