generated: '2026-08-12' method: searched probe: true probe_note: >- 0-working/probe-security-programs.py returned trust=none because trust.epsilon3.io is a Vanta-hosted single-page app - the served HTML is 7,201 bytes containing only the title "Epsilon3 Trust Center", with every certification rendered client-side, so the probe's keyword threshold could not be met. The trust center is nonetheless real and reachable (HTTP 200), and Epsilon3's own security page names the certifications server-side. This file is written from that server-side evidence, not from the JS-rendered page. url: https://trust.epsilon3.io/ http_status: 200 provider: Vanta content_rendering: client-side (JS); no certification text in the served HTML source_page: https://www.epsilon3.io/security certifications: - SOC 2 Type II - FedRAMP High Authorization - NIST SP 800-171 - DFARS 252.204-7012 - CMMC - ITAR - EAR controls: - {control: encryption-in-transit, detail: TLS 1.3} - {control: encryption-at-rest, detail: AES-256} - {control: access-control, detail: Role-Based Access Control to restrict access to classified or sensitive data} - {control: identity, detail: Single Sign-On (SSO) and Multi-Factor Authentication (MFA)} - {control: auditability, detail: one-click audit bundle export for internal reviews and regulatory audits} - {control: continuity, detail: dual-region clouds plus an offline mode} hosting: AWS GovCloud deployment_models: - compliant cloud (AWS GovCloud, FedRAMP High) - on-premises - hybrid and international - classified environments ai_data_posture: >- AI features are opt-in and under user control; Epsilon3 states its contracts prevent customer data being used to train models. evidence: - {source: 'https://www.epsilon3.io/security', http_status: 200, keywords: [SOC 2 Type II, FedRAMP High, NIST 800-171, DFARS 252.204-7012, CMMC, ITAR, EAR, AWS GovCloud, TLS 1.3, AES-256, Vanta trust report]} - {source: 'https://trust.epsilon3.io/', http_status: 200, keywords: [Epsilon3 Trust Center], note: title only - remainder is JS-rendered} gaps: - No public vulnerability disclosure or responsible disclosure policy. The strings "disclosure", "bug bounty", "security@" and "penetration" do not appear on www.epsilon3.io/security, no /.well-known/security.txt is served on any Epsilon3 host, and no HackerOne/Bugcrowd/Intigriti program was found. No Security pointer is claimed in apis.yml as a result. - Certification reports themselves are behind the Vanta trust center, which requires interaction to reach; nothing is downloadable anonymously. - ISO 27001 is not among the named certifications.