generated: '2026-08-04' method: searched probe: true source: https://www.exo.inc/security-trust-center url: https://www.exo.inc/security-trust-center sections: - name: Security url: https://www.exo.inc/security-trust-center/security - name: Privacy url: https://www.exo.inc/security-trust-center/privacy - name: Resources url: https://www.exo.inc/security-trust-center/resource certifications: - HITRUST - SOC 2 Type II - ISO 27001 - ISO 27701 - HIPAA - GDPR practices: - Information security policies based on ISO/IEC 27001 - Secure software development lifecycle risk identification and mitigation program - Continuous monitoring of the cloud-hosted environment for anomalies and suspicious events - Ongoing penetration testing of cloud services and applications - AES 256-bit encryption in transit and at rest - Role-based access control (RBAC) and auto log-off certification_requests: https://support.exo.inc/hc/en-us vulnerability_disclosure: null notes: 'No published vulnerability disclosure policy, bug bounty program, or /.well-known/security.txt was found on any Exo host as of the probe date. Certifications are stated on the trust center; copies are provided on request through the support portal rather than self-served.' evidence: - source: https://www.exo.inc/security-trust-center/security keywords: - HITRUST - SOC 2 Type II - ISO 27001 - HIPAA - penetration testing http_status: 200 - source: https://www.exo.inc/exo-works/specs keywords: - HITRUST certified - HIPAA-compliant - SOC 2 TYPE II - ISO 27001 - ISO 27701 - GDPR http_status: 200