generated: '2026-08-12' method: searched probe: true source: https://trust.feedly.com/ — fetched 2026-08-12, HTTP 200 url: https://trust.feedly.com/ description: >- Feedly, Inc. runs a public trust portal (Simple Trust Portal). The landing page is public and names its document set; the reports themselves are access-gated behind a "Request Access to All Documents" form. The certifications are therefore publicly ASSERTED even though the evidence is gated. platform: Simple Trust Portal public_landing_page: true documents_gated: true certifications: - name: SOC 2 Type 1 document_title: Feedly 2026 SOC 2 Type 1 Report year: 2026 access: request required evidence: >- Listed in the trust portal document manifest with description "Feedly Inc. SOC 2 Type 1 Report 2026" and storage filename Feedly-2026-SOC-2-Type-1-Report.pdf. - name: SOC 2 Type 2 document_title: Feedly 2026 SOC 2 Type 2 Report year: 2026 access: request required evidence: >- Listed in the trust portal document manifest; storage filename Feedly-2026-SOC_2_Type_2_Report.pdf. document_sections: - name: Public Documents note: >- "All documents in this section are public and don't need requests" — the portal renders a public section, but the two SOC 2 reports sit under the confidential grouping. - name: Confidential Documents note: Requires an access request. not_listed: note: >- Absence recorded as data. No document in the portal manifest names any of the following. frameworks: - ISO 27001 - ISO 27017 - ISO 27018 - PCI DSS - HIPAA - FedRAMP - CSA STAR - FIPS 140 - TISAX related_pages: privacy_policy: https://feedly.com/legal/privacy terms_of_service: https://feedly.com/legal/terms api_terms: https://developers.feedly.com/reference/feedly-api-terms-of-service status_page: https://status.feedly.com/ x-evidence: - source: https://trust.feedly.com/ http_status: 200 fetched: '2026-08-12' keywords: [trust portal, SOC 2 Type 1, SOC 2 Type 2, confidential documents, request access] note_on_automated_probe: >- 0-working/probe-security-programs.py reported trust=none for this provider. That is a false negative: the portal is a JavaScript-rendered single-page app whose document manifest is embedded in a JSON blob rather than in visible HTML text, so the probe's ≥2-keyword body check does not fire. The certifications above were read out of that embedded manifest in the page source. This artifact is therefore method: searched, not probed-only.