generated: '2026-08-17' method: searched probe: true source: https://trust.koyeb.com/ provider: Koyeb providerId: koyeb url: https://trust.koyeb.com/ http_status: 200 platform: Vanta platform_evidence: >- The document root carries data-signature-manifest-url="https://assets.vanta.com/static/vite/signature-manifest...", data-api-version-endpoint-url="https://static.vanta.com/api/version", assets served from assets.vanta.com, and og:image at https://app.eu.vanta.com/doc?s=... — a Vanta Trust Center on the EU instance. title: Koyeb Trust Center canonical: https://trust.koyeb.com certifications: - SOC 2 - ISO 27001 certification_source: >- Named on Koyeb's own pricing page as an Enterprise-tier entitlement — verbatim "ISO27001 and SOC2 Certifications" (https://www.koyeb.com/pricing). NOT read off the Trust Center itself; see the caveat. caveat: >- trust.koyeb.com is a client-rendered Vanta single-page app. The server response contains only the shell plus the page title and canonical URL — no certification list, no subprocessor list, no document list, no security-contact address is present in the HTML. Vanta retired its public GraphQL API (api.eu.vanta.com returns HTTP 410 "The GraphQL API is no longer available in favor of the Vanta REST API"), and /api/trust-report, /sitemap.xml and /robots.txt all return the same SPA shell. So the trust center is REAL and VERIFIED to exist, its contents are NOT machine-readable, and the two certifications above are corroborated from the pricing page rather than inspected in the Trust Center. machine_readable: false documents_enumerable: false related: data_processing_agreement: https://www.koyeb.com/docs/legal/data-processing-agreement master_service_agreement: https://www.koyeb.com/docs/legal/msa service_level_agreement: https://www.koyeb.com/docs/legal/sla terms_of_service: https://www.koyeb.com/docs/legal/terms vulnerability_disclosure: published: false note: >- No security/koyeb-vulnerability-disclosure.yml was written on this pass and no `Security` pointer was wired into apis.yml, because nothing was found: /.well-known/security.txt 404s on every host, koyeb.com/security and koyeb.com/docs/security both 404, no HackerOne / Bugcrowd / Intigriti program was found, and no security@koyeb.com address is published anywhere machine-readable. Running a Vanta Trust Center without an RFC 9116 security.txt or a reachable disclosure page is the gap. evidence: - {source: 'https://trust.koyeb.com/', http_status: 200, checked: '2026-08-17', keywords: [Koyeb Trust Center, vanta, Trust Security Compliance Automation]} - {source: 'https://www.koyeb.com/pricing', http_status: 200, checked: '2026-08-17', quote: 'ISO27001 and SOC2 Certifications'} - {source: 'https://www.koyeb.com/docs/legal/data-processing-agreement', http_status: 200, checked: '2026-08-17'} - {source: 'https://www.koyeb.com/.well-known/security.txt', http_status: 404, checked: '2026-08-17'} - {source: 'https://www.koyeb.com/security', http_status: 404, checked: '2026-08-17'} recommendations_for_provider: - Publish /.well-known/security.txt on www.koyeb.com with Contact and Policy fields pointing at the Trust Center. - Expose the certification list on a server-rendered page (or the Vanta REST API) so it can be read without a browser session. maintainers: - FN: Kin Lane email: kin@apievangelist.com