generated: '2026-08-23' method: probed source: https://trust.landbase.com/ description: >- Landbase operates a public trust center at trust.landbase.com, hosted on Vanta. It returned HTTP 200 with a real page (canonical https://trust.landbase.com, Landbase Trust Center, Vanta build 9de42673d566d80a3bb761a085c15754242c3e29, prod environment) on 2026-08-23. The trust center is NOT linked from the landbase.com navigation, footer, pricing page or documentation — it was found by probing the conventional trust. host, which means most visitors and every automated crawler will miss it. url: https://trust.landbase.com/ platform: Vanta http_status: 200 discoverable_from_site: false certifications: [] certifications_machine_readable: false certifications_note: >- The certification and subprocessor lists are rendered client-side by a Vanta React bundle (assets.vanta.com/static/index-trust-report-*.js) that fetches over GraphQL; the served HTML carries only meta tags and no cert names, and Vanta's own API returns 401 to anonymous callers. No certification is therefore recorded here. This is an absence of EVIDENCE, not evidence of absence — a human with a browser may well see SOC 2 or ISO 27001 listed. Because nothing could be verified, no `Compliance` pointer is emitted in apis.yml. security_txt: none — /.well-known/security.txt returns 404 on every Landbase host (see well-known/landbase-well-known.yml) vulnerability_disclosure: >- None found. No security.txt, no /security page, and no HackerOne / Bugcrowd / Intigriti program surfaced for landbase.com on 2026-08-23. There is no published route for a researcher to report a vulnerability except the general contact form. related_public_policies: - {name: Privacy Policy, url: https://www.landbase.com/legal/privacy-policy} - {name: Terms of Service, url: https://www.landbase.com/legal/terms-of-service} - {name: Google Limited Use Policy, url: https://www.landbase.com/google-limited-use-policy} data_processing_note: >- Landbase names third parties in its own pricing copy — contact enrichment is "routed through 20+ providers automatically, powered by BetterContact", with Bouncer performing email verification. For a B2B contact-data platform processing personal data at scale, that subprocessor disclosure and the trust center are the visible parts of the compliance posture; no DPA, subprocessor list or data-retention statement is reachable without JavaScript.