generated: '2026-08-26' method: searched probe: true source: https://trust.mosaic.tech/ url: https://trust.mosaic.tech/ title: Mosaic.tech Trust Center platform: Conveyor http_status: 200 note: >- The Trust Center is the one Mosaic-branded public surface still standing after the HiBob acquisition. trust.mosaic.tech resolves independently (it does NOT redirect to hibob.com, unlike every other mosaic.tech path) and still serves Mosaic-named documents. Content read verbatim from the live page on 2026-08-26. certifications: - name: SOC 2 Type II status: held badge: true auditor: Sensiba San Filippo, LLP (SSF) evidence: >- "SOC 2 Type II" badge on the Trust Center; announcement dated 2023-03-21 "Mosaic Completes 2023 SOC 2 Type II Audit" stating the report "didn't have any noted exceptions and therefore was issued with a 'clean' audit opinion"; featured document "Mosaic Finance SOC2 Type II Report 2025". documents: count: 3 featured: - name: Mosaic Finance SOC2 Type II Report 2025 access: gated - name: Mosaic Data Processing Addendum (DPA) access: gated - name: Mosaic 2024 Penetration Test access: gated note: >- Documents are listed publicly but require a "Get Access" request through Conveyor; the documents themselves were not fetched and are not reproduced here. knowledge_base: faq_count: 167 categories: - {name: Overview, answers: 7} - {name: Access Management, answers: 13} - {name: Application and Data Security, answers: 41} - {name: Cloud Security, answers: 25} - {name: Continuity and Disaster Recovery, answers: 7} - {name: Device Management, answers: 21} - {name: Incident Management, answers: 23} - {name: Personnel Security, answers: 24} - {name: Privacy, answers: 14} - {name: Risk and Vulnerability Management, answers: 35} - {name: Security Governance, answers: 47} - {name: Vendor Management, answers: 9} summary_claims: - One or more annual third-party audit(s) - Has a formal mobile device management (MDM) program - Annual third-party penetration testing - Has a disaster recovery plan - Will enter into a DPA - Has a status page security_contact: named_role: Lead Security Engineer (Josh Sussman, per the Trust Center philosophy section) email: null note: No security contact address, vulnerability disclosure policy, or bug-bounty program is published. staleness: note: >- The Trust Center carries un-refreshed content from the pre-acquisition era — a "Coming Soon" block still advertising "Next Penetration Test: Q4'23" and "Next Security Awareness & Training: Q3'23". The featured SOC 2 report is dated 2025, so the page is partially maintained, but the forward-looking section has not been updated in roughly three years.