generated: '2026-08-26' method: searched probe: true source: https://trust.oncolens.com/ url: https://trust.oncolens.com/ name: OncoLens Trust Center description: >- OncoLens operates a real, publicly reachable SafeBase trust center on its own domain. It is the single most substantive machine-adjacent artifact the company publishes — 30+ security controls marked at full maturity, SOC 2 and HIPAA compliance entries, and gated report downloads. It carries no API, developer, or interoperability content. platform: SafeBase platform_evidence: 'DNS CNAME: trust.oncolens.com -> oncolens.portals.safebase.io' plan: free custom_domain: trust.oncolens.com primary_domain: oncolens.com evidence: - source: https://trust.oncolens.com/ http_status: 200 content_type: text/html bytes: 236247 method: >- Read from the embedded __NEXT_DATA__ payload on the rendered page. NOTE for re-runs: a curl request sending a full desktop-browser User-Agent is answered with a Cloudflare interactive challenge (HTTP 403, "Just a moment..."); a plain library User-Agent is served the page (HTTP 200). The 403 is a bot-fingerprint edge policy, not an access wall. keywords: [soc 2, hipaa, trust center, safebase] certifications: - name: SOC 2 status: published maturity: full report_available: true report_access: gated report_note: >- A "SOC 2 Report" document entry is enabled and carries attached files, but the files are not shared publicly (isShared false) — access is request/NDA gated through SafeBase. Report type (Type I vs Type II), auditor and period are not disclosed anonymously. - name: HIPAA status: published maturity: full report_available: false report_note: >- The HIPAA compliance entry is enabled; the separate "HIPAA Report" document entry is NOT enabled on this trust center. - name: SOC 3 status: not-published note: The "SOC 3 Report" item exists in the SafeBase template but is disabled. - name: ISO 27001 status: not-published - name: HITRUST status: not-published note: >- Notable for a US oncology data platform — HITRUST CSF is the certification most often requested of healthcare vendors handling PHI, and it is absent. - name: PCI DSS status: not-published note: Not applicable; OncoLens is not a payment surface. - name: FedRAMP status: not-published security_program: penetration_testing: published: true maturity: full report_access: gated controls_published: 38 controls_at_full_maturity: 33 controls: - Access Monitoring - BC/DR - Cloud Workload Protection - Code of Ethics - Critical Dependence - Cyber Insurance - DNS Filtering - Data Access Level - Data Backups - Data Erasure - Data Loss Prevention - Data Privacy Officer - Disk Encryption - Effective Board Oversight - Employee Privacy Training - Encryption-at-rest - Encryption-in-transit - Endpoint Detection & Response - Hosting - Impact Level - Infrastructure Security - Pentest Report - Physical Security - Secure Development Training - Security Information and Event Management - Separate Production Environment - Software Bill of Materials (SBOM) - Software Development Lifecycle - Third Party Dependence - Threat Detection - Virtual Private Cloud - Vulnerability & Patch Management - Web Application Firewall - Zero Trust subprocessors_published: true gaps: - >- securityMailbox is null on the SafeBase org record, and no security.txt is served on any OncoLens host — there is no published vulnerability-disclosure contact or policy despite a full pentest program being advertised. - >- The trust center's own "Terms of Service" and "Privacy Policy" document slots are disabled, and no terms-of-service page exists on www.oncolens.com (probed /terms/, /terms-of-use/, /terms-of-service/, /terms-and-conditions/ — all 404). - >- No API, integration, or interoperability content appears anywhere in the trust center. checked: '2026-08-26'