generated: '2026-08-13'
method: searched
probe: true
source: https://security.oneshot.ai
url: https://security.oneshot.ai
platform: Vanta
title: OneShot.ai Trust Center
certifications: []
note: >-
OneShot operates a branded Vanta Trust Center at https://security.oneshot.ai. The host
is verified first-party by DNS: it CNAMEs to 66589c2f3a3cc20954b0df68.cname.vantatrust.com,
Vanta's trust-center delegation target, and the served document carries
OneShot.ai Trust Center with .
This is a real trust center, not the SPA false positive — the host exists only for this purpose.
NO CERTIFICATIONS ARE RECORDED because none are publicly readable: the trust-center content is
rendered client-side from a signed-operation GraphQL API, so the served HTML (4,530 bytes)
contains no framework or certification names, and Vanta trust centers gate document access
behind an access request. certifications: [] means "checked, nothing publicly readable",
not "none held". A future pass should re-check if OneShot enables the public overview.
evidence:
- source: https://security.oneshot.ai
http_status: 200
content_type: text/html
signal: title "OneShot.ai Trust Center"; canonical https://security.oneshot.ai
- source: dns
record: security.oneshot.ai CNAME 66589c2f3a3cc20954b0df68.cname.vantatrust.com
signal: dedicated Vanta trust-center delegation
related:
- type: gdpr-commitment
url: https://www.oneshot.ai/handlingdata
- type: data-processing-terms
url: https://www.oneshot.ai/data-processing
- type: privacy-policy
url: https://www.oneshot.ai/privacy-policy