generated: '2026-08-26' method: probed source: https://trust.ppro.com/ present: true url: https://trust.ppro.com/ title: PPRO Trust Center vendor: Vanta http_status: 200 content_type: text/html x-evidence: fetched: '2026-08-26' url: https://trust.ppro.com/ http_status: 200 content_location: https://assets.vanta.com/static/index-trust-report.99d0d39bb4af803452373227c024e486137353b7.html note: Served through Cloudflare from Vanta's static trust-report bundle; page title is "PPRO Trust Center". certifications: [] certifications_note: >- ZERO certifications were read. The Vanta trust report renders entirely client-side and its backing API (api.vanta.com) returns 401 Unauthorized to an anonymous caller, so the certification list, subprocessor list and policy documents are all behind a rendering/authorization wall. PPRO's public developer hub names no certification either — the only compliance language there is a PCI SCOPE statement about the integrator's own footprint when using the Drop-in Checkout, which is not a PPRO attestation. Recording an empty list is the honest outcome; asserting SOC 2 / ISO 27001 / PCI DSS Level 1 here would be fabrication. follow_up: >- A named-certification claim would need either an authenticated Vanta trust-report request or a PPRO-published compliance page. Worth re-probing on the next pass.