generated: '2026-08-26' method: searched source: https://safe.security/security/ name: SAFE Security trust center url: https://safe.security/security/ http_status: 200 dedicated_trust_portal: false note: >- SAFE has no trust portal in the Vanta/Drata/SafeBase sense - trust.safe.security does not resolve (DNS NXDOMAIN) and there is no evidence-request or NDA-gated document exchange. What exists is a single public Security Statement page on the marketing site, plus one downloadable report. It is unusually substantive for a marketing page and it names the certifications explicitly, but the artefacts behind them are not published apart from the SOC 3. certifications: - name: SOC 2 Type 2 public_report: false - name: SOC 3 public_report: true url: https://safe.security/wp-content/uploads/safe-security-soc3-report-2026.pdf http_status: 200 content_type: application/pdf note: Downloadable with no form, no login and no NDA - the strongest single piece of published assurance evidence SAFE offers. - name: ISO 27001:2013 public_report: false - name: ISO 9001:2015 public_report: false - name: TX-RAMP public_report: false note: The Texas state cloud authorization programme, not federal FedRAMP. security_controls: hosting: AWS, customer-selected region at tenant signup data_residency_doc: https://docs.safe.security/docs/data-residency-in-safe encryption_in_transit: TLS 1.2 over public networks encryption_at_rest: AES-256 via AWS KMS customer_managed_keys: true cmk_note: Customers may supply their own AWS KMS key, in which case key generation and management access sit entirely with the customer. byoa: true byoa_note: >- "Bring Your Own Account" customers run SAFE in their own AWS account and get CloudWatch and CloudTrail log access for SIEM ingestion. tenancy: per-tenant, per-region observed_posture: source: security/safe-security-domain-security.yml tls: TLSv1.3 negotiated on safe.security, docs.safe.security and us.safeone.ai hsts: enabled on all three hosts dnssec: safe.security: true safeone.ai: false caa: none published on either domain spf: present on both domains dmarc: present on both domains, policy quarantine note: >- Worth reading against the certifications: safeone.ai - the domain the PRODUCT and both APIs are served from - has no DNSSEC, neither domain publishes CAA records, and both DMARC policies stop at quarantine rather than reject. These are exactly the outside-in controls SAFE's own TPRM product assesses third parties on. evidence: - url: https://safe.security/security/ status: 200 - url: https://safe.security/wp-content/uploads/safe-security-soc3-report-2026.pdf status: 200 - url: https://trust.safe.security/ status: null note: DNS does not resolve gaps_for_provider: - No trust portal; certifications are prose rather than requestable artefacts. - No FedRAMP, HIPAA or PCI DSS attestation published despite healthcare and financial verticals being marketed. - No subprocessor list published. - CAA records absent on both domains; DNSSEC absent on safeone.ai.