generated: '2026-08-26' method: searched source: https://trust.semprehealth.com/ name: Sempre Health Trust Center description: 'Sempre Health runs a hosted trust center at trust.semprehealth.com, built on Vanta. The page was fetched successfully (HTTP 200) and is genuinely Sempre Health''s - , Sempre Health Trust Center, and a description naming Sempre Health''s prescription savings product. The certification list itself is rendered client-side from Vanta''s GraphQL API, which rejects anonymous reads (POST https://app.vanta.com/graphql -> HTTP 400 "Missing `signature` or `signedAt`"), so the documents and control list published inside the trust center could not be enumerated without a browser session. The one certification Sempre Health names in plain text on its own site is HITRUST.' trust_center: url: https://trust.semprehealth.com/ platform: Vanta status: live http_status: 200 content_type: text/html machine_readable: false note: Vanta trust-report SPA; contents load from a signed GraphQL endpoint and are not anonymously enumerable. certifications: - name: HITRUST evidence: https://www.semprehealth.com/health-plans/ quote: Sempre signs a BAA & MSA and is HITRUST certified. method: searched - name: HIPAA Business Associate Agreement (BAA) evidence: https://www.semprehealth.com/health-plans/ quote: Sempre signs a BAA & MSA and is HITRUST certified. method: searched not_found: - No SOC 2, ISO 27001, PCI DSS or FedRAMP claim is made anywhere on the public site. - No security.txt, /security page, or public bug bounty could be found (see security/sempre-health-vulnerability-disclosure.yml). x-evidence: - url: https://trust.semprehealth.com/ status: 200 fetched: '2026-08-26' - url: https://www.semprehealth.com/health-plans/ status: 200 fetched: '2026-08-26' - url: https://app.vanta.com/graphql status: 400 fetched: '2026-08-26' note: anonymous introspection rejected - "Missing `signature` or `signedAt`"