generated: '2026-08-14' method: searched source: https://www.stedi.com/docs/healthcare/trust-center trust_center: url: https://trust.stedi.com/ http_status: 200 platform: Vanta platform_evidence: The page loads assets.vanta.com trust-report bundles and renders entirely client-side; the served HTML carries only the title "Stedi Trust Center". machine_readable: false machine_readable_note: The trust center is a JS-rendered Vanta report. Nothing on it is readable without executing JavaScript, so the certifications below are recorded from Stedi's own documentation page, which names them in plain text. certifications: - name: SOC 2 Type II status: published evidence: Named on https://www.stedi.com/docs/healthcare/trust-center as a certification available through the trust center. - name: HIPAA status: published evidence: Named on https://www.stedi.com/docs/healthcare/trust-center alongside a HIPAA compliance policy. documents_available: - Certifications (SOC 2 Type II, HIPAA) - HIPAA compliance policy - Security and privacy controls - Data management and access control policies not_found: - ISO 27001 - PCI DSS - HITRUST - FedRAMP - Published penetration test summary - Public subprocessor list note: > Absence above means "not named on Stedi's public trust documentation as read on 2026-08-14", not "does not hold". The Vanta report itself may list more; it cannot be read without a browser. related: vulnerability_disclosure: security/stedi-vulnerability-disclosure.yml domain_security: security/stedi-domain-security.yml privacy_notice: https://legal.stedi.com/legal/privacy-notice-b91ef9d6 service_terms: https://www.stedi.com/terms baa_note: Stedi's documentation repeatedly instructs customers to have a BAA in place with third-party tools (Postman, Claude, ChatGPT) before routing PHI through them, which implies Stedi executes BAAs with its own customers, but no public BAA document was found.