generated: '2026-08-05' method: searched source: https://trustandwill.com/security note: Trust & Will publishes no machine-readable API contract, so no standard below could be derived from a specification. Every entry is asserted only from the compliance and security posture the company publishes on its own security page. standards: - id: soc2-type-ii conforms: true evidence: 'Security page: "undergone Type 2 Service Organization Control 2 (SOC 2 Type II)" examination with independent CPA certification' source: https://trustandwill.com/security - id: hipaa conforms: true evidence: 'Security page: completed a Health Insurance Portability and Accountability Act examination' source: https://trustandwill.com/security - id: tls-1.2 conforms: true evidence: 'Security page: data in transit protected with TLS 1.2 and a DigiCert certificate; live TLS probe of trustandwill.com negotiated TLSv1.3' source: https://trustandwill.com/security - id: aes-256-at-rest conforms: true evidence: 'Security page: AES 256-bit encryption for data at rest' source: https://trustandwill.com/security - id: oauth2 conforms: false evidence: no published securitySchemes; no OAuth documentation found on any public host - id: openid-connect conforms: false evidence: /.well-known/openid-configuration returned 404 on trustandwill.com and api.trustandwill.com - id: rfc9457-problem-details conforms: false evidence: 'api.trustandwill.com returns a proprietary JSON error envelope ({"state":"error","error":{"message":"404_NOT_FOUND"}}) with content-type application/json, not application/problem+json' - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on every host; a security contact is published in prose at https://trustandwill.com/security instead - id: iso-27001 conforms: false evidence: not claimed on the published security page - id: pci-dss conforms: false evidence: not claimed on the published security page