name: Walnut Trust Center description: >- Walnut runs a dedicated trust center at security.walnut.io, linked from its public Legal Hub. The portal is a HyperComply-hosted single-page application: it answers HTTP 200 but renders its content client-side through an Apollo GraphQL client, so the certification list, sub-processor register and document requests cannot be read without executing JavaScript. The certifications recorded below are therefore taken from Walnut's own machine-readable and human-readable pages, not scraped from the portal shell. generated: '2026-08-13' method: searched source: https://security.walnut.io/ checked: '2026-08-13' trust_center: url: https://security.walnut.io/ http_status: 200 platform: HyperComply machine_readable: false render: client-side (JavaScript required; "You need to enable JavaScript to run this app.") discovered_via: https://www.walnut.io/legal-hub/ gated: >- Document access on a HyperComply portal typically requires a request or NDA. Not tested — no request was submitted. certifications: - name: SOC 2 Type II status: certified scope: not published publicly evidence: - url: https://www.walnut.io/llms.txt quote: '"**Compliance**: SOC 2 Type II, GDPR."' status: 200 - url: https://www.walnut.io/product/enterprise/ quote: '"We''re SOC 2 certified, which means you can share your demos with the peace of mind that your customers'' data is safe."' status: 200 report_available: >- Not published openly. A SOC 2 report would be requested through security.walnut.io or the Walnut account team. - name: GDPR status: compliance program type: regulation evidence: - url: https://www.walnut.io/llms.txt status: 200 - url: https://www.walnut.io/dpa/ status: 200 note: Data Processing Agreement published on the Legal Hub. - name: CCPA status: compliance program type: regulation evidence: - url: https://www.walnut.io/ccpa/ status: 200 note: CCPA Notice published on the Legal Hub. not_claimed: - ISO 27001 - PCI DSS - HIPAA - FedRAMP - TISAX - CSA STAR not_claimed_note: >- No claim to any of these was found on walnut.io, help.walnut.io or in Walnut's llms.txt. Their absence here means "not found", not "does not hold" — the trust center itself is JS-rendered and may list more. legal_documents: - name: Master Services Agreement url: https://www.walnut.io/msa/ status: 200 - name: Data Processing Agreement url: https://www.walnut.io/dpa/ status: 200 - name: Privacy Policy url: https://www.walnut.io/privacy/ status: 200 - name: Acceptable Use Policy url: https://www.walnut.io/acceptable-use-policy/ status: 200 - name: AI Terms & Conditions url: https://www.walnut.io/ai-terms-conditions/ status: 200 - name: CCPA Notice url: https://www.walnut.io/ccpa/ status: 200 - name: Cookies List url: https://www.walnut.io/cookies-list/ status: 200 - name: Legal Hub (index) url: https://www.walnut.io/legal-hub/ status: 200 enterprise_security_features: - SSO (SAML) — Accelerate and Scale plans - SCIM provisioning — Accelerate and Scale plans - Role-based access control (Account Owner, Admin, Editor, Presenter, Collaborator) - Access gates and access codes on demos, Playlists and Deal Rooms - Allow and block lists for demo viewers - White-labeled / custom-domain demo delivery enterprise_security_features_source: https://www.walnut.io/product/enterprise/ gaps: - >- No security.txt at /.well-known/security.txt on any Walnut host, so there is no machine- discoverable route from an API host to this trust center. See well-known/walnut-well-known.yml. - >- No public sub-processor list, penetration-test summary, or uptime/SLA commitment reachable without JavaScript. - No published vulnerability disclosure policy or bug bounty program (see notes below). vulnerability_disclosure: found: false note: >- Probed 2026-08-13. No /.well-known/security.txt on www.walnut.io, help.walnut.io, app.teamwalnut.com, customer-api.teamwalnut.com or api.teamwalnut.com; no HackerOne, Bugcrowd or Intigriti program found; no /security or /responsible-disclosure page on walnut.io (https://www.walnut.io/security returned 404). A disclosure policy may exist behind the JS-rendered trust center, but nothing is publicly readable, so no security/walnut-vulnerability-disclosure.yml artifact and no `Security` pointer is emitted.