generated: '2026-08-12' method: probed source: https://trust.zefr.com/ present: true platform: Drata url: https://trust.zefr.com/ note: >- Zefr operates a trust center. It is provisioned on a Zefr-controlled hostname (trust.zefr.com) that CNAMEs to trust.cname.drata.com — Drata's hosted Trust Center product — and the page is publicly indexed under the title "Trust Center | Powered by Drata". The document itself could NOT be read: trust.zefr.com sits behind a Cloudflare bot challenge that answers HTTP 403 with a "Just a moment..." interstitial to every non-browser client, including a browser-UA curl and the fetch tool. We do not evade challenges. Presence is therefore asserted; contents are not. evidence: - kind: dns record: CNAME name: trust.zefr.com value: trust.cname.drata.com note: Drata Trust Center hosted endpoint on a Zefr-controlled hostname. - kind: http url: https://trust.zefr.com/ status: 403 content_type: text/html; charset=UTF-8 body_signature: Cloudflare managed challenge ("Just a moment...", challenges.cloudflare.com CSP) - kind: http url: https://trust.zefr.com/api/trust-center/zefr status: 403 - kind: search-index query: site:trust.zefr.com result: 'Indexed page title: "Trust Center | Powered by Drata"' certifications: read: false published: [] note: >- NO certification is asserted. SOC 2, ISO 27001, PCI DSS, HIPAA and similar are commonly surfaced by Drata trust centers, but none was read from Zefr's, so none is recorded. A reader who needs Zefr's certification list must open trust.zefr.com in a browser. subprocessors: read: false documents_on_request: read: false coverage: state: blocked reason: bot-challenge detail: >- trust.zefr.com returns a Cloudflare managed challenge (HTTP 403) to every non-browser client, so the trust center's certification list could not be read.