Does that vendor have SOC 2? Who processes their data? When did it change?

StackPosture consolidates the trust facts B2B SaaS vendors publish — certifications, subprocessors, data residency, incident disclosures — into one dated, sourced record. Free to use.

28
Vendors tracked
218
Facts on record
45
Changes logged

Recent changes

Vendors overwrite their subprocessor lists and trust pages. We keep the history.

2026-06-10
Airtable
Subprocessor list extracted from Airtable's published page (airtable.com/company/subprocessors, vendor-dated March 31, 2026): 22 third-party subprocessors (core infrastructure, in-product AI, and support/service providers) plus 3 Formagrid affiliates.
2026-06-10
Airtable
Verification pass: SOC 2 Type II, ISO 27001:2022 (public certificate PDF), ISO 27701, HIPAA, and TX-RAMP Level 2 confirmed against Airtable's trust page. Security page URL corrected to /company/trust-and-security; subprocessors list and DPA links added.
2026-06-10
Airtable
Vendor added to StackPosture — initial snapshot from published trust documentation. Verification pass pending.
2026-06-10
Anthropic
Subprocessor list extracted from Anthropic's trust center (trust.anthropic.com/subprocessors, fetched 2026-06-10): 18 subprocessors. Notable: three hyperscalers (GCP, AWS, Azure) plus Palantir Federal Cloud Service for Claude for Government, ElevenLabs for voice mode, and Brave Search/TurboPuffer powering web search.
2026-06-10
Anthropic
Vendor added with a verified initial snapshot: SOC 2 Type II, ISO 27001:2022, ISO/IEC 42001:2023, and HIPAA BAA availability confirmed against Anthropic's Privacy Center certification article (fetched 2026-06-10). DPA confirmed at anthropic.com/legal/data-processing-addendum. Trust portal (trust.anthropic.com) is JS-rendered — Vanta-hosted; subprocessor list extraction pending.
2026-06-10
Asana
Verification pass: SOC 2 Type II, ISO 27001:2022 (plus 27017/27018/27701), HIPAA, and CSA STAR Level 1 confirmed against Asana's trust page. Status page and EU/AU/JP data residency recorded; trust center corrected to security.asana.com.
2026-06-10
Asana
Vendor added to StackPosture — initial snapshot from published trust documentation. Verification pass pending.
2026-06-10
Atlassian
Vendor added with a verified initial snapshot: SOC 2 (Coalfire-audited, cloud products), ISO/IEC 27001:2022 with ISO 27018 extension, and FedRAMP Moderate (Jira, Confluence, JSM) each confirmed against Atlassian's dedicated compliance resource pages (fetched 2026-06-10). PCI DSS kept as reported only — the logo appears on the compliance page without a linked resource. The full 34-item compliance resource list is JS-filtered; remaining certifications can be verified individually later.

View the full changelog →

How it works

We collect trust facts from vendor-published documentation and public regulatory records — never from scanning, probing, or anything a vendor didn't publish themselves.
Every fact carries a source link and a date. Facts we haven't yet verified against a primary source are clearly marked as pending.
We re-check vendors on a schedule and log every change — so you can see not just what a vendor's posture is, but how it has moved.

Missing a vendor?

Tell us which vendor you're reviewing and we'll add them, usually within a few days: hello@stackposture.com