Does that vendor have SOC 2? Who processes their data? When did it change?
StackPosture consolidates the trust facts B2B SaaS vendors publish — certifications, subprocessors, data residency, incident disclosures — into one dated, sourced record. Free to use.
/
28
Vendors tracked
218
Facts on record
45
Changes logged
Recent changes
Vendors overwrite their subprocessor lists and trust pages. We keep the history.
2026-06-10
Airtable
Subprocessor list extracted from Airtable's published page (airtable.com/company/subprocessors, vendor-dated March 31, 2026): 22 third-party subprocessors (core infrastructure, in-product AI, and support/service providers) plus 3 Formagrid affiliates.
2026-06-10
Airtable
Verification pass: SOC 2 Type II, ISO 27001:2022 (public certificate PDF), ISO 27701, HIPAA, and TX-RAMP Level 2 confirmed against Airtable's trust page. Security page URL corrected to /company/trust-and-security; subprocessors list and DPA links added.
2026-06-10
Airtable
Vendor added to StackPosture — initial snapshot from published trust documentation. Verification pass pending.
2026-06-10
Anthropic
Subprocessor list extracted from Anthropic's trust center (trust.anthropic.com/subprocessors, fetched 2026-06-10): 18 subprocessors. Notable: three hyperscalers (GCP, AWS, Azure) plus Palantir Federal Cloud Service for Claude for Government, ElevenLabs for voice mode, and Brave Search/TurboPuffer powering web search.
2026-06-10
Anthropic
Vendor added with a verified initial snapshot: SOC 2 Type II, ISO 27001:2022, ISO/IEC 42001:2023, and HIPAA BAA availability confirmed against Anthropic's Privacy Center certification article (fetched 2026-06-10). DPA confirmed at anthropic.com/legal/data-processing-addendum. Trust portal (trust.anthropic.com) is JS-rendered — Vanta-hosted; subprocessor list extraction pending.
2026-06-10
Asana
Verification pass: SOC 2 Type II, ISO 27001:2022 (plus 27017/27018/27701), HIPAA, and CSA STAR Level 1 confirmed against Asana's trust page. Status page and EU/AU/JP data residency recorded; trust center corrected to security.asana.com.
2026-06-10
Asana
Vendor added to StackPosture — initial snapshot from published trust documentation. Verification pass pending.
2026-06-10
Atlassian
Vendor added with a verified initial snapshot: SOC 2 (Coalfire-audited, cloud products), ISO/IEC 27001:2022 with ISO 27018 extension, and FedRAMP Moderate (Jira, Confluence, JSM) each confirmed against Atlassian's dedicated compliance resource pages (fetched 2026-06-10). PCI DSS kept as reported only — the logo appears on the compliance page without a linked resource. The full 34-item compliance resource list is JS-filtered; remaining certifications can be verified individually later.
How it works
We collect trust facts from vendor-published documentation and public regulatory records — never from scanning, probing, or anything a vendor didn't publish themselves.
Every fact carries a source link and a date. Facts we haven't yet verified against a primary source are clearly marked as pending.
We re-check vendors on a schedule and log every change — so you can see not just what a vendor's posture is, but how it has moved.
Missing a vendor?
Tell us which vendor you're reviewing and we'll add them, usually within a few days: hello@stackposture.com