Map a project's third-party dependencies to public vendor trust center records using the trustlists directory. Produces a documentation-visibility inventory without treating directory absence as security risk. Use when asked to audit dependencies, review the software supply chain, or inventory third-party services.
Quickly check whether a vendor's public trustlists record lists a requested framework or CSA STAR level. Use during vendor review or code review when someone asks about SOC 2, ISO 27001, HIPAA documentation, PCI DSS, or CSA STAR. Free, no credits.
Look up a vendor's public trust center and listed frameworks using the trustlists directory of thousands of companies. Use when the user asks where to find a company's security documentation, whether its directory record lists SOC 2 / ISO / HIPAA information, or when reviewing a third-party service.