{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"easol","name":"Easol","domain":"easol.com","category":"E-commerce","one_liner":"Shopify for experiences","trust_center_url":"https://trust.easol.com/","security_page_url":null,"url":"https://certreports.com/vendors/easol/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/easol/soc-2","evidence":[{"source_type":"trust_center","source_name":"Easol trust centre (Vanta)","url":"https://trust.easol.com/","fetched_at":"2026-09-18 23:17:59.670395+00","content_hash":"5eb6f78f7a2d37ef18ebb58d59783d3e0cec779e7a346c89fc784dc3f6020781","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS - SAQ A on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/easol/pci-dss","evidence":[{"source_type":"trust_center","source_name":"Easol trust centre (Vanta)","url":"https://trust.easol.com/","fetched_at":"2026-09-18 23:17:59.670395+00","content_hash":"5eb6f78f7a2d37ef18ebb58d59783d3e0cec779e7a346c89fc784dc3f6020781","wayback_url":null,"quote":"PCI DSS - SAQ A","confidence":1}]},{"framework":"soc-3","framework_name":"SOC 3","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a public SOC 3 report on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states SOC 3 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/easol/security","evidence":[{"source_type":"trust_center","source_name":"Easol trust centre (Vanta)","url":"https://trust.easol.com/","fetched_at":"2026-09-18 23:17:59.670395+00","content_hash":"5eb6f78f7a2d37ef18ebb58d59783d3e0cec779e7a346c89fc784dc3f6020781","wayback_url":null,"quote":"SOC 3","confidence":1}]}],"brief":null,"legal_docs":[{"kind":"privacy","url":"https://easol.com/privacy-policy/","availability":"public","detail":null,"as_of":"2026-09-18"},{"kind":"subprocessors","url":"https://trust.easol.com/","availability":"public","detail":"25 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Amazon Web Services","domain":"amazon.com","purpose":"Cloud provider","location":null,"vendor_url":"https://certreports.com/vendors/amazon/security"},{"name":"Chargebee","domain":null,"purpose":"Finance and payments","location":null,"vendor_url":null},{"name":"Cloudflare Dashboard","domain":null,"purpose":"Infrastructure","location":null,"vendor_url":null},{"name":"Crunchy Bridge","domain":"crunchydata.com","purpose":"Infrastructure","location":null,"vendor_url":null},{"name":"Datadog","domain":null,"purpose":"Cloud monitoring","location":null,"vendor_url":null},{"name":"GitHub","domain":"github.com","purpose":"Version control","location":null,"vendor_url":null},{"name":"Google Workspace","domain":"google.com","purpose":"Identity provider","location":null,"vendor_url":null},{"name":"Heroku","domain":"heroku.com","purpose":"Cloud provider","location":null,"vendor_url":"https://certreports.com/vendors/heroku/security"},{"name":"Humaans","domain":"humaans.io","purpose":"Employee management","location":null,"vendor_url":"https://certreports.com/vendors/humaans/security"},{"name":"Justt","domain":"justt.ai","purpose":"Chargeback management","location":null,"vendor_url":null},{"name":"Lattice","domain":null,"purpose":"Employee management","location":null,"vendor_url":null},{"name":"Linear","domain":"linear.app","purpose":"Collaboration","location":null,"vendor_url":null},{"name":"Notion","domain":null,"purpose":"Collaboration","location":null,"vendor_url":null},{"name":"Nuvei","domain":"nuvei.com","purpose":"Payment processing","location":null,"vendor_url":"https://certreports.com/vendors/nuvei-us-llc/security"},{"name":"OpenRouter","domain":"openrouter.ai","purpose":"AI Inference","location":null,"vendor_url":null},{"name":"PostHog","domain":null,"purpose":"Product analytics","location":null,"vendor_url":null},{"name":"Primer","domain":"primer.io","purpose":"Payment orchestration","location":null,"vendor_url":"https://certreports.com/vendors/primer-api-limited/security"},{"name":"Redis","domain":"redis.io","purpose":"Key value storage","location":null,"vendor_url":null},{"name":"Retool","domain":"retool.com","purpose":"IT","location":null,"vendor_url":"https://certreports.com/vendors/retool/security"},{"name":"Sentry","domain":null,"purpose":"Cloud monitoring","location":null,"vendor_url":null},{"name":"Slack","domain":"slack.com","purpose":"Collaboration","location":null,"vendor_url":"https://certreports.com/vendors/slack-technologies/security"},{"name":"Stripe","domain":null,"purpose":"Finance and payments","location":null,"vendor_url":null},{"name":"TrueLayer Console","domain":null,"purpose":"Payment processing","location":null,"vendor_url":null},{"name":"Vanta","domain":"vanta.com","purpose":"Security","location":null,"vendor_url":"https://certreports.com/vendors/vanta/security"},{"name":"Zoom","domain":null,"purpose":"Collaboration","location":null,"vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T12:55:46.953Z"}