Third Party Index

Snapshot 35870

Document
Trust center
URL
https://trust.composio.dev/?cta_placement=footer-trust
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
96309 bytes
SHA-256 (raw)
6a505b1d984fb0d405dcea1ecd5d917a7f44dd6d470fde6a928a3ff92167f4c9
SHA-256 (normalized text)
6d088ac841b806eadbd128c34895793625633b6508c52f36b91ef0506350fdd6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
Composio
Composio.dev is your AI-powered conductor, orchestrating seamless SaaS integrations with agents as instruments and MCP as the score. From Slack to Salesforce, every service plays in sync—no more messy solos of auth or APIs. Let AI agents handle the backend while your app hits every note, fast and flawlessly.
[email protected]
Privacy PolicyOpens in new tab
Compliance
SOC 2
ISO 27001:2022
Resources
View all
Audit Reports
SOC 2 Type II Report
Composio Dashboard Web Application Executive Summary
Policies
Business Continuity and Disaster Recovery Plan
Incident Response Plan
Data Management Policy
Secure Development Policy
Other resources
Engagement Letter
Data Processing Addendum (DPA)
Opens in new tab
Business Associate Agreement (BAA)
Opens in new tab
Controls
View all
Infrastructure security
Remote access MFA enforced
Remote access encrypted enforced
Network segmentation implemented
Product security
Data encryption utilized
Control self-assessments conducted
Internal security procedures
System changes externally communicated
Organization structure documented
Support system available
View 2 more Internal security procedures controls
Subprocessors
View all
Amazon Web Services
•
Cloud infrastructure
us-east-1 N Virginia
Hosts and processes customer request data across AWS cloud infrastructure, including ECS Fargate, Lambda, RDS, S3, Secrets Manager, KMS, and related networking/security services.
Cloudflare
•
DNS and Workers
Workers to delivers trigger payloads to customer webhooks; file upload relay downloads third-party files and writes them to R2 storage.
Vercel
•
Serves APIs, Vercel AI for LLM routing
Backend processes all API requests via Vercel hosted service. Additionally, Vercel AI routes selected AI SDK model calls to configured model providers for workbench/runtime flows.
We've enabled ZDR on Vercel.
OpenAI
•
LLM inferences
Processes prompts, reranking inputs, and embeddings where OpenAI models are selected or routed.
We've Disabled sharing data for improving models and training on our data.
Updates
View all
Security
Statement of Non-Impact: Vercel April 2026 Security Incident
Published May 11, 2026
Overview
On April 19, 2026, Vercel disclosed a security incident in which an attacker gained unauthorized access to internal Vercel systems through a compromised third-party AI tool used by a Vercel employee. The attacker was able to enumerate and decrypt non-sensitive environment variables belonging to a limited subset of Vercel customers.
Composio uses Vercel as a critical part of our production environment, as our main API gateway. Given that exposure, we conducted a detailed investigation to determine whether we were impacted.
Findings
We have confirmed the following:
Vercel confirmed directly to us that our account was not among those impacted by this incident. We separately reviewed our Vercel activity logs for the relevant window and found no suspicious access, deployments, or configuration changes.
All environment variables held in our Vercel account have been rotated as a precaution, in line with Vercel's published guidance. Going forward, secrets are stored using Vercel's sensitive environment variables feature, so their values cannot be read back.
Vercel has confirmed, with GitHub, npm, and Socket, that no npm packages published by Vercel have been tampered with. Our dependencies are unaffected.
There is no evidence that Composio customer data or credentials were accessed or exfiltrated. Our services continue to operate normally.
Conclusion
Based on this review, Composio is not impacted by the Vercel April 2026 security incident. We will continue to monitor Vercel's updates and will notify customers directly if anything changes.
Compliance
Updated SOC 2 Type II report
Published March 12, 2026
Our Trust Center just got an update — Composio's renewed SOC 2 Type II report is now available. Security and compliance aren't checkboxes for us; they're part of how we build. Head to our Trust Center to view the latest report.
General
Composio Trust Center News Feed
Published June 9, 2025
Welcome to Composio’s Trust Center, a.k.a. the Fortress of Transparency!
We’ll be dropping occasional updates here — nothing spammy, just the good stuff. Want to stay in the loop? Click on the Subscribe 🔔 button.
Here’s what you might hear from us about:
New reports and artifacts
Changes to our list of Subprocessors
Big moves in our trust & security program
We promise not to overdo it — updates will be rare, relevant, and ridiculously useful.
Media
View all
Building Trust: Security & Compliance for AI Agents at Composio Opens in new tab
At Composio, security isn’t an afterthought—it is foundational to how agents take actions safely at scale. In this video, Head of Security at Composio breaks down our approach to building a platform trusted by everyone.