Trust centers

Watch vendor trust-center and subprocessor pages for DPA changes

Subprocessor & Trust Center Scraper fetches public vendor trust-center, subprocessor, security, and DPA pages you list and returns severity-scored JSON digests with change flags, delta summaries, and remediation guidance. Feed changedSinceLastRun-style flags into Jira or security dashboards. It is passive public-page monitoring — not a pentest, not an HHS OCR portal watch, and not a status-page incident digest.

$10.00 / 1,000 delivered monitoring result rows (unchanged runs are free)

Open Subprocessor & Trust Center Scraper on Apify

Trust-center diffs, not OCR breaches, status pages, or page-body RAG

Use this page when the job is DPA and subprocessor text changes on vendor security pages. Use HHS Healthcare Data Breach Change Scraper for HHS OCR disclosures. Use SaaS Status Page & Incident Scraper for outage digests. Use Website Content Extractor for cleaned policy HTML. Use SSL/TLS Certificate Scraper and DMARC & Email Security Checker for TLS and email-auth DNS.

This Actor HHS Healthcare Data Breach SaaS Status Page & Incident
Intent DPA / subprocessor / trust-center diffs Newly published HHS OCR disclosures Vendor status-page incident digests
Input vendors[] with trust/DPA/subprocessor URLs Date window and optional filters vendors[] with statusPageUrl
Default emit changes_only changes_only all
Not this job Pentest, OCR portal, status outages Vendor DPA HTML diffs Subprocessor list diffs

Store ID: taroyamada/trust-center-subprocessor-monitor. Schema prefill uses Okta public trust/DPA/subprocessor URLs as a capability example, not an affiliation.

Use cases

How is Subprocessor & Trust Center Scraper different from HHS Healthcare Data Breach Change Scraper and Website Content Extractor?

This Actor fetches public vendor trust-center, subprocessor, security, and DPA pages you list and emits severity-scored JSON digests with change flags, delta summaries, and remediation guidance. Required input is vendors. Store ID taroyamada/trust-center-subprocessor-monitor. HHS Healthcare Data Breach Change Scraper monitors the public HHS OCR Breach Portal, not vendor trust pages. Website Content Extractor cleans docs/policy HTML into markdown or text; it does not compute subprocessor diffs. SaaS Status Page & Incident Scraper monitors status pages for outages, not DPA text. DMARC and SSL Actors check DNS and TLS, not trust-center HTML.

What input is required?

vendors is required. README examples that send urls[], emitTextDiff, or emitChangedOnly are not live schema fields. Use vendors[] plus datasetMode. additionalProperties is false.

Field Type Default Notes
vendors object[] required Shorthand: trustCenterUrl, subprocessorsUrl, securityUrl, dpaUrl, or urlPacks
requestTimeoutSeconds integer 30 HTTP timeout
maxChars integer 40000 Max extracted text per page
delivery string dataset dataset, webhook, or email. email is not implemented
datasetMode string changes_only action_needed, changes_only, or all
webhookUrl string — Required when delivery is webhook
notifyOnNoChange boolean false Skip webhook if no change and no action
snapshotKey string trust-center-subprocessor-monitor-snapshots Change the key to reset the baseline. Store example uses trust-center-quickstart
diffMode string line_summary line_summary or hash_only
summaryMaxLines integer 15 Max added/removed lines in evidence
concurrency integer 3 Keep 1–3
batchDelayMs integer 500 Inter-batch delay
dryRun boolean false No persist / no delivery

Published Store example run input uses Okta public URLs plus snapshotKey trust-center-quickstart, concurrency 2, and dryRun false. Schema prefill: subprocessors + DPA + https://trust.okta.com/.

Run Subprocessor & Trust Center Scraper on Apify

What does a monitoring result contain?

Published README fields include meta, actionNeeded[] (vendorId, vendorName, owner, severity, status, reason, changedPacks, recommendedActions, executiveSummary), and results. The published sample is truncated; treat it as an illustration, not a live coverage guarantee.

How do changes_only, snapshots, and webhooks work?

datasetMode default is changes_only: emit only when pages changed. all always emits. action_needed emits only when actionNeeded is true. Unchanged runs are free on the live Store event. Keep snapshotKey constant to preserve the baseline; change it to reset. notifyOnNoChange default is false. dryRun true does not persist or deliver. delivery email is a placeholder and is not implemented; use dataset or webhook.

Is this a pentest or a SOC2 certification?

No. Passive public pages only. Not a pentest: no exploitation, fuzzing, or auth bypass. Published FAQ: evidence artifacts may support SOC2 workflows; the Actor is not itself a SOC2 certification. Scan only pages you are authorized to monitor under your own policy.

How is Subprocessor & Trust Center Scraper priced?

Billing is pay per event. The live Store card is $10.00 / 1,000 delivered monitoring result rows. The billed event is Delivered monitoring result row (apify-default-dataset-item) at $0.01, charged only when a new or changed monitoring result row is delivered. Unchanged runs are free. There is no Actor Start on the current pricing tab. The README Cost section that still quotes $0.01 start plus $0.003 per item is stale.

$10.00 per 1,000 delivered monitoring result rows ($0.01 per new or changed row)

See Subprocessor & Trust Center Scraper pricing on Apify

Limits to keep in mind

Open Subprocessor & Trust Center Scraper on Apify

Related pages