Trust centers
Watch vendor trust-center and subprocessor pages for DPA changes
Subprocessor & Trust Center Scraper fetches public vendor trust-center, subprocessor, security, and DPA pages you list and returns severity-scored JSON digests with change flags, delta summaries, and remediation guidance. Feed changedSinceLastRun-style flags into Jira or security dashboards. It is passive public-page monitoring — not a pentest, not an HHS OCR portal watch, and not a status-page incident digest.
$10.00 / 1,000 delivered monitoring result rows (unchanged runs are free)
Open Subprocessor & Trust Center Scraper on Apify
Trust-center diffs, not OCR breaches, status pages, or page-body RAG
Use this page when the job is DPA and subprocessor text changes on vendor security pages. Use HHS Healthcare Data Breach Change Scraper for HHS OCR disclosures. Use SaaS Status Page & Incident Scraper for outage digests. Use Website Content Extractor for cleaned policy HTML. Use SSL/TLS Certificate Scraper and DMARC & Email Security Checker for TLS and email-auth DNS.
| This Actor | HHS Healthcare Data Breach | SaaS Status Page & Incident | |
|---|---|---|---|
| Intent | DPA / subprocessor / trust-center diffs | Newly published HHS OCR disclosures | Vendor status-page incident digests |
| Input | vendors[] with trust/DPA/subprocessor URLs |
Date window and optional filters | vendors[] with statusPageUrl |
| Default emit | changes_only |
changes_only |
all |
| Not this job | Pentest, OCR portal, status outages | Vendor DPA HTML diffs | Subprocessor list diffs |
Store ID: taroyamada/trust-center-subprocessor-monitor. Schema prefill uses Okta public trust/DPA/subprocessor URLs as a capability example, not an affiliation.
Use cases
- Vendor inventory: recurring snapshot watches on public trust pages.
- New-subprocessor alerts for security and procurement owners.
- SOC2 evidence collection from public pages (not a certification).
- Ticket on
action_neededwhen severity-scored changes appear.
How is Subprocessor & Trust Center Scraper different from HHS Healthcare Data Breach Change Scraper and Website Content Extractor?
This Actor fetches public vendor trust-center, subprocessor, security, and DPA pages you list and emits severity-scored JSON digests with change flags, delta summaries, and remediation guidance. Required input is vendors. Store ID taroyamada/trust-center-subprocessor-monitor. HHS Healthcare Data Breach Change Scraper monitors the public HHS OCR Breach Portal, not vendor trust pages. Website Content Extractor cleans docs/policy HTML into markdown or text; it does not compute subprocessor diffs. SaaS Status Page & Incident Scraper monitors status pages for outages, not DPA text. DMARC and SSL Actors check DNS and TLS, not trust-center HTML.
What input is required?
vendors is required. README examples that send urls[], emitTextDiff, or emitChangedOnly are not live schema fields. Use vendors[] plus datasetMode. additionalProperties is false.
| Field | Type | Default | Notes |
|---|---|---|---|
vendors |
object[] | required | Shorthand: trustCenterUrl, subprocessorsUrl, securityUrl, dpaUrl, or urlPacks |
requestTimeoutSeconds |
integer | 30 | HTTP timeout |
maxChars |
integer | 40000 | Max extracted text per page |
delivery |
string | dataset |
dataset, webhook, or email. email is not implemented |
datasetMode |
string | changes_only |
action_needed, changes_only, or all |
webhookUrl |
string | — | Required when delivery is webhook |
notifyOnNoChange |
boolean | false | Skip webhook if no change and no action |
snapshotKey |
string | trust-center-subprocessor-monitor-snapshots |
Change the key to reset the baseline. Store example uses trust-center-quickstart |
diffMode |
string | line_summary |
line_summary or hash_only |
summaryMaxLines |
integer | 15 | Max added/removed lines in evidence |
concurrency |
integer | 3 | Keep 1–3 |
batchDelayMs |
integer | 500 | Inter-batch delay |
dryRun |
boolean | false | No persist / no delivery |
Published Store example run input uses Okta public URLs plus snapshotKey trust-center-quickstart, concurrency 2, and dryRun false. Schema prefill: subprocessors + DPA + https://trust.okta.com/.
Run Subprocessor & Trust Center Scraper on Apify
What does a monitoring result contain?
Published README fields include meta, actionNeeded[] (vendorId, vendorName, owner, severity, status, reason, changedPacks, recommendedActions, executiveSummary), and results. The published sample is truncated; treat it as an illustration, not a live coverage guarantee.
How do changes_only, snapshots, and webhooks work?
datasetMode default is changes_only: emit only when pages changed. all always emits. action_needed emits only when actionNeeded is true. Unchanged runs are free on the live Store event. Keep snapshotKey constant to preserve the baseline; change it to reset. notifyOnNoChange default is false. dryRun true does not persist or deliver. delivery email is a placeholder and is not implemented; use dataset or webhook.
Is this a pentest or a SOC2 certification?
No. Passive public pages only. Not a pentest: no exploitation, fuzzing, or auth bypass. Published FAQ: evidence artifacts may support SOC2 workflows; the Actor is not itself a SOC2 certification. Scan only pages you are authorized to monitor under your own policy.
How is Subprocessor & Trust Center Scraper priced?
Billing is pay per event. The live Store card is $10.00 / 1,000 delivered monitoring result rows. The billed event is Delivered monitoring result row (apify-default-dataset-item) at $0.01, charged only when a new or changed monitoring result row is delivered. Unchanged runs are free. There is no Actor Start on the current pricing tab. The README Cost section that still quotes $0.01 start plus $0.003 per item is stale.
$10.00 per 1,000 delivered monitoring result rows ($0.01 per new or changed row)
See Subprocessor & Trust Center Scraper pricing on Apify
Limits to keep in mind
- Required:
vendors[]. Not a top-levelurlsarray. emaildelivery is not implemented. Use dataset or webhook.- Passive public pages only. Not a pentest and not a SOC2 certification.
- Keep concurrency 1–3. Default
changes_onlyso unchanged runs are free.
Open Subprocessor & Trust Center Scraper on Apify
Related pages
- SaaS Status Page & Incident Scraper — status-page outages, not DPA diffs
- HHS Healthcare Data Breach Change Scraper — HHS OCR disclosures, not vendor trust pages
- SSL/TLS Certificate Scraper — TLS expiry, not subprocessor HTML
- DMARC & Email Security Checker — SPF/DMARC/MX, not trust-center text
- robots.txt Parser & AI Crawler Block Checker — robots.txt AI policies
- Website Content Extractor — cleaned policy HTML, not change diffs
- SaaS Pricing Tracker — pricing/terms diffs, not subprocessors
- Docs & Changelog Drift Scraper — docs/changelog drift, not trust-center vendor lists
- GDPR & CCPA Cookie Compliance Scraper — cookie banners, not subprocessors
- Tools