Featured in our Forbes AI 50 security study: see how elevenlabs.io compares with the other 49 →
C
Trust rating
Fair · 75/100
Procurement snapshot
0 critical findings identified — these point to architectural gaps, not just configuration tweaks.
Strengths
MX Records & Mail Provider
TLS Configuration
TLS Protocol Support
security.txt (RFC 9116)
Estimated remediation effort: 1–2 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change
1 scan · Last scanned September 28, 2026
Score
100
75
50
25
0
C
75/100
Compliance & Certifications
SOC 2 Type II
3rd party · AICPA
ISO 27001
3rd party · accredited body
GDPR
Self-reported
CCPA
Self-reported
Incident History
No public breaches on record
Security Posture
7 items need attention
8 passed
Add 4 missing security headers
Security Headers
This leaves visitors exposed to attacks like clickjacking and content-type sniffing. elevenlabs.io is missing 4 of the 5 security headers browsers use to protect visitors — for example, one stops your site being loaded inside a hidden frame on another site to trick people into clicking things (clickjacking). These are settings, not code changes, so they're usually quick to add. On top of that, 1 of the headers you do have is misconfigured: CSP: no default-src fallback directive.
PCI-DSS 4.0Req 6.4.1
Security headers are required application controls
OWASPSecure Headers
Recommended baseline for web applications
How to fix this
1Add these headers exactly as shown. If you manage your own server (nginx, Apache, IIS) or a CDN like Cloudflare, add it in that config. If your site is on a managed platform (Wix, Squarespace, Shopify, WordPress.com), search their help center for "custom headers" or ask their support — most support it, though a few don't.
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()
2Fix these existing headers — they're present but not doing their job: CSP: no default-src fallback directive. If you manage your own server (nginx, Apache, IIS) or a CDN like Cloudflare, add it in that config. If your site is on a managed platform (Wix, Squarespace, Shopify, WordPress.com), search their help center for "custom headers" or ask their support — most support it, though a few don't.
3Confirm it worked: search "http header checker" and enter elevenlabs.io — the headers above should appear in the response.
Report unlocked.
View all 8 passed checks
MX Records & Mail Provider
TLS Configuration
TLS Protocol Support
security.txt (RFC 9116)
Subprocessors & Tech Stack
Known Breaches
Certificate Hygiene
CVE Exposure
Couldn't check: Malware / Phishing Blocklist — the check didn't complete (the site blocked or timed out our scanner, or a data source was unavailable), so this isn't counted in the score.
Company Signals
Operational risk
Last funding
Employees
Trust Resources
Claim profile →
Trust Center
Not detected
Security contact (security.txt)
elevenlabs.io/.well-known/security.txt
Privacy Policy
DPA (Data Processing Agreement)
Subprocessors List
Similar companies
Appears in
Vendors graded C
697 companies · LynxRadar ranking
LynxRadar Pro
Unlock the full report
$9/mo · cancel anytime
- Step-by-step fixes with copy-paste values for every finding
- Procurement-ready PDF report for vendor reviews
- Alerts when a vendor's grade changes coming soon
- Company signals, incident history & compliance status coming soon
Pro is launching soon — we'll email you when it's ready.