observe.ai

B+
Pass · 88/100
Shows significant security gaps that need urgent attention. Positive signals: DMARC / Email Security, MX Records & Mail Provider, and Known Breaches all passed. 2 action items identified, including 0 critical. The issues point to real architectural gaps, not just configuration tweaks. A focused remediation effort of 1–2 days could address all findings.
Trust Score Trend
→ No change 1 scan · Last scanned February 18, 2026
Your rating Industry average
Score
100 75 50 25 0
B+
observe.ai
88/100
Compliance & Certifications
5 of 5 verified via Trust Center
SOC 2 TYPE II
SOC 2 Type II
Listed on self-hosted Trust Center
View trust center
ISO 27001
ISO 27001
Listed on self-hosted Trust Center
View trust center
GDPR
GDPR
Listed on self-hosted Trust Center
View trust center
CCPA
CCPA
Listed on self-hosted Trust Center
View trust center
PCI DSS
PCI DSS
Listed on self-hosted Trust Center
View trust center
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
Security Posture
2 items need attention
8 passed
Add 5 missing security headers
Security Headers
1–2 hours

This leaves visitors exposed to attacks like clickjacking and content-type sniffing. observe.ai is missing 5 of the 5 security headers browsers use to protect visitors — for example, one stops your site being loaded inside a hidden frame on another site to trick people into clicking things (clickjacking). These are settings, not code changes, so they're usually quick to add.

PCI-DSS 4.0Req 6.4.1
Security headers are required application controls
OWASPSecure Headers
Recommended baseline for web applications
How to fix this
1Add these headers exactly as shown. You're using Cloudflare in front of this site — add it there, see https://developers.cloudflare.com/rules/transform/response-header-modification/create-dashboard/.
Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; script-src 'self' 'unsafe-inline'; upgrade-insecure-requests
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()
2Confirm it worked: search "http header checker" and enter observe.ai — check the headers below in the response.
Report unlocked.
View all 8 passed checks
DMARC / Email Security
MX Records & Mail Provider
Known Breaches
TLS Configuration
HSTS Header
CVE Exposure
Certificate Hygiene
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Self-hosted Trust Center
observe.ai/contact-center-security
Security page
observe.ai/security ↗
Privacy Policy
observe.ai/privacy ↗
DPA (Data Processing Agreement)
observe.ai/dpa ↗
Updated recently
Subprocessors List
observe.ai/policies/subprocessors ↗
Tech Stack Detected
Subprocessors
Cloudflare
Similar companies in B2B SaaS / Software
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
Track
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Track
Top AI vendors by trust score
94 companies · LynxRadar ranking
Track
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking
Track