Trust & Security
TrustisCore.
We earn the trust of our customers and partners through transparency, security, and compliance - backed by infrastructure built to the highest standards in identity security.
- SOC 2
- CSA STAR
- CISA
- GDPR
- CCPA
Frameworks & Certifications
Independent attestationsand the frameworks we align to.
Third-party audits, regulatory alignment, and cross-border privacy — renewed on a schedule and available to security reviewers on request.
SOC 2 Type II
Annually audited. Controls span security, availability, and confidentiality.
CSA STAR Level 1
Cloud Security Alliance Level 1 compliant.
CISA Secure-by-Design Pledge
Prioritizing the security of customers.
GDPR
Compliant data processing with EU data residency options.
CCPA
California Consumer Privacy Act compliant.
SOC 2 Type II
Annually audited. Controls span security, availability, and confidentiality.
CSA STAR Level 1
Cloud Security Alliance Level 1 compliant.
CISA Secure-by-Design Pledge
Prioritizing the security of customers.
GDPR
Compliant data processing with EU data residency options.
CCPA
California Consumer Privacy Act compliant.
The Program
37 controls, six domains,one continuous program.
The Full Program
Every control we run,documented in plain language.
6 domains · 37 controls
Information Security Management
Our CISO owns the information security program, supported by a Security Steering Committee and quarterly Board oversight.
Security Leadership
Our CISO owns the information security program, supported by a Security Steering Committee and quarterly Board oversight.
Information Security Policies and Procedures
We maintain a comprehensive policy set, approved by management, reviewed at least annually, and available to all employees on our internal portal.
Background Checks
All candidates undergo screening and reference checks as part of the hiring process, in accordance with local laws.
Employee Confidentiality
All new hires sign an employment agreement covering confidentiality, code of conduct, and intellectual property.
Mandatory Security Awareness Training
All employees complete security awareness training within 30 days of joining and annually thereafter, with additional role-specific training for higher-risk roles.
Risk Management Program
We run a formal risk management program, led by the CISO, with an annual risk assessment and management-approved remediation.
Disciplinary Process
A documented disciplinary process addresses violations of our security policies.
Independent Annual Audit
We undergo an independent annual SOC 2 Type II examination by a qualified third-party CPA firm.
Cyber Insurance
We maintain a cyber insurance policy with coverage appropriate to the scale and risk profile of our business.
Network & Infrastructure Security
Our cloud infrastructure runs across multiple availability zones and auto-scales to maintain availability under demand.
High Availability & Auto-Scaling
Our cloud infrastructure runs across multiple availability zones and auto-scales to maintain availability under demand.
Logging & Monitoring
All production activity is logged, centralized, and continuously monitored, with alerts triggered on anomalies.
Disaster Recovery
Infrastructure and data are distributed across multiple availability zones with automated backups, and recovery is tested through an annual DR drill.
Least Privilege
Access is provisioned by role and baselined regularly, with permissions to production, databases, and applications reviewed at least annually.
Production Environment Isolation
The production environment is fully separated from the corporate environment, requiring two-factor authentication and IP filtering for access.
Network Security & Segmentation
Resources are protected by firewalls, VPNs, encrypted tunnels, intrusion-detection monitoring, and least-privilege port configuration.
Infrastructure Provider Oversight
We review our cloud provider's SOC 2 report annually and document the complementary controls we operate.
Data Privacy & Protection
All data at rest is encrypted with AES-256 using hardware-bound keys, with no action required from customers.
Encryption at Rest
All data at rest is encrypted with AES-256 using hardware-bound keys, with no action required from customers.
Encryption in Transit
All traffic is served over HTTPS and encrypted in transit using TLS 1.2+ with strong cipher suites.
Data Retention & Disposal
Data retention and deletion follow customer contracts and applicable law, with customer data returned on termination and then securely erased.
Key Management
Encryption keys are hardware-bound with unique keys per environment, automated rotation, dual authorization, and full lifecycle logging.
Data Classification & Inventory
We classify data by sensitivity and maintain an inventory of sensitive and personal data, including owner, location, and processing purpose.
Privacy by Design & GDPR
We apply data minimization and privacy impact assessments, maintain a disclosed sub-processor list, and notify the data controller of a personal data breach within 72 hours.
Incident Detection & Response
Every pull request undergoes mandatory peer review, documented in our source-control tool, before it can be merged.
Code Review
Every pull request undergoes mandatory peer review, documented in our source-control tool, before it can be merged.
Incident Response Process
We maintain a tested incident response plan with defined escalation, rapid mitigation, and post-incident root-cause analysis.
24/7 Monitoring & Escalation
Our Security team monitors production continuously, with a defined escalation matrix and time-bound response targets for critical alerts.
Vendor Risk Assessments
We formally assess vendors and sub-processors at least annually, with a higher bar for those handling sensitive data or critical systems.
Breach Notification
Breach notification procedures meet GDPR and customer-contractual SLAs and are documented in our Incident Response Policy and DPAs.
Product Security
Independent third-party experts perform a detailed penetration test of the application and infrastructure at least annually, with critical and high findings resolved.
Penetration Testing
Independent third-party experts perform a detailed penetration test of the application and infrastructure at least annually, with critical and high findings resolved.
Single Sign-On & Authentication
The platform supports SAML 2.0, OpenID Connect, OAuth 2.0, and LDAP/Active Directory, plus FIDO2 passkeys, hardware tokens, push, and one-time passwords.
Multi-Factor Authentication
MFA is required for access to sensitive systems and for privileged access to sensitive data.
Secure Development Lifecycle
We follow a documented SDLC with OWASP secure coding standards, mandatory code review, automated testing, and SAST and dependency scanning as CI gates.
Vulnerability Management
Vulnerabilities are scanned continuously, prioritized using CVSS, and remediated against defined SLAs.
Change Management
All production changes follow a documented change-control process with approval, testing, and a required rollback plan.
Endpoint Security
All corporate devices use full-disk AES-256 encryption enforced via MDM and can be remotely wiped if lost or compromised.
Endpoint Encryption
All corporate devices use full-disk AES-256 encryption enforced via MDM and can be remotely wiped if lost or compromised.
Endpoint Management
Employee devices are enrolled in MDM with enforced patching, screen lock, and managed configuration.
Antivirus & EDR
Endpoint detection and response and antivirus run on all endpoints via a centralized tool with automatically updated signatures.
Remote Work & BYOD
Remote-work and BYOD protections are governed by our Acceptable Use, BYOD, and Physical Security policies.
Know what exists.Know what needs action.
See how we discover identities beyond the IdP, resolve fragmented records into one current view, and trace the access paths that need review.