Security & Compliance

Security and compliance at Truto

Certifications and security program overview.

Controls
118
Certifications
05
Subprocessors
05

01

Updates

01 update

  1. SOC 2 Type II observation period underway

    Truto has entered the observation period for its fourth consecutive SOC 2 Type II audit, conducted by our independent auditor, Prescient Security. The audit evaluates the operating effectiveness of our security controls across the observation window, with the renewed report available to customers under NDA on completion.

02

Certifications

05 active

  • SOC 2 Type II

    ● Active

    Apr 1, 2026 → Mar 31, 2027

  • ISO 27001

    ● Active

    Oct 1, 2024 → Sep 30, 2027

  • GDPR

    ● Active

    Active

  • HIPAA

    ● Active

    Active

  • CASA Type II

    ● Active

    Active

05

Controls

118 controls

  • Single Sign-On (SSO)Enterprise SSO via SAML and OIDC so teams authenticate through their own identity provider.
  • Two-Factor Authentication (2FA)Multi-factor authentication enforced for privileged and administrative access.
  • Role-Based Access Control (RBAC)Least-privilege, role-based permissions across the platform.
  • AES-256 Encryption at RestAll data at rest is encrypted with AES-256.
  • Latest TLS in TransitAll data in transit is encrypted with the latest TLS (1.2+).
  • Database Region SelectionChoose the region where your data is stored to meet residency requirements.
  • Zero-Data Storage ModelA pass-through architecture: customer data flows in real time and is never persisted on Truto's platform.
Truto is built on a pass-through, zero-storage architecture: your customers' data flows through Truto in real time and is never persisted on our platform. That single design decision shrinks our attack surface and keeps you in control of where data lives. Our security program is independently audited — SOC 2 Type II and ISO 27001 — and continuously monitored through Sprinto, with each control mapped to a live evidence check rather than a point-in-time screenshot. Access follows least-privilege RBAC with enforced MFA, all data is encrypted in transit (TLS 1.2+) and at rest (AES-256), and infrastructure runs on SOC 2-certified providers across US and EU regions. We run annual third-party penetration tests, maintain a documented incident-response plan with customer notification within 48 hours, and give at least 15 days' notice before adding or replacing any subprocessor.

08

Subprocessors

05 vendors

  • Purpose
    Hosting, infrastructure, internet security, CDN and monitoring
    Location
    Global (multi-region)
  • Purpose
    Infrastructure monitoring, log management, APM and alerting
    Location
    United States
  • Purpose
    Cloud infrastructure, compute, database and storage services
    Location
    United States
  • Purpose
    Transactional and marketing email delivery
    Location
    United States
  • Purpose
    Cloud infrastructure, compute, database and storage services
    Location
    France (EU)

09

FAQ

06 questions

  • 01Does Truto store our customers' data?

    No. Truto runs on a pass-through, zero-storage model — your customers' data flows directly from the source system to you in real time and is never persisted on Truto's platform.

  • 02Which security certifications and frameworks does Truto maintain?

    Truto maintains SOC 2 Type II and ISO 27001, and operates in alignment with GDPR and HIPAA. The current status and validity for each is shown in the Certifications section above.

  • 03Can we review your SOC 2 report and DPA?

    Yes. Our Data Processing Agreement is published at truto.one/dpa, and the full SOC 2 Type II report is available to enterprise customers under NDA — just email security@truto.one.

  • 04How is data protected in transit and at rest?

    All data is encrypted in transit using TLS 1.2+, and any operational metadata at rest is encrypted with AES-256. Internal access is governed by role-based access control and enforced multi-factor authentication.

  • 05How do you manage subprocessors?

    Our subprocessors are listed publicly in the Subprocessors section. We give at least 15 days' advance notice before adding or replacing any subprocessor, and you may object on reasonable data-protection grounds.

  • 06Can Truto be deployed on-premise?

    Yes. Truto offers both a managed cloud and an on-prem / self-hosted deployment, so sensitive data never has to leave your own environment.

10

Documents

05 available

  • GDPR Compliance CertificateRequest
  • HIPAA Compliance CertificateRequest
  • ISO 27001 CertificateRequest
  • Penetration Test SummaryRequest
  • SOC 2 Type II ReportRequest

11

Policies

23 documents

The information-security policies behind our program. Documents are shared on request — submit a request and we’ll send a secure link once approved.

  • Acceptable Use PolicyRequest
    ISMS · v2.0
  • Access Control PolicyRequest
    ISMS · v2.1
  • Application Security PolicyRequest
    Security · v1.1
  • Asset Management PolicyRequest
    ISMS · v1.3
  • Business Continuity & Disaster Recovery PlanRequest
    Operations · v1.3
  • Change Management PolicyRequest
    Operations · v1.3
  • Code of Business ConductRequest
    People · v1.4
  • Cryptography & Key Management PolicyRequest
    Security · v1.2
  • Data Backup PolicyRequest
    Operations · v1.3
  • Data Classification & Handling PolicyRequest
    Privacy · v1.2
  • Data Protection & Privacy PolicyRequest
    Privacy · v2.0
  • Data Retention & Disposal PolicyRequest
    Privacy · v1.1
  • Endpoint & Mobile Device Security PolicyRequest
    Security · v1.0
  • Human Resources Security PolicyRequest
    People · v1.3
  • Incident Response PlanRequest
    Operations · v1.4
  • Information Security PolicyRequest
    ISMS · v3.2
  • Network Security PolicyRequest
    Security · v1.3
  • New Hire Onboarding PolicyRequest
    People · v1.1
  • Risk Assessment & Management PolicyRequest
    ISMS · v1.4
  • Secure Software Development PolicyRequest
    Security · v1.4
  • Security & Privacy Awareness PolicyRequest
    People · v1.2
  • Vendor & Subprocessor Management PolicyRequest
    ISMS · v1.2
  • Vulnerability & Patch Management PolicyRequest
    Security · v1.1