Security & Compliance
Security and compliance at Truto
Certifications and security program overview.
- Controls
- 118
- Certifications
- 05
- Subprocessors
- 05
SOC 2 Type II observation period underway
Truto has entered the observation period for its fourth consecutive SOC 2 Type II audit, conducted by our independent auditor, Prescient Security. The audit evaluates the operating effectiveness of our security controls across the observation window, with the renewed report available to customers under NDA on completion.
SOC 2 Type II
● ActiveApr 1, 2026 → Mar 31, 2027
ISO 27001
● ActiveOct 1, 2024 → Sep 30, 2027
GDPR
● ActiveActive
HIPAA
● ActiveActive
CASA Type II
● ActiveActive
- Single Sign-On (SSO)Enterprise SSO via SAML and OIDC so teams authenticate through their own identity provider.
- Two-Factor Authentication (2FA)Multi-factor authentication enforced for privileged and administrative access.
- Role-Based Access Control (RBAC)Least-privilege, role-based permissions across the platform.
- AES-256 Encryption at RestAll data at rest is encrypted with AES-256.
- Latest TLS in TransitAll data in transit is encrypted with the latest TLS (1.2+).
- Database Region SelectionChoose the region where your data is stored to meet residency requirements.
- Zero-Data Storage ModelA pass-through architecture: customer data flows in real time and is never persisted on Truto's platform.
| Name | Purpose | Location |
|---|---|---|
Cloudflare | Hosting, infrastructure, internet security, CDN and monitoring | Global (multi-region) |
Datadog | Infrastructure monitoring, log management, APM and alerting | United States |
DigitalOcean | Cloud infrastructure, compute, database and storage services | United States |
Mailchimp | Transactional and marketing email delivery | United States |
OVHcloud | Cloud infrastructure, compute, database and storage services | France (EU) |
- Purpose
- Hosting, infrastructure, internet security, CDN and monitoring
- Location
- Global (multi-region)
- Purpose
- Infrastructure monitoring, log management, APM and alerting
- Location
- United States
- Purpose
- Cloud infrastructure, compute, database and storage services
- Location
- United States
- Purpose
- Transactional and marketing email delivery
- Location
- United States
- Purpose
- Cloud infrastructure, compute, database and storage services
- Location
- France (EU)
01Does Truto store our customers' data?
No. Truto runs on a pass-through, zero-storage model — your customers' data flows directly from the source system to you in real time and is never persisted on Truto's platform.
02Which security certifications and frameworks does Truto maintain?
Truto maintains SOC 2 Type II and ISO 27001, and operates in alignment with GDPR and HIPAA. The current status and validity for each is shown in the Certifications section above.
03Can we review your SOC 2 report and DPA?
Yes. Our Data Processing Agreement is published at truto.one/dpa, and the full SOC 2 Type II report is available to enterprise customers under NDA — just email security@truto.one.
04How is data protected in transit and at rest?
All data is encrypted in transit using TLS 1.2+, and any operational metadata at rest is encrypted with AES-256. Internal access is governed by role-based access control and enforced multi-factor authentication.
05How do you manage subprocessors?
Our subprocessors are listed publicly in the Subprocessors section. We give at least 15 days' advance notice before adding or replacing any subprocessor, and you may object on reasonable data-protection grounds.
06Can Truto be deployed on-premise?
Yes. Truto offers both a managed cloud and an on-prem / self-hosted deployment, so sensitive data never has to leave your own environment.
- GDPR Compliance CertificateRequest
- HIPAA Compliance CertificateRequest
- ISO 27001 CertificateRequest
- Penetration Test SummaryRequest
- SOC 2 Type II ReportRequest
The information-security policies behind our program. Documents are shared on request — submit a request and we’ll send a secure link once approved.
- Acceptable Use PolicyRequestISMS · v2.0
- Access Control PolicyRequestISMS · v2.1
- Application Security PolicyRequestSecurity · v1.1
- Asset Management PolicyRequestISMS · v1.3
- Business Continuity & Disaster Recovery PlanRequestOperations · v1.3
- Change Management PolicyRequestOperations · v1.3
- Code of Business ConductRequestPeople · v1.4
- Cryptography & Key Management PolicyRequestSecurity · v1.2
- Data Backup PolicyRequestOperations · v1.3
- Data Classification & Handling PolicyRequestPrivacy · v1.2
- Data Protection & Privacy PolicyRequestPrivacy · v2.0
- Data Retention & Disposal PolicyRequestPrivacy · v1.1
- Endpoint & Mobile Device Security PolicyRequestSecurity · v1.0
- Human Resources Security PolicyRequestPeople · v1.3
- Incident Response PlanRequestOperations · v1.4
- Information Security PolicyRequestISMS · v3.2
- Network Security PolicyRequestSecurity · v1.3
- New Hire Onboarding PolicyRequestPeople · v1.1
- Risk Assessment & Management PolicyRequestISMS · v1.4
- Secure Software Development PolicyRequestSecurity · v1.4
- Security & Privacy Awareness PolicyRequestPeople · v1.2
- Vendor & Subprocessor Management PolicyRequestISMS · v1.2
- Vulnerability & Patch Management PolicyRequestSecurity · v1.1





















