Third Party Index

Snapshot 37112

Document
Trust center
URL
https://trust.truto.one/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
311066 bytes
SHA-256 (raw)
d6af835253ee8c9b79ad1e00ccbf115a082097b3e8ef6848201859c225cb48c6
SHA-256 (normalized text)
23884325e7c461de6e04c10624b9b747d496c163b9824857c3b4dd778dae847e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security & Compliance
Security and compliance at Truto
Certifications and security program overview.
Controls
118
Certifications
05
Subprocessors
05
01
Updates
01 update
Jun 12, 2026
SOC 2 Type II observation period underway
Truto has entered the observation period for its fourth consecutive SOC 2 Type II audit, conducted by our independent auditor, Prescient Security. The audit evaluates the operating effectiveness of our security controls across the observation window, with the renewed report available to customers under NDA on completion.
02
Certifications
05 active
SOC 2 Type II
● Active
Apr 1, 2026 → Mar 31, 2027
ISO 27001
● Active
Jan 22, 2026 → Jan 22, 2027
GDPR
● Active
Active
HIPAA
● Active
Active
CASA Type II
● Active
Active
03
Trusted by
Sprinto
Thoropass
15Five
Spendflo
Springworks
DocsBot
SiteGPT
Senja
ZenAdmin
Evergrowth
BalkanID
Claira
Cloudficient
Omnitrain
NAQ Cyber
04
Compliance program
Compliance automationSprinto
Independent auditorPrescient Security
05
Controls
118 controls
06
Security & data protection
07 practices
Single Sign-On (SSO)Enterprise SSO via SAML and OIDC so teams authenticate through their own identity provider.
Two-Factor Authentication (2FA)Multi-factor authentication enforced for privileged and administrative access.
Role-Based Access Control (RBAC)Least-privilege, role-based permissions across the platform.
AES-256 Encryption at RestAll data at rest is encrypted with AES-256.
Latest TLS in TransitAll data in transit is encrypted with the latest TLS (1.2+).
Database Region SelectionChoose the region where your data is stored to meet residency requirements.
Zero-Data Storage ModelA pass-through architecture: customer data flows in real time and is never persisted on Truto's platform.
07
Security overview
Truto is built on a pass-through, zero-storage architecture: your customers' data flows through Truto in real time and is never persisted on our platform. That single design decision shrinks our attack surface and keeps you in control of where data lives. Our security program is independently audited — SOC 2 Type II and ISO 27001 — and continuously monitored through Sprinto, with each control mapped to a live evidence check rather than a point-in-time screenshot. Access follows least-privilege RBAC with enforced MFA, all data is encrypted in transit (TLS 1.2+) and at rest (AES-256), and infrastructure runs on SOC 2-certified providers across US and EU regions. We run annual third-party penetration tests, maintain a documented incident-response plan with customer notification within 48 hours, and give at least 15 days' notice before adding or replacing any subprocessor.
08
Subprocessors
05 vendors
Third-party subprocessors used by Truto
Name	Purpose	Location
Cloudflare	Hosting, infrastructure, internet security, CDN and monitoring	Global (multi-region)
Datadog	Infrastructure monitoring, log management, APM and alerting	United States
DigitalOcean	Cloud infrastructure, compute, database and storage services	United States
Mailchimp	Transactional and marketing email delivery	United States
OVHcloud	Cloud infrastructure, compute, database and storage services	France (EU)
Cloudflare
Purpose
Hosting, infrastructure, internet security, CDN and monitoring
Location
Global (multi-region)
Datadog
Purpose
Infrastructure monitoring, log management, APM and alerting
Location
United States
DigitalOcean
Purpose
Cloud infrastructure, compute, database and storage services
Location
United States
Mailchimp
Purpose
Transactional and marketing email delivery
Location
United States
OVHcloud
Purpose
Cloud infrastructure, compute, database and storage services
Location
France (EU)
09
FAQ
06 questions
01Does Truto store our customers' data?
No. Truto runs on a pass-through, zero-storage model — your customers' data flows directly from the source system to you in real time and is never persisted on Truto's platform.
02Which security certifications and frameworks does Truto maintain?
Truto maintains SOC 2 Type II and ISO 27001, and operates in alignment with GDPR and HIPAA. The current status and validity for each is shown in the Certifications section above.
03Can we review your SOC 2 report and DPA?
Yes. Our Data Processing Agreement is published at truto.one/dpa, and the full SOC 2 Type II report is available to enterprise customers under NDA — just email [email protected].
04How is data protected in transit and at rest?
All data is encrypted in transit using TLS 1.2+, and any operational metadata at rest is encrypted with AES-256. Internal access is governed by role-based access control and enforced multi-factor authentication.
05How do you manage subprocessors?
Our subprocessors are listed publicly in the Subprocessors section. We give at least 15 days' advance notice before adding or replacing any subprocessor, and you may object on reasonable data-protection grounds.
06Can Truto be deployed on-premise?
Yes. Truto offers both a managed cloud and an on-prem / self-hosted deployment, so sensitive data never has to leave your own environment.
10
Documents
05 available
GDPR Compliance CertificateRequest
HIPAA Compliance CertificateRequest
ISO 27001 CertificateRequest
Penetration Test SummaryRequest
SOC 2 Type II ReportRequest
11
Policies
23 documents
The information-security policies behind our program. Documents are shared on request — submit a request and we’ll send a secure link once approved.
Acceptable Use PolicyRequest
ISMS · v2.0
Access Control PolicyRequest
ISMS · v2.1
Application Security PolicyRequest
Security · v1.1
Asset Management PolicyRequest
ISMS · v1.3
Business Continuity & Disaster Recovery PlanRequest
Operations · v1.3
Change Management PolicyRequest
Operations · v1.3
Code of Business ConductRequest
People · v1.4
Cryptography & Key Management PolicyRequest
Security · v1.2
Data Backup PolicyRequest
Operations · v1.3
Data Classification & Handling PolicyRequest
Privacy · v1.2
Data Protection & Privacy PolicyRequest
Privacy · v2.0
Data Retention & Disposal PolicyRequest
Privacy · v1.1
Endpoint & Mobile Device Security PolicyRequest
Security · v1.0
Human Resources Security PolicyRequest
People · v1.3
Incident Response PlanRequest
Operations · v1.4
Information Security PolicyRequest
ISMS · v3.2
Network Security PolicyRequest
Security · v1.3
New Hire Onboarding PolicyRequest
People · v1.1
Risk Assessment & Management PolicyRequest
ISMS · v1.4
Secure Software Development PolicyRequest
Security · v1.4
Security & Privacy Awareness PolicyRequest
People · v1.2
Vendor & Subprocessor Management PolicyRequest
ISMS · v1.2
Vulnerability & Patch Management PolicyRequest
Security · v1.1
12
Legal & privacy
03 documents
Privacy Policy
Data Processing Agreement (DPA)
CCPA Notice