Snapshot 37112
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security & Compliance Security and compliance at Truto Certifications and security program overview. Controls 118 Certifications 05 Subprocessors 05 01 Updates 01 update Jun 12, 2026 SOC 2 Type II observation period underway Truto has entered the observation period for its fourth consecutive SOC 2 Type II audit, conducted by our independent auditor, Prescient Security. The audit evaluates the operating effectiveness of our security controls across the observation window, with the renewed report available to customers under NDA on completion. 02 Certifications 05 active SOC 2 Type II ● Active Apr 1, 2026 → Mar 31, 2027 ISO 27001 ● Active Jan 22, 2026 → Jan 22, 2027 GDPR ● Active Active HIPAA ● Active Active CASA Type II ● Active Active 03 Trusted by Sprinto Thoropass 15Five Spendflo Springworks DocsBot SiteGPT Senja ZenAdmin Evergrowth BalkanID Claira Cloudficient Omnitrain NAQ Cyber 04 Compliance program Compliance automationSprinto Independent auditorPrescient Security 05 Controls 118 controls 06 Security & data protection 07 practices Single Sign-On (SSO)Enterprise SSO via SAML and OIDC so teams authenticate through their own identity provider. Two-Factor Authentication (2FA)Multi-factor authentication enforced for privileged and administrative access. Role-Based Access Control (RBAC)Least-privilege, role-based permissions across the platform. AES-256 Encryption at RestAll data at rest is encrypted with AES-256. Latest TLS in TransitAll data in transit is encrypted with the latest TLS (1.2+). Database Region SelectionChoose the region where your data is stored to meet residency requirements. Zero-Data Storage ModelA pass-through architecture: customer data flows in real time and is never persisted on Truto's platform. 07 Security overview Truto is built on a pass-through, zero-storage architecture: your customers' data flows through Truto in real time and is never persisted on our platform. That single design decision shrinks our attack surface and keeps you in control of where data lives. Our security program is independently audited — SOC 2 Type II and ISO 27001 — and continuously monitored through Sprinto, with each control mapped to a live evidence check rather than a point-in-time screenshot. Access follows least-privilege RBAC with enforced MFA, all data is encrypted in transit (TLS 1.2+) and at rest (AES-256), and infrastructure runs on SOC 2-certified providers across US and EU regions. We run annual third-party penetration tests, maintain a documented incident-response plan with customer notification within 48 hours, and give at least 15 days' notice before adding or replacing any subprocessor. 08 Subprocessors 05 vendors Third-party subprocessors used by Truto Name Purpose Location Cloudflare Hosting, infrastructure, internet security, CDN and monitoring Global (multi-region) Datadog Infrastructure monitoring, log management, APM and alerting United States DigitalOcean Cloud infrastructure, compute, database and storage services United States Mailchimp Transactional and marketing email delivery United States OVHcloud Cloud infrastructure, compute, database and storage services France (EU) Cloudflare Purpose Hosting, infrastructure, internet security, CDN and monitoring Location Global (multi-region) Datadog Purpose Infrastructure monitoring, log management, APM and alerting Location United States DigitalOcean Purpose Cloud infrastructure, compute, database and storage services Location United States Mailchimp Purpose Transactional and marketing email delivery Location United States OVHcloud Purpose Cloud infrastructure, compute, database and storage services Location France (EU) 09 FAQ 06 questions 01Does Truto store our customers' data? No. Truto runs on a pass-through, zero-storage model — your customers' data flows directly from the source system to you in real time and is never persisted on Truto's platform. 02Which security certifications and frameworks does Truto maintain? Truto maintains SOC 2 Type II and ISO 27001, and operates in alignment with GDPR and HIPAA. The current status and validity for each is shown in the Certifications section above. 03Can we review your SOC 2 report and DPA? Yes. Our Data Processing Agreement is published at truto.one/dpa, and the full SOC 2 Type II report is available to enterprise customers under NDA — just email [email protected]. 04How is data protected in transit and at rest? All data is encrypted in transit using TLS 1.2+, and any operational metadata at rest is encrypted with AES-256. Internal access is governed by role-based access control and enforced multi-factor authentication. 05How do you manage subprocessors? Our subprocessors are listed publicly in the Subprocessors section. We give at least 15 days' advance notice before adding or replacing any subprocessor, and you may object on reasonable data-protection grounds. 06Can Truto be deployed on-premise? Yes. Truto offers both a managed cloud and an on-prem / self-hosted deployment, so sensitive data never has to leave your own environment. 10 Documents 05 available GDPR Compliance CertificateRequest HIPAA Compliance CertificateRequest ISO 27001 CertificateRequest Penetration Test SummaryRequest SOC 2 Type II ReportRequest 11 Policies 23 documents The information-security policies behind our program. Documents are shared on request — submit a request and we’ll send a secure link once approved. Acceptable Use PolicyRequest ISMS · v2.0 Access Control PolicyRequest ISMS · v2.1 Application Security PolicyRequest Security · v1.1 Asset Management PolicyRequest ISMS · v1.3 Business Continuity & Disaster Recovery PlanRequest Operations · v1.3 Change Management PolicyRequest Operations · v1.3 Code of Business ConductRequest People · v1.4 Cryptography & Key Management PolicyRequest Security · v1.2 Data Backup PolicyRequest Operations · v1.3 Data Classification & Handling PolicyRequest Privacy · v1.2 Data Protection & Privacy PolicyRequest Privacy · v2.0 Data Retention & Disposal PolicyRequest Privacy · v1.1 Endpoint & Mobile Device Security PolicyRequest Security · v1.0 Human Resources Security PolicyRequest People · v1.3 Incident Response PlanRequest Operations · v1.4 Information Security PolicyRequest ISMS · v3.2 Network Security PolicyRequest Security · v1.3 New Hire Onboarding PolicyRequest People · v1.1 Risk Assessment & Management PolicyRequest ISMS · v1.4 Secure Software Development PolicyRequest Security · v1.4 Security & Privacy Awareness PolicyRequest People · v1.2 Vendor & Subprocessor Management PolicyRequest ISMS · v1.2 Vulnerability & Patch Management PolicyRequest Security · v1.1 12 Legal & privacy 03 documents Privacy Policy Data Processing Agreement (DPA) CCPA Notice