Third Party Index

Snapshot 44790

Document
Security page
URL
https://trestleiq.com/security-and-privacy/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
197354 bytes
SHA-256 (raw)
68d987c6231bc8a53bd8212adb29c1fc5906cb089e7b37bb17861100a44039a1
SHA-256 (normalized text)
1bf4b98f0027269239da5ab32b035ed785098aa6eefdcbb6c8af3e95e1ff0d3e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trestle Security Overview
Trestle is a trusted name in the identity verification space, and we take that trust seriously. We based our first information security program on ISO 27001:2005. We take a risk-based approach to information security, which is to say a practical one: we protect systems and data according to their sensitivity and exposure to threats. Trestle Solutions Inc. successfully completed the AICPA Service Organization Control (SOC) 2 Type I audit. The audit confirms that Trestle Solutions Inc.’s information security practices, policies, procedures, and operations meet the SOC 2 standards for security.
Security FAQ
What are your risk management practices?
Trestle employs a risk-based information security program: we protect systems and data according to their sensitivity and exposure to threats. Our baseline risk assessments occur annually across both corporate and service environments. They include policy and procedure reviews, control design and functionality review, technical configuration analysis, network and web application penetration testing, and interviews with team members. All risks are documented with their associated vulnerabilities, controls, and recommendations for risk reduction.
These risk assessments feed into an enterprise-wide risk register which is maintained continuously. As new risks are identified, they’re formally documented and addressed. This whole process is overseen by our Information Security Officer and executive leadership.
How are access controls determined and maintained?
Trestle employs role-based access controls based on need-to-know and least privilege. Each team member is assigned a primary role at hire, or transfer, which determines their access to systems and applications. Each role is formally defined, as its access. In order to gain access outside an individual’s role, an access request ticket must be submitted, approved, and provisioned.
Access control reviews are performed quarterly as part of internal audits conducted by our Information Security Officer.
How do you respond to incidents?
Trestle has established a formal Incident Management Program that covers security, privacy, and availability incidents. For each type of incident, there are reporting, response, and retrospective requirements and supporting materials. Customer notifications are a formally documented aspect of each incident type.
Do you have a Security Incident and Event Management system?
Yes, Trestle employs an appropriate incident and event management system.
How is remote access to your service environment handled?
Trestle employs MFA to access all corporate assets including internal documents, email systems, and code base. An IAM policy enforces MFA for our GCP and AWS console, and alerting is configured should it be disabled.
Do your applications have periodic third-party penetration tests?
Yes, Trestle employs a Qualified Security Assessor company to perform penetration tests annually against our APIs, web applications and external networks. The latest report is available to prospective and existing customers upon request.
What encryption standards are used for communication with your services?
All Trestle, and most other Trestle properties, use HTTP Strict Transport Security, which forces all connections to use HTTPS. We currently only support TLS 1.2.
What do you do to mitigate DDoS attacks?
Trestle service environment is hosted in AWS across multiple availability zones. Necessary DDoS protection services are deployed for protection purposes.
Is secure software development and OWASP Top 10 training required for your developers?
Yes. Every software developer takes secure software development training annually. This includes taking courses on securing AWS database offerings.
What physical security controls are implemented for your service environments?
Trestle employs AWS for its service infrastructure at the physical layer, and we review AWS SOC 2 Type 2 reports twice annually as part of our risk management program.
What is Trestle’s policy when it comes to reporting security vulnerabilities?
At Trestle, safety and security are foundational principles central to every part of our company and the innovative technology platforms and services we enable. We know that secure products and services are essential to our customers’, cardholders’, merchants’, and other partners’ trust in us.
If you believe you have identified a security vulnerability, we encourage you to report this to us as soon as possible through security@trestleiq.com. We’ll investigate all verifiable and legitimate reports and do our best to fix the problem as quickly as possible.
What platforms and vulnerability categories are in scope?
All our APIs documented here and our Developer Portal here.
What if I identify vulnerabilities or issues outside of these areas?
Monetary rewards are offered to external security researchers if they identify an issue on one of the in-scope platforms. Compensation depends on the severity and impact of the identified issue. Trestle reviews each identified vulnerability and reserves the right to reward submissions made on out-of-scope assets.
What is the reward process for reported vulnerabilities?
You can submit potential security vulnerabilities through our security alias for reward consideration. The rewards will range from $50 to $5,000, depending on the vulnerability and its severity and impact.
Do you have 24/7 monitoring for your environment?
In addition to our dedicated security team, Trestle also employs 24/7 monitoring of our service and corporate environments.
Products
Enrichment
Reverse Phone APIGLOBAL
Verify and enrich phone numbers
Reverse Address API
Verify and enrich address information
Caller Identification API
Identify and enrich caller information
Add-Ons
Litigator Check
Identify phone numbers associated with serial litigators
Email Deliverability
Confirm email inboxes accept mail in real-time
Spam Check
Flag phone numbers tied to high-risk calling activity
Email Age Score
Score how long an email has existed
Validation & Verification
Phone Validation APIGLOBAL
Validate phone numbers and identify disconnected numbers
Real Contact API
Verify phone, email, and address information
Address Validation API
Validate and normalize addresses
Assess Risk
Decision Console
Optimize identity verification for manual review
Decision Signals API
Automate identity verification for risk decisioning
Start using Trestle products today
Get started for free—no credit card required
Start Your Free Trial
Solutions
Industries
B2B Contact Data
eCommerce
Insurance
Lead Generation
Real Estate
Communications
Use Cases
Verify and Prioritize Leads
Outbound Dialing Optimization
Assess Risk And Prevent Fraud
Inbound Call Routing and Verification​
Signup and Onboarding​
Optimize AI Voice Agents
Start using Trestle products today
Get started for free—no credit card required
Start Your Free Trial
Pricing
Resources
API Documentation
Blog
Knowledge Base
Case Studies
Glossary
Partners and Integrations
Company
About Us
Why Trestle
Careers
Affiliate Program
Contact
Log In
Start for Free