

Practical details for security reviewers: how data moves, what we encrypt, what zero-knowledge covers, and how to request a Security Assurance readiness package.
Last updated August 11, 2026
Request Security Assurance packageWe design controls for enterprise security and privacy requirements. Security Assurance materials and readiness evidence are shared under NDA with qualified prospects and customers. This page does not claim a completed SOC 2 or ISO 27001 certification or a published audit report.
Controls are mapped to the Trust Services Criteria. No SOC 2 audit report has been issued.
Security program aligned to selected ISO/IEC 27001:2022 controls. Trustity is not ISO 27001 certified.
DPA and international-transfer support available for applicable deployments. GDPR is not a certification.
Not currently supported unless a signed BAA and an approved deployment scope are in place.
Endpoints run the TAO agent (and GenGuard in the browser where deployed). Policy and telemetry travel to the Trustity Cloud Portal over TLS. Operators manage fleet policy there - not on this marketing site.
TAO enforces VisionX, HostGuard, and local PAM rotation. GenGuard applies browser policy where installed. VisionX detection is designed to run on the device.
Agent and portal APIs use TLS in transit. Cloud databases and object storage use provider-managed encryption at rest with industry-standard cryptography.
Each customer organization is isolated. Admins see only their tenant’s devices, policies, and audit events.
Vault wrapping keys are designed so Trustity cannot read customer vault secrets in cleartext. This does not apply to every telemetry field in the portal.
Least privilege, tenant isolation, and zero-knowledge vault design for secrets that customers entrust to the portal.
TLS for portal and agent traffic. Provider-managed encryption at rest for cloud databases and storage, using industry-standard cryptography.
Applies to vaulted secrets / credentials under split-key wrapping - not to every telemetry field in the portal.
Operational monitoring plus a documented channel at security@trustity.co. Researchers can also use /.well-known/security.txt.
Current processors used to operate the product. Ask security@trustity.co for the signed schedule under NDA, including regions and transfer mechanisms.
| Provider | Purpose | Scope |
|---|---|---|
| Supabase | Database, auth, storage | Cloud Portal / SecSend |
| Vercel | Application hosting | Websites and apps |
| Cloudflare | DNS / edge, where configured | Public sites |
| Resend | Transactional email | Notifications / SecSend |
| Twilio | SMS delivery | SecSend unlock codes |
If you found a potential issue in Trustity systems, contact us promptly. Do not include customer secrets or exploit payloads in public channels. Testing is limited to systems you are authorized to assess; denial-of-service and social engineering are out of scope.
Contact Security TeamLooking for product docs or a technical deep-dive for integrators?