Our security posture
Security at TrustVendor.
A product that helps customers verify vendor security claims should hold itself to the same standard. This page describes TrustVendor's own security controls, updated quarterly.
Certifications
- ✓ SOC 2 Type II (in progress)
- ✓ ISO 27001 (roadmap)
- ✓ GDPR DPA available
Infrastructure
- ✓ AWS us-east-1 primary, eu-west-1 failover
- ✓ All data encrypted at rest (AES-256)
- ✓ TLS 1.2+ in transit, HSTS enforced
- ✓ WAF in front of all public endpoints
Access control
- ✓ SSO enforced internally (Okta)
- ✓ MFA required for all engineers
- ✓ Least-privilege IAM, reviewed quarterly
- ✓ No standing database access — JIT provisioned
Data handling
- ✓ PHI never stored — not in scope
- ✓ Tenant data isolated by Postgres RLS
- ✓ Data deletion within 30 days of account termination
- ✓ Subprocessor list published and monitored
Vulnerability management
- ✓ Dependency scanning on every CI build (Snyk)
- ✓ Annual penetration test (third-party)
- ✓ Bug bounty program (coordinated disclosure)
Incident response
- ✓ Documented IR plan with runbooks
- ✓ Breach notification within 72 hours (GDPR)
- ✓ Post-mortems published for material incidents
Security questions
Where is TrustVendor data stored?
Primary data is stored in AWS us-east-1. EU customer data can be configured for eu-west-1 storage. All data is encrypted at rest using AES-256 and in transit using TLS 1.2+.
Can I request TrustVendor's SOC 2 report?
Our SOC 2 Type II audit is in progress. When the report is available, it will be shared with customers and prospects under NDA on request. Sign up at [email protected] to be notified when it is available.
Does TrustVendor store the vendor documents it processes?
Yes. Snapshots of vendor documents are stored in encrypted blob storage. Each snapshot is sha256-hashed before storage. Full document content is visible only to authenticated workspace members with access to that vendor. The public vendor graph shows extracted claims and short cited spans, not full document content.
How do I report a security vulnerability?
Email [email protected] with a description of the vulnerability. We will acknowledge receipt within 48 hours and provide a timeline for remediation. We do not pursue legal action against researchers who disclose responsibly.
Security contact: [email protected] — Subprocessor list: available in our DPA — Last updated: September 2026