Trust & Security

Security at TrustFoundry

Security is foundational to how we build. We protect customer data with layered controls, least-privilege access, and continuous monitoring, and we report our posture transparently through our Trust Center.

Visit our Trust Center

Our approach

Least privilege

Access to systems and data is limited to what each person and service needs.

Defense in depth

Controls are layered so no single failure exposes data.

Continuous monitoring

We continuously monitor our security controls with Vanta.

Privacy by design

Data protection is considered from the first line of design, not bolted on later.

Data protection

Encryption in transit

All traffic between clients and our services is encrypted with TLS 1.2 or higher.

Encryption at rest

Data stored in our cloud infrastructure is encrypted at rest.

Secrets management

Encryption keys and credentials are held in a managed secrets service with restricted access.

Application & infrastructure security

Secure development

Changes are peer reviewed before they ship, and automated linting and checks run in our pipeline.

Dependency scanning

Dependencies are scanned for known vulnerabilities as part of our build process.

Hardened cloud

Our services run on hardened cloud infrastructure with network access controls and audit logging.

Access & operational security

Identity & access

Access to internal systems requires authentication and is granted on a least-privilege basis.

Monitoring & logging

Systems are logged and monitored so we can detect and respond to unusual activity.

Data privacy

We handle personal data in line with our Privacy Policy and give users control over their information.

Compliance & Trust Center

We continuously monitor our security controls with Vanta. For our current security and compliance status, visit our Trust Center.

Open Trust Center